Fixed issues
Splunk Enterprise 8.0.1 was released on December 12, 2019. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.
Data input issues
Date resolved
|
Issue number
|
Description
|
2019-11-14 |
SPL-178916, SPL-171961 |
The datetime.xml timestamp recognition file does not recognize two-year dates after 2019 or Unix epoch-time seconds higher than 1599999999 (12:26:39 UTC 13 Sep 2020)
|
2019-11-14 |
SPL-178638, SPL-147902 |
Frequent renaming of splunkd.pid.tmp to splunkd.pid causing D state for process runner.
|
Search issues
Date resolved
|
Issue number
|
Description
|
2019-11-15 |
SPL-179157, SPL-176046 |
Lookup overwrites source filed when OUTPUTNEW is used in search
|
2019-11-14 |
SPL-179594, SPL-177665 |
tstats where clause does not filter as expected when structured like "WHERE * NOT (field1=foo AND field2=bar)"
|
2019-11-13 |
SPL-179202, SPL-178149 |
Wrong output of stats caused by incorrect value of _tmpResultsDir
|
2019-11-12 |
SPL-178263, SPL-176921 |
Search results not returned intermittently for _indextime search on hot bucket, results are found on later searches (Windows platform only).
|
2019-11-08 |
SPL-178625, SPL-177844 |
"tostring" function doesn't add a leading zero when using the duration format in 7.2.x
|
2019-11-08 |
SPL-177851, SPL-164106 |
export results function in the UI produces "Invalid latest_time: latest_time must be after earliest_time" message
|
2019-10-24 |
SPL-176009, SPL-166728 |
Alert email spacing issue
|
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2019-11-15 |
SPL-179612, SPL-173414 |
Splunk unable to load defined Saved Searches in a conf file if a bad/malformed cron_schedule value is present/set
|
2019-11-08 |
SPL-178522, SPL-173502 |
Windows - Alert Triggered Time displays GMT despite Local Time set as AEST for Alert Owner in Preferences
|
2019-11-07 |
SPL-177933, SPL-176477 |
action.email.pdf.logo_path in savedsearches.conf doesn't work
|
2019-11-07 |
SPL-177905, SPL-175886 |
Creating report from alert also copies alert trigger condition settings
|
2019-10-24 |
SPL-176009, SPL-166728 |
Alert email spacing issue
|
Charting, reporting, and visualization issues
Date resolved
|
Issue number
|
Description
|
2019-11-08 |
SPL-179171, SPL-178113 |
Editing color scale using colorpalette in dashboard creates custom configuration
|
2019-11-07 |
SPL-179167, SPL-178012 |
Dashboard having post-process search without <query> element is not loading
|
Indexer and indexer clustering issues
Date resolved
|
Issue number
|
Description
|
2019-11-21 |
SPL-180014, SPL-175926 |
S2 Smartstore :Indexer cluster not recovering when decommissioning indexers greater than or equal to SF/RF
|
2019-11-14 |
SPL-178413, SPL-155281 |
Indexer Clustering Search Performance - search manifest updates should be locked per site+genid
|
Monitoring Console/DMC issues
Date resolved
|
Issue number
|
Description
|
2019-11-08 |
SPL-140654, SPL-178056 |
wrong integrity check alert for file etc/users/users.ini
|
Splunk Web and interface issues
Date resolved
|
Issue number
|
Description
|
2019-11-14 |
SPL-176739, SPL-176234 |
Lookup file Permissions displays the csv filename instead of app name
|
2019-10-24 |
SPL-176009, SPL-166728 |
Alert email spacing issue
|
Authentication and Authorization issues
Date resolved
|
Issue number
|
Description
|
2019-11-25 |
SPL-180079, SPL-179933 |
SAML Failure after upgrade to 7.0.13 - ERROR UiSAML - Malformed SAML document(Assertion) received from IDP
|
2019-11-08 |
SPL-177707, SPL-174145 |
CSRF token failure on timeout, multiple browser tabs constantly reauthenticating
|
Admin and CLI issues
Date resolved
|
Issue number
|
Description
|
2019-11-15 |
SPL-179612, SPL-173414 |
Splunk unable to load defined Saved Searches in a conf file if a bad/malformed cron_schedule value is present/set
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2019-11-15 |
SPL-179496, SPL-179347 |
msearch: multi-valued fields are not extracted properly
|
2019-11-14 |
SPL-177925, SPL-176230 |
HealthReporter threads deadlock resulting in stuck _reload, blocked ingestion, eventually causing a crash
|
2019-11-11 |
SPL-178767, SPL-149157 |
Missing some meta keys extracted by INDEXED_EXTRACTION after changing _raw content and adding index-time field extraction
|
2019-11-08 |
SPL-176751, SPL-174948 |
Indexers in Cluster having problems utilizing AWS storage gateway for cold storage
|
2019-11-08 |
SPL-178124, SPL-177659 |
Embedding base64 image in dashboard is not displayed
|
2019-11-07 |
SPL-178138, SPL-176190 |
Count option is not working when it is set with a token
|
2019-10-29 |
SPL-177847, SPL-176142 |
IOStats events for introspection occasionally reports negative avg_total_ms
|
Splunk Analytics Workspace
Date resolved
|
Issue number
|
Description
|
2019-11-05 |
MAW-3135, MAW-3060 |
Email options for streaming alert creation does not result in expected email content
|
Feedback submitted, thanks!