4.0.10
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
4.0.10
The following issues have been resolved in this release:
- As of Splunk version 4.0.10, summary index searches do not count towards your indexed data volume. (SPL-29515)
- Events generated by the internal auditing feature, which creates events for user-actions such as fired searches are no longer counted against the license. (SPL-28462)
- Summary indexing now works if var/run/splunk and var/spool/splunk are on different filesystems. (SPL-26631)
- Summary index searches that are suspended due to exceeding disk or concurrent search quotas now resume when the quota is available again, and do not require a restart to resume. (SPL-28999)
- Splunk search is no longer limited to lists of OR terms around 415 long, eg "1 OR 2 OR 3.... OR 415". (SPL-28301)
- Deploying apps that do not contain a local directory will no longer cause Splunk to crash on the client. (SPL-29019, SPL-30225)
- Deploying apps to a location outside of $SPLUNK_HOME/etc/apps will no longer cause a crash on the deployment client. (SPL-29484)
- Quotes in saved searches are now correctly being escaped and are no longer returning zero results. (SPL-28734)
- Show source is now available for monitor inputs specified as a UNC path on a remote volume. (SPL-28455)
- Accessing a search from a link sent in an email alert will no longer display an error. (SPL-29420)
- Scheduled saved searches that have never been run from inside Splunk Web now work correctly in email alerts. (SPL-29483, SPL-28302)
- Searches with
NOT field="value"are now correctly escaped. (SPL-29353, SPL-29121) - An issue with LDAP anonymous bind and squashing of uppercase characters in the failsafe username has been resolved. (SPL-28902, SPL-28874)
- Indexing memory leaks have been addressed. (SPL-28772, SPL-30101)
- The string "head 1" no longer gets converted to "head true" in search. (SPL-30058)
- The
tailing_proc_speedsetting is now available inlimits.conf. Refer tolimits.conf.specfor details. - An issue with stats/chart/timechart values of min/max/first when calculated using summary index data generated using sistats/sichart/sitimechart has been resolved. (SPL-29643)
- An error is no longer generated when disabling/clearing Windows Event Log inputs. (SPL-29568)
- A STOP exception related to converting the
_timefield to non-epochTime in Windows evt files has been resolved. (SPL-29453) - All available roles are now available for permissions assignments in Manager. (SPL-28338, SPL-29328)
- An issue with inconsistent numbers of results displayed when changing the results per page setting on IE browsers has been resolved. (SPL-29314)
- An issue with report count and result count displaying differing values in IE has been resolved. (SPL-28976)
- An issue involving SSL errors on deployment clients after upgrade to 4.0.9 has been resolved. (SPL-29284)
- Some issues with multi-byte character handling in
substr()andlen()have been resolved. (SPL-29233) - An issue involving KV_MODE=auto not working correctly on data converted from SHIFT-JIS to UTF-8 has been resolved. (SPL-29151)
- A locale setting issue reporting "Message:"null" is null or not an object" when using the Windows app has been resolved. (SPL-28458)
- Specifying
index=*when forcing a roll from hot to warm works correctly and does not generate an error. (SPL-29049) - A crash related to searches with multiple append strings has been resolved. (SPL-28636)
- The block signing functionality now recognizes events deleted from within Splunk as potential gaps. (SPL-28508)
- The sendemail script now sends only one email regardless of whether a preview has been generated or not. (SPL-29500)
- A crash involving "No memory mapped" has been resolved. (SPL-29468, SPL-28854)
- An issue with Solaris /etc/timezone value not being recognized, resulting in incorrect display timestamps, has been resolved. (SPL-29460)
- Search assistant command link now handles doublequotes correctly. (SPL-26977)
This documentation applies to the following versions of Splunk: 4.0.10 , 4.0.11 View the Article History for its revisions.