4.0.9
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
4.0.9
The following issues have been resolved in this release:
- Some issues related to high memory consumption have been resolved. (SPL-28480, SPL-28303)
- A security issue involving passing absolute URIs has been resolved. (SPL-28706)
- An issue related to the UTF-8 processor consuming too much memory has been resolved. (SPL-28814)
- Excessive FileClassifierManager logging around UTF-8 and VISCII has been resolved. (SPL-28774)
- An issue involving Splunk Web hanging when using SSL has been resolved. (SPL-28315)
- Splunk Web will no longer generate an error when reloading the page during a search. (SPL-28460)
- An issue with garbled WMI-collected Windows Event log messages on Windows 2008 has been resolved. (SPL-28346)
- The number of global events indexed is now displayed correctly when using distributed search and multiple indexes. (SPL-28305)
- Total events indexed and index sizes are now displayed for all indexes. (SPL-26998)
- Event counts are now displayed correctly in the Search app Summary page. (SPL-28499)
- The IIS source type now correctly extracts fields for IIS Web logs. (SPL-28272)
- The default IIS log file format (the "W3C Extended" standard) is now automatically classified by Splunk. (SPL-28271)
- The *Nix app now correctly loads the "Percent % Load by Host" graph. (SPL-28514)
- An issue involving Splunk crashing at the login screen due to issues with older metadata files has been resolved. (SPL-28502)
- An indexer crash involving
HTTPRequestHandlerThreadat shutdown has been resolved. (SPL-28711) - Splunk no longer arbitrarily closes standard TCP connections after 15 minutes when
enableS2SHeartbeatis true. (SPL-28411) - An issue involving correctly following directory paths in lookup scripts has been resolved. (SPL-28240, SPL-28229)
- Key-value extraction now works correctly on Fortinet log events. (SPL-27889)
- An issue involving a crash resulting from very large strings in expanded searches has been resolved. (SPL-27645)
- A cloned report now includes displayview information correctly. (SPL-27633)
- An emailed report generated from a saved search now includes the correct chart formatting. (SPL-25671)
- A
WARN TcpInputFd - Closing socket errno=0error will no longer be repeatedly written to splunkd.log. (SPL-27618) - An issue around lock files not being cleaned up and preventing an indexer from being restarted has been resolved. (SPL-27410)
- Misconfigured forwarders (for example, accidentally configured to point to the splunkweb port instead of the receiving port) can now be shut down and restarted correctly once they are reconfigured. (SPL-27285)
- Fields for reporting are now displayed correctly in Firefox 3.5. (SPL-25977)
- All indexes are now listed correctly in Manager across all distributed search heads without having to create dummy indexes. (SPL-23796)
- Back slashes are no longer erroneously added to saved search strings involving
NOTstatements. (SPL-28640, SPL-28136) - Saved searches with NOTs in them now have correctly escaped quotation marks. (SPL-28640, SPL-26944)
- All AD monitoring-related fields are now available in the fields picker. (SPL-28537, SPL-28329)
- Accessing the _bump endpoint now correctly reloads configs and does not generate a 500 error. (SPL-28464)
- Values removed from pages in Manager (such as the Roles page) now remain empty when the page is saved. (SPL-28328)
- An issue with forwarders losing a single event when restarted has been resolved. (SPL-26876)
This documentation applies to the following versions of Splunk: 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.