Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


Splunk Enterprise version 8.0 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 8.0.4.1

Splunk Enterprise 8.0.4.1 was released on June 9, 2020. This release fixes the following issue:

Date resolved Issue number Description
2020-05-27 SPL-185514, ADDON-26828 Addons unable to load UI or collect data on Splunk Enterprise 8.0.4.

Splunk Enterprise 8.0.4

Splunk Enterprise 8.0.4 was released on May 21, 2020. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Data input issues

Date resolved Issue number Description
2020-04-06 SPL-185132, SPL-143408 CHARSET=AUTO does not convert

Search issues

Date resolved Issue number Description
2020-04-28 SPL-186537, SPL-185417 Specific Search Crashes After Returning Few Results
2020-04-28 SPL-184546, SPL-153652 srchTimeWin in authorize.conf not applied (when et,lt is specified in the search string) to Fast or Smart or Verbose mode search when configured
2020-04-28 SPL-186001, SPL-183436 Index Time Extraction Padding Checksum
2020-04-27 SPL-183344, SPL-186261 UI bug - The number of excess buckets clusterwide is not shown on the UI
2020-04-24 SPL-186424, SPL-185211 indexed_kv_limit related warning messages
2020-04-23 SPL-185943 Timechart for values with wildcard and by argument doesn't give any result
2020-04-21 SPL-186669, SPL-180741 Clarification of expected behavior with subsearch
2020-04-15 SPL-186357, SPL-184352 No more "Wrap results" option when using "Show source" in 8.0+
2020-04-14 SPL-186235, SPL-181035 alert.expires can't be used to set default alert expiry for new alerts
2020-04-14 SPL-185915, SPL-184106 User with neither READ nor WRITE permission can still use `outputlookup` to overwrite existing on-disk CSV lookup file
2020-04-13 SPL-185796, SPL-185555 Realtime search breaks when customizing server.conf
2020-04-13 SPL-183750, SPL-181801 | delete command may generate unnecessary errors when SmartStore cache is under pressure
2020-04-13 SPL-180882, SPL-184741, SPL-185940 Searches are slow to finish with high startup.handoff times
2020-04-06 SPL-184392, SPL-185102, SPL-185145, SPL-192489 Any jobs starting with subsearch_ will return a 403 when requested from the jobs endpoint, for example "| sendemail" from within "|map" search fails with " Client is not authorized to perform requested action" in python.log
2020-04-02 SPL-185692, SPL-185078 update MaxMind GeoLite2-City DB to latest version 20200317
2020-03-30 SPL-184348, SPL-184601, SPL-185393, SPL-185394 Splunk returns no results after adding field extractions without capturing group in REGEX when using FORMAT field::value
2020-03-20 SPL-184937, SPL-183884 Simple XML dashboards with base searches don't report results correctly in version 8+
2020-03-19 SPL-182511, SPL-183265 split() on an empty string results in typeof(field) = Invalid and a "| mvexpand" will then not return that event
2020-03-17 SPL-183947, SPL-184689 Search process crashes on idx processing lookup in FAST mode
2020-03-11 SPL-182918, SPL-183963 Raw events are not shown in verbose mode in stats command coming after table command
2020-03-11 SPL-184707, SPL-179445 custom.xml in default/data/ui/nav breaks navigation bar in other apps

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2020-04-17 SPL-184327, SPL-184806, SPL-185856 Accelerated Report summaries not being used
2020-04-14 SPL-186235, SPL-181035 alert.expires can't be used to set default alert expiry for new alerts
2020-04-07 SPL-185212, SPL-178252 DMA consuming much more RAM after upgrade 7.X

Charting, reporting, and visualization issues

Date resolved Issue number Description
2020-04-14 SPL-182027, SPL-185738, SPL-186302 Drilldown tokens with filters are not working when entered through the UI (the "|" pipe symbol is encoded as %7C)
2020-04-02 SPL-185581, SPL-185142 Can Not Open In Search From Dashboard Panel
2020-03-16 SPL-183301, SPL-181931 Drilldown is not working if search string contains & or ?

Data model and pivot issues

Date resolved Issue number Description
2020-04-07 SPL-185212, SPL-178252 DMA consuming much more RAM after upgrade 7.X

Indexer and indexer clustering issues

Date resolved Issue number Description
2020-04-28 SPL-186340, SPL-184899 Data rebalance performance issues in a large indexer cluster
2020-04-02 SPL-184957, SPL-183290 (Quake) - Using REST or CLI to validate and apply bundle causes peers to restart twice
2020-03-13 SPL-183949, SPL-181945 Rebalancing isn't completing due to missing cold buckets

Distributed search and search head clustering issues

Date resolved Issue number Description
2020-04-24 SPL-185654, SPL-184281 Explanation for user-prefs replication and option to disable these.
2020-04-20 SPL-186584, SPL-175689 Enhancing error message for SH heartbeat lost
2020-04-09 SPL-181074, SPL-177889 Events found but not displayed, eventstats some events been ignored occasionally

Universal forwarder issues

Date resolved Issue number Description
2020-03-31 SPL-185540, SPL-183953 Batch Stanza deleting file upon restart/read completion

Splunk Web and interface issues

Date resolved Issue number Description
2020-04-28 SPL-186537, SPL-185417 Specific Search Crashes After Returning Few Results
2020-04-28 SPL-184546, SPL-153652 srchTimeWin in authorize.conf not applied (when et,lt is specified in the search string) to Fast or Smart or Verbose mode search when configured
2020-04-28 SPL-186001, SPL-183436 Index Time Extraction Padding Checksum
2020-04-27 SPL-183344, SPL-186261 UI bug - The number of excess buckets clusterwide is not shown on the UI
2020-04-24 SPL-186424, SPL-185211 indexed_kv_limit related warning messages
2020-04-23 SPL-185943 Timechart for values with wildcard and by argument doesn't give any result
2020-04-21 SPL-186669, SPL-180741 Clarification of expected behavior with subsearch
2020-04-15 SPL-186357, SPL-184352 No more "Wrap results" option when using "Show source" in 8.0+
2020-04-14 SPL-186235, SPL-181035 alert.expires can't be used to set default alert expiry for new alerts
2020-04-14 SPL-185915, SPL-184106 User with neither READ nor WRITE permission can still use `outputlookup` to overwrite existing on-disk CSV lookup file
2020-04-13 SPL-185796, SPL-185555 Realtime search breaks when customizing server.conf
2020-04-13 SPL-183750, SPL-181801 | delete command may generate unnecessary errors when SmartStore cache is under pressure
2020-04-13 SPL-180882, SPL-184741, SPL-185940 Searches are slow to finish with high startup.handoff times
2020-04-06 SPL-184392, SPL-185102, SPL-185145, SPL-192489 Any jobs starting with subsearch_ will return a 403 when requested from the jobs endpoint, for example "| sendemail" from within "|map" search fails with " Client is not authorized to perform requested action" in python.log
2020-04-02 SPL-185692, SPL-185078 update MaxMind GeoLite2-City DB to latest version 20200317
2020-03-30 SPL-184348, SPL-184601, SPL-185393, SPL-185394 Splunk returns no results after adding field extractions without capturing group in REGEX when using FORMAT field::value
2020-03-20 SPL-184937, SPL-183884 Simple XML dashboards with base searches don't report results correctly in version 8+
2020-03-19 SPL-182511, SPL-183265 split() on an empty string results in typeof(field) = Invalid and a "| mvexpand" will then not return that event
2020-03-17 SPL-183947, SPL-184689 Search process crashes on idx processing lookup in FAST mode
2020-03-11 SPL-182918, SPL-183963 Raw events are not shown in verbose mode in stats command coming after table command
2020-03-11 SPL-184707, SPL-179445 custom.xml in default/data/ui/nav breaks navigation bar in other apps

REST, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2020-04-02 SPL-184957, SPL-183290 (Quake) - Using REST or CLI to validate and apply bundle causes peers to restart twice

Authentication and authorization issues

Date resolved Issue number Description
2020-04-08 SPL-185714, SPL-183142 Session token generated in JWT/Bearer token-based call cannot be used to auth rest calls

PDF issues

Date resolved Issue number Description
2020-03-22 SPL-183655, SPL-184809 re-add patch for reportlab-3.5 to use SHA-1 in preference to MD5

Admin and CLI issues

Date resolved Issue number Description
2020-03-17 SPL-184331, SPL-179501 Some page at "Settings > All Configurations" throws 404 ERROR

Uncategorized issues

Date resolved Issue number Description
2020-04-24 SPL-186483, SPL-184315 Search Head Cluster Member appending splunk.secret with contents from memory
2020-04-20 SPL-183467, SPL-183647 It is not possible to use custom python on Universal Forwarder breaking scripted inputs for example
2020-04-17 SPL-186351, SPL-186282 DMA rebuild is causing random indexer crashes
2020-04-09 SPL-185962, SPL-181222 SummaryDirector for Authentication DMA has incorrect search
2020-04-02 SPL-185141, SPL-170326 HTTP Event Collector sporadically fails to index JSON extractions when "Tried to set INDEXED_EXTRACTIONS but it already had a value!" error occurs.
2020-04-01 SPL-183003, SPL-183000 diag cannot get index listings for UNC paths
2020-03-23 SPL-184463, SPL-184961 Multiple timezone indexer cluster - timechart span=1d snaps to multiple hours
2020-03-18 SPL-184962, SPL-183477 MC: Health Check page stuck in "Loading..." when Forwarder license is used
2020-03-11 SPL-184618, SPL-184144 500 Internal Server Error while opening several pages in Splunk GUI
Last modified on 11 February, 2021
PREVIOUS
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
  NEXT
Deprecated and removed in version 8.0

This documentation applies to the following versions of Splunk® Enterprise: 8.0.4


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters