Splunk® Enterprise

Release Notes

Download manual as PDF

Download topic as PDF

6.6.0

Splunk Enterprise 6.6.0 was released on May 2, 2017.

In addition to the following resolved issues, this release also incorporates fixes documented in the changelogs for 6.5.1, 6.5.2, 6.5.3, and the cloud-only release 6.5.1612.

For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Search issues

Date resolved Issue number Description
2017-05-25 SPL-142008, SPL-131720 Search message reporting slow configuration initialization should not be shown to cloud customers (users & admins)
2017-03-03 SPL-135505, SPL-134343 Admin user sharing a search via the 'Share' button to a non-admin user may result in 'Permission Denied' for user when clicking the link
2017-02-22 SPL-134132, SPL-134076 Windows central site SH crashes by user without permission accessing search.log of ad hoc search.

Indexer and indexer clustering issues

Date resolved Issue number Description
2017-03-08 SPL-136737, SPL-100516 Events deleted in an index cluster via the delete search operator may be inconsistently deleted on secondaries
2017-02-22 SPL-133895, SPL-113104 Misleading log message when Indexer Discovery fails in forwarders due to mismatch in pass4SymmKey.

Distributed search and search head clustering issues

Date resolved Issue number Description
2017-02-27 SPL-135744, SPL-135367 Total concurrency deals with only scheduler enabled peers in an SHC leading to lower concurrency limits cluster-wide
2017-01-13 SPL-133356, SPL-132893 SHC - Creating huge number of connections when a peer is down
2017-01-12 SPL-132805, SPL-131398 Search head cluster contention on Linux due to poor hashing inside OpenSSL's error container.
2017-01-10 SPL-129081 srchDiskQuota is ignored when shc_role_quota_enforcement = true

Universal forwarder issues

Date resolved Issue number Description
2017-01-20 SPL-135022, SPL-134112 Unactionable error message for invalid server URIs in outputs.conf.

Data Management Console Issues

Date resolved Issue number Description
2017-01-05 SPL-134591, SPL-134175 The Monitoring Console's "Search Head Clustering: Status & Configuration" page incorrectly calculates cluster-wide search concurrency limits
2017-01-03 SPL-133001 Search Head Clustering: Scheduler Delegation -- Scheduler Delegation Count -- split by "Instance" incorrect
2016-12-13 SPL-133195 Saved search manager page does not honor url context
2016-12-13 SPL-133124 Pagination control does not match results on default page open
2016-12-08 SPL-133192 Edit Acceleration window is empty if you create report with an incorrect search
2016-12-07 SPL-132924 /apps endpoint returns server error during stress test
2016-12-01 SPL-130183 Drilldown search for the "Search scheduler skip ratio" Monitoring Console health-check runs against all time instead of last 60 minutes

Splunk Web and interface issues

Date resolved Issue number Description
2017-01-17 SPL-133902, SPL-132920 Multibyte characters in search bar is broken during typing in Chrome

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2017-04-10 SPL-136983, SPL-105125 If you set a TLS1.2 cipher in web.conf for great browser security, it breaks CLI access to Splunk.

Admin and CLI issues

Date resolved Issue number Description
2017-03-03 SPL-135505, SPL-134343 Admin user sharing a search via the 'Share' button to a non-admin user may result in 'Permission Denied' for user when clicking the link

Unsorted issues

Date resolved Issue number Description
2017-03-06 SPL-92771 On Windows, configuring heavyweight forwarders to send events to indexers that have been configured with SSL and indexer acknowledgment (useACK=true) results in slow-arriving events and some duplicates.

Uncategorized issues

Date resolved Issue number Description
2017-02-22 SPL-135026, SPL-134501 Add validation to transforms.conf DELIMS as it does not support non-ASCII delimiters.
2017-01-13 SPL-134618, SPL-133720 splunkd instrument-resource-usage process uses one full CPU core after upgrade to 6.5.1 on Centos 5
2017-01-05 SPL-133215, SPL-133216, SPL-133217, SPL-133218, SPL-133219 IP location is wrongly mapped in both Splunk Core & ES


6.5.1612

The following issues were fixed in the cloud-only release version 6.5.1612. Splunk Enterprise 6.6.0 delivers these fixes for the first time to on-premises customers.

Data input issues

Date resolved Issue number Description
2016-11-09 SPL-129606, SPL-111204 Splunk 6.3 appears to delete symbolic links
2016-10-26 SPL-129166, SPL-130569, SPL-130811 AWS TA s3 data collection performance degradation in Splunk 6.5.0

Search issues

Date resolved Issue number Description
2016-11-18 SPL-131015, SPL-129846 backslash \ character in search terms outside of quote pairs is not working correctly in search strings in 6.5
2016-11-14 SPL-130888, SPL-130025 Order of Apps in dropdown menu not consistent from Launcher Home
2016-11-14 SPL-131452 Dashboard editor raises a validation warning when "depends" or "rejects" attributes are added to a time input
2016-11-10 SPL-130187, SPL-124997 Dashboard Check Boxes Altered From UI Do Not Alter the Source
2016-11-02 SPL-129907, SPL-131250 Tabs within a dashboard post-process search query cause the search to return no results
2016-10-24 SPL-128639, SPL-126179 MultiSelectInput/MultiDropdownView is crashing Internet Explorer 11

