Splunk® Enterprise

Release Notes

Splunk Enterprise version 7.3 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 7.3.8 was released on November 12, 2020. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Authentication and authorization issues

Date resolved Issue number Description
2020-10-28 SPL-195586, SPL-196213, SPL-196619, SPL-196620 Linux 7.2.4.2 SHC + Duo Security 2FA - Authentication - login fails when using a custom root_endpoint
2020-10-09 SPL-190298, SPL-191781, SPL-194287, SPL-194288 SAML - unable to update idpCerts via idpCertChain text box in SHC with replicate certificates enabled

Upgrade issues

Date resolved Issue number Description
2020-10-30 SPL-195414, SPL-195992, SPL-196903, SPL-197918 Custom Navigation Menus Lost When Upgrading Splunk from 7.3.6 to 7.3.7

Search issues

Date resolved Issue number Description
2020-10-29 SPL-193845, SPL-194117, SPL-196222, SPL-196223 Bucket that rolled during search execution contained events missing from results
2020-10-29 SPL-196392, SPL-194368 Linux 8.0.3 autoloadbalanced SHC + IDX cluster - Admin Cli - many random searches are crashing after upgrade
2020-10-14 SPL-196152, SPL-194016 search optimizer causing some search condition to be missing in remote search for searches including multiple wildcarded terms for the same field
2020-10-08 SPL-193949, SPL-194568, SPL-195123, SPL-195126 search process throws exception with "ERROR SearchEvaluatorBasedExpander - Caught exception during filter to index expansion - unbalanced parentheses"
2020-09-11 SPL-194286, SPL-191472 Getting Security ID value equal to NONE_MAPPED for Member for the EventCode = 4732
2020-09-03 SPL-193073, SPL-194540, SPL-193598, SPL-194536 reverse lookup shows inconsistent behaviors
2020-08-05 SPL-193144, SPL-191605 fields command being run before streamstats in search causing incorrect results

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2020-08-26 SPL-194252, SPL-193332 After upgrade , the splunk user needs the "admin_all_objects" capability to send email alert

Charting, reporting, and visualization issues

Date resolved Issue number Description
2020-08-20 SPL-193476, SPL-192954 Post 7.3.4 upgrade regression: SimpleXML: <selectFirstChoice> causes browser hang, cpu spike, when value is set to 'true'

Indexer and indexer clustering issues

Date resolved Issue number Description
2020-10-19 SPL-194863, SPL-195264, SPL-196334, SPL-196335 During indexer cluster searchable rolling restart, indexer was stuck in ReassigningPrimaries
2020-09-11 SPL-194552, SPL-193066 Deserialization failed. val for key=indexing_disk_space is not a valid unsigned long long number.
2020-09-02 SPL-190111, SPL-90688 Platform alert "DMC Alert - Search Peer Not Responding" will never trigger for cluster peers who are down because clustering doesn't track peers in this state

Distributed search and search head clustering issues

Date resolved Issue number Description
2020-09-02 SPL-190111, SPL-90688 Platform alert "DMC Alert - Search Peer Not Responding" will never trigger for cluster peers who are down because clustering doesn't track peers in this state

Monitoring Console issues

Date resolved Issue number Description
2020-09-02 SPL-190111, SPL-90688 Platform alert "DMC Alert - Search Peer Not Responding" will never trigger for cluster peers who are down because clustering doesn't track peers in this state

Splunk Web and interface issues

Date resolved Issue number Description
2020-09-11 SPL-194286, SPL-191472 Getting Security ID value equal to NONE_MAPPED for Member for the EventCode = 4732
2020-09-11 SPL-194801, SPL-188395, SPL-194413 WebUI is not Returning Proper Bundle Validation-Restart check when there is a "Not Critical" error

Uncategorized issues

Date resolved Issue number Description
2020-10-25 SPL-196439, SPL-195411 Redundant absent summary cachemanager open calls.
2020-10-23 SPL-193426, SPL-191436 Diag needs updating so it obfuscates or removes values for remote.s3.kms.key_id values
Last modified on 03 May, 2023
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020   Deprecated and removed in version 7.3

This documentation applies to the following versions of Splunk® Enterprise: 7.3.8


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters