4.1.8
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
4.1.8
The following issues have been resolved in this release of Splunk:
- Epoch timestamps not parsed correctly after March 12, 2011, (SPL-38016)
- A crash issue has been identified with SuSE Linux Enterprise Server 11 / OpenSuSE 11.0,11.1,11.2 and 11.3, combined with Splunk on x86_64. It is caused by a SuSE patch to glibc which breaks programs using external mallocs. The problem can be identified by __res_iclose() in the backtrace in the crash log. (SPL-37331)
- Improvements to IndexProcessor service performance. (SPL-37390)
- Annoying but harmless "ERROR Timeliner - Failed to rm dir" (SPL-35722)
- Scheduled searches stop firing with occasional "WARN SavedSplunker - Saved splunk failed to get current user context" error in scheduler.log. (SPL-33391, SPL-38047)
- Crash in AD with a large number of .dmp files whenever the AD message has %s or similar string. (SPL-37640)
- Window installation erroneously creates splunk-regmon.py and splunk-wmi.py stanzas in inputs.conf. (SPL-37440)
- When registry monitoring baseline data from multiple hives are selected to be monitored, the baseline events from the first collection are repeated multiple times. The baseline data from the other stanzas do not show up. (SPL-37381)
- Incomplete events in parsingQueue are indexed as 'complete' when the 10 second idle timeout limit is hit. (SPL-37252)
- Diag is failing due to token files in $SPLUNK_HOME/etc/alive_tokens/alive_xxxx.token. (SPL-37934)
- Issues with getting results for certain session IDs with error "ERROR SearchResults - Error reading internal file header". (SPL-37712)
- If splunk-regmon baseline=1 is set for a stanza, regmon collects events even if it the collection is disabled. (SPL-37620)
- Regmon filters are case sensitive and shouldn't be. (SPL-37619)
This documentation applies to the following versions of Splunk: 4.1.8 View the Article History for its revisions.