Charting, reporting, and visualization issues

Date resolved Issue number Description
2016-11-18 SPL-131015, SPL-129846 backslash \ character in search terms outside of quote pairs is not working correctly in search strings in 6.5
2016-11-14 SPL-130888, SPL-130025 Order of Apps in dropdown menu not consistent from Launcher Home
2016-11-14 SPL-131452 Dashboard editor raises a validation warning when "depends" or "rejects" attributes are added to a time input
2016-11-10 SPL-130187, SPL-124997 Dashboard Check Boxes Altered From UI Do Not Alter the Source
2016-11-02 SPL-129907, SPL-131250 Tabs within a dashboard post-process search query cause the search to return no results
2016-10-24 SPL-128639, SPL-126179 MultiSelectInput/MultiDropdownView is crashing Internet Explorer 11

Indexer and indexer clustering issues

Date resolved Issue number Description
2016-11-03 SPL-130131 Metadata search command stops reporting results when more than 5 index=... specifiers are used
2016-10-24 SPL-70433 Clustering error "unexpected duplicate app" for apps in both $SPLUNK_HOME/etc/apps and $SPLUNK_HOME/etc/slave-apps.
2016-10-24 SPL-71645 Report acceleration Summary folders (summaryHomePath) cannot be created if thehomePath of the index is at the root of the filesystem, (homePath=D:\myindex orhomePath=/myindex).

Distributed search and search head clustering issues

Date resolved Issue number Description
2016-11-15 SPL-131909, SPL-131030 Clarify fetch_remote_search_log in limits.conf.spec
2016-11-14 SPL-128605, SPL-122602 Memory leak triggered by reloading splunkd SSL servers without restarting the process.
2016-11-14 SPL-131423, SPL-126219, SPL-132795 Log warning when configuration reloads are issued too frequently.
2016-10-25 SPL-121147 Long file path (>255 characters) can break the tarball creation and lead to snapshot creation failure
2016-10-05 SPL-129175, SPL-123853 Show all settings in SHC not functioning properly
2016-06-23 SPL-114079 SHC bootstrap times out on Windows at 40+ nodes, works fine on Linux.

Splunk Web and interface issues

Date resolved Issue number Description
2016-11-14 SPL-130888, SPL-130025 Order of Apps in dropdown menu not consistent from Launcher Home
2016-10-27 SPL-130165, SPL-129870 PDF and CSV attachments don't show up when viewing email on iPhone's default mail application
2016-10-24 SPL-128639, SPL-126179 MultiSelectInput/MultiDropdownView is crashing Internet Explorer 11
2016-10-04 SPL-129362, SPL-129561 Syntax highlighting and other search IDE features fail to work with free license

Rest, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2016-11-09 SPL-128611, SPL-121332 Getting error "'NoneType' object has no attribute '_cafile'" when trying to install an app via the REST API

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2016-11-15 SPL-131337, SPL-94016 Expand TLS Control settings for KV store.
2016-10-07 SPL-128746, SPL-128742, SPL-129878, SPL-129879, SPL-129945 Explicitly disable JavaScript support in KVStore Backend

Admin and CLI issues

Date resolved Issue number Description
2016-11-15 SPL-126746, SPL-122988 Forcing HTTPS on splunkd breaks compatibility with the CLI for reloading auth and deploy-server even enabling an additional localhost-only httpServerListener with SSL disabled.
2016-11-15 SPL-131909, SPL-131030 Clarify fetch_remote_search_log in limits.conf.spec
2016-11-14 SPL-131890, SPL-130822 Splunk startup is delayed by validation of non-essential XML files.

Unsorted issues

Date resolved Issue number Description
2016-11-15 SPL-131337, SPL-94016 Expand TLS Control settings for KV store.
2016-10-07 SPL-128746, SPL-128742, SPL-129878, SPL-129879, SPL-129945 Explicitly disable JavaScript support in KVStore Backend

Uncategorized issues

Date resolved Issue number Description
2016-11-11 SPL-131934, SPL-130646 token value does not reflect a label name in 6.5.0
2016-10-24 SPL-118713 SAML and SSO should be mutually exclusive
2016-10-24 SPL-130182, SPL-126100 Splunk field extraction using delimiter as " (double quote) works in preview but fails to create a valid search extraction
2016-10-24 SPL-128163, SPL-126535 Dashboard replace eval-function does not perform a global replacement
2016-10-13 SPL-119333 SSO setup should not let the user to configure Duo2FA
2016-09-12 SPL-128260 Instrumentation: Opt-in modal not appear when login through proxy/sso
PREVIOUS
6.6.1
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 6.6.0, 6.6.1, 6.6.2, 6.6.3


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters