4.0.3
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
4.0.3
The following issues have been resolved in this release:
Resolved general issues
- An issue in which some saved searches were not correctly reflecting the entered string has been resolved. Known situations were when using top for multiple fields as in
|top field1, field2ortop x by x. The error was appearing as "Unknown search operator: Undefined" (SPL-25447), or was displaying different search (SPL-25446). - Upon migration from an earlier version, saved searches are now moved correctly to the Search App and promoted to globally available status. (SPL-25311)
- The search documentation cheatsheet is now updated for version 4.x. (SPL-23986)
- Various issues around resurrecting search jobs and search clause ordering have been resolved. (SPL-21740)
- An issue with incorrect character set detection when certain combinations of Unicode characters appear in an active file has been resolved. (SPL-20780)
- Running
./splunk list forward-serverin the CLI now correctly reflects the status of the forwarders. (SPL-25626) - The listtails command now runs to completion. (SPL-25587)
- An issue with slow Splunk startup has been resolved. (SPL-25572)
- Automatic header-based field extraction now displays correctly when defining report content (SPL-25544)
- The path for results sent to scripts via alerts is now correct. (SPL-25512)
- The 'always' alert condition now triggers correctly. (SPL-25504)
- The splunkmon.log file now reports restarts accurately. (SPL-24928)
- The admin role now sees all non-internal indexes by default. (SPL-24962)
- Subsearch clauses are now resurrected when running a saved search with a subsearch. (SPL-24957)
- The schedule for a scheduled saved search is now preserved when that saved search is disabled. (SPL-25073)
- A crash involving groupmappingattribute when configuring LDAP settings has been resolved. (SPL-25089)
- Editing a saved search no longer causes chart formatting settings to be lost. (SPL-24750)
- Renaming a source type is now reflected correctly in search assistant (SPL-24672)
- An issue with being unable to log into Splunk Web when it starts before splunkd has been resolved. (SPL-24141)
- Searching for a single Japanese character no longer requires double quotes ("). (SPL-23697)
- New source types are now created correctly when a /learned directory is present in /etc/bundles. (SPL-25556)
- The CLI no longer gives a permissions exception when it can't write to authToken. (SPL-25347)
- The isReadOnly option for indexes.conf now works correctly. (SPL-25233)
- The CLI and search command to roll buckets has been changed to:
splunk search "| debug cmd=roll index=index_name"(SPL-25227) - When using an Enterprise Trial license, the same license can be used on multiple distributed search heads. (SPL-24892)
- The addcoltotals operator now works correctly. (SPL-24628)
Resolved Splunk Web/Manager issues
- The browser's selected locale will now always be respected; and Splunk Web will no longer fall back to en_US. (SPL-25432)
- Splunk Web will no longer hang when selecting the "Manager" link from the Launcher or Search App if Splunk cannot connect to splunk.com. (SPL-25520, SPL-24670)
- Linewrapping now works correctly in Firefox 3.5. (SPL-24856)
- The 'next' pagination link is now localizable. (SPL-25378)
- The UDP inputs page now displays the data correctly (does not show all IPs that have forwarded data to the UDP port). (SPL-25465)
- Views with modules that include Flash items now load correctly even when scrolled down. (SPL-25476)
- Semicolons are now correctly handled in field names in Splunk Web. (SPL-17300)
- Non-UTF-8 inputs are now handled correctly in Splunk Web, and do not generate an "[SimpleResultsTable module] Input is not proper UTF-8" error. (SPL-25529)
- The report builder now handles more complex searches properly. (SPL-25322)
Resolved Windows-specific issues
- WMI collection inputs are now supported correctly from all Apps, not just Search and the Windows App. (SPL-25209)
- Various broken links in the Windows App have been fixed. (SPL-25548)
- The Windows App is no longer enabled by default when installing using the commandline/MSI. (SPL-25487)
- Splunk Web no longer adds an extra backslash (\) when displaying Windows source types. (SPL-25298)
- "Object Name" and "Object Type" field Windows Security Event Log GUIDs are now translated correctly. (SPL-25263)
- The spec and example files for admon.conf are now included in the shipping product. (SPL-25231)
- The header for
admon.confno longer erroneously states that changes to the file should be made to$SPLUNK_HOME/etc/system/localwhen changes should be made to$SPLUNK_HOME/etc/apps/windows/local. (SPL-24859) - WMI events no longer are forwarded to non-Windows indexers with spaces appended to the source and source type values. (SPL-25666)
- Scripted inputs are much faster than in earlier versions. (SPL-25452)
- objectGUID is now reported correctly in Admon events. (SPL-25315)
This documentation applies to the following versions of Splunk: 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.