Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.5.0

Splunk Enterprise 6.5.0 was released on September 27, 2016.

In addition to the following resolved issues, this release also incorporates fixes documented in the changelogs for 6.4.1, 6.4.2, and 6.4.3.

For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Data input issues

Date resolved Issue number Description
2016-08-11 SPL-125707, SPL-102939 Archive Processor cannot handle zip files containing entries with non-ascii utf8 chars in their filenames
2016-05-17 SPL-113738, SPL-109285 Workflow Actions will not send more than 9 POST arguments
2016-05-04 SPL-115015, SPL-119571, SPL-119570, SPL-119573 Powershell Script randomly stops running untill Splunk is restarted

Search issues

Date resolved Issue number Description
2016-08-22 SPL-123134, SPL-95575 SortProcessor::getStreamingOp crashes in appendpipe subsearch due to inserting streaming operators into report search
2016-08-11 SPL-124539, SPL-104555 Multisearch returns different results than individual searches
2016-08-03 SPL-122519, SPL-116867 Search Process crashes in dispatch thread when the custom alert condition search contains invalid search query
2016-07-29 SPL-124241, SPL-118842 Missing Event Type Color for transaction search results including multiple Event Types.
2016-06-30 SPL-74151 When using SimpleXML, an extra pipe in the search post process of a form runs fine on the dashboard but shows errors when linked to the search page.
2016-06-29 SPL-121968, SPL-105581 Search with an eval or calculated field which calls the tostring(..., "duration") function fails with: "Invalid number"
2016-06-29 SPL-91996, SPL-91818 No error if ref panel can't render because of ID collision.
2016-04-22 SPL-118301, SPL-117295 Add logging to LookupOperator warning users about implicitly defined lookups
2016-02-29 SPL-113654, SPL-58137 Crashing thread: DispatchReaper - assert fail in TimeFormat::render()
2016-02-23 SPL-102405 Search operator outputcsv provides no explanation for the rejection of a file name with OS separators: "/" or "\"

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2016-08-16 SPL-124771, SPL-124301 Data Model Acceleration stops running for certain Data Models after success=0 multiple times
2016-07-29 SPL-124241, SPL-118842 Missing Event Type Color for transaction search results including multiple Event Types.
2016-04-29 SPL-32670, SPL-111916 Jobs in job manager with filter does not update after an action is performed.
2016-04-12 SPL-115722, SPL-110142 'null' password gets hashed and breaks email alerts
2016-02-12 SPL-108314 After stopping Splunk and attempting splunk clean command, error occurs: Could not remove all contents of 'C:\Users\Administrator\tmp\var\lib\splunk\kvstore'
2016-01-07 SPL-111916, SPL-32670 Jobs in job manager with filter does not update after an action is performed.

Charting, reporting, and visualization issues

Date resolved Issue number Description
2016-07-18 SPL-91074, SPL-91065 Submit button does not get rendered when instantiating a form via the client-side parser/factory
2016-06-30 SPL-79562 Cloned dashboard is not scheduled but "Schedule PDF Delivery" link indicates that the schedule was cloned.
2016-06-30 SPL-74151 When using SimpleXML, an extra pipe in the search post process of a form runs fine on the dashboard but shows errors when linked to the search page.
2016-06-29 SPL-91996, SPL-91818 No error if ref panel can't render because of ID collision.
2016-05-04 SPL-91211 Cascading form inputs that uses an unset condition on a form input causes a continuous loop for the form input values.
2015-12-17 SPL-76824 Dashboard returns 400 error and invalid message if "maxLines" and "count" is empty for Panel Type: Event.

Data model and pivot issues

Date resolved Issue number Description
2016-08-16 SPL-124771, SPL-124301 Data Model Acceleration stops running for certain Data Models after success=0 multiple times
2016-02-12 SPL-108314 After stopping Splunk and attempting splunk clean command, error occurs: Could not remove all contents of 'C:\Users\Administrator\tmp\var\lib\splunk\kvstore'

Indexer and indexer clustering issues

Date resolved Issue number Description
2016-08-12 SPL-122187, SPL-106900 Audit trail spams splunkd.log with errors: "Failed to save seq_no=7885 for host="host::MLTPSAPV224" to disk!"
2016-07-26 SPL-123603, SPL-123262 Crashing thread: indexerPipe on failing to write raw data to a hot bucket due to no space on disk
2016-06-22 SPL-122154, SPL-121693 CSV Streaming Parser crashing for quoted empty strings followed by a space and Windows newline

Distributed search and search head clustering issues

Date resolved Issue number Description
2016-08-16 SPL-124771, SPL-124301 Data Model Acceleration stops running for certain Data Models after success=0 multiple times
2016-08-15 SPL-123775, SPL-80967 Configuration bundles corrupted during creation might be replicated, causing issues in other servers.
2016-08-15 SPL-120038, SPL-115793 Error messaging unclear when there are failures creating replication bundles.
2016-08-11 SPL-125138, SPL-126603, SPL-126604 The description of shc_local_quota_check in limits.conf.spec is inaccurate
2016-06-30 SPL-123305, SPL-123479, SPL-123375 loadjob not working - statusCode=403, Forbidden
2016-05-12 SPL-119829, SPL-113189 SHC members do not always restart properly after bundle push
2016-02-18 SPL-99072 Search Head Cluster Members exit with warning while startup continues after performing rolling restart

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2016-06-07 SPL-118097, SPL-113405 Forwarder Management Add data - Unable to add inputs with unique serverclasses and same sourcepath

Monitoring Console/DMC issues

Date resolved Issue number Description
2016-08-18 SPL-121813, SPL-119348 DMC doesn't support Cluster Label with space in it
2016-05-26 SPL-113844 Splunk TCP Input Performance: Instance doesn't work with pipelinesets.
2016-05-26 SPL-113843 Splunk TCP Input Performance: Deployment doesn't work with pipelinesets.
2016-02-26 SPL-101270 In the DMC, the sort button overlaps with the column separator.

Splunk Web and interface issues

Date resolved Issue number Description
2016-09-19 SPL-91346, SPL-91344 A user with a non-admin role but edit_user capability can map to the Roles page. User receives a message that there is an error retrieving the configuration, and cannot process the page.
2016-07-29 SPL-124241, SPL-118842 Missing Event Type Color for transaction search results including multiple Event Types.
2016-04-06 SPL-117137, SPL-117217 When using appServerPorts = 0 and SSL Splunkweb will not start in 6.4.0.

Windows-specific issues

Date resolved Issue number Description
2016-08-15 SPL-122696, SPL-118920 Windows local user added to domain group does not properly translate SID/GUIDs.

Rest, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2016-05-17 SPL-113738, SPL-109285 Workflow Actions will not send more than 9 POST arguments

Unsorted issues

Date resolved Issue number Description
2016-08-26 SPL-127079, SPL-127095 Duplicate events with indexerDiscovery following outages on indexer cluster.
2016-08-19 SPL-125703, SPL-98358 WARN TcpOutputProc - The event is missing source information.
2016-08-03 SPL-122893, SPL-108622 CallbackRunnerThread may stop servicing callbacks on high load, preventing license usage rollovers.
2016-06-20 SPL-120526, SPL-118185 When "useDeploymentServer = 1", HttpInputConf does not properly load tokens into memory

Uncategorized issues

Date resolved Issue number Description
2016-08-10 SPL-96091 SimpleXML: cannot use token in <option name="count">$token$</option>
PREVIOUS
6.5.1
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.2, 6.5.3


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters