Splunk® Enterprise

Release Notes

Splunk Enterprise version 8.1 will no longer be supported as of April 19, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 8.1.3 was released on March 18, 2021. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Authentication and authorization issues

Date resolved Issue number Description
2021-02-26 SPL-201488, SPL-201034 Scripted Auth - cacheTiming config migration is triggered repeatedly under app context

Search issues

Date resolved Issue number Description
2021-02-24 SPL-198241, SPL-198094 srchTimeWin not effective if earliest= is used in query
2021-02-19 SPL-201160, SPL-198279 Search crashes with Segmentation Fault when slow_peer_disconnect is enabled
2021-02-09 SPL-199538, SPL-200107 Use of lookup eval function causes crash of splunkd and splunkweb
2021-02-02 SPL-199443, SPL-198891 Search head instances in SHC not able to run Web UI searches (i.e. index=_internal or index=<foo>)
2021-02-02 SPL-199440, SPL-198755 False positive indexed_kv_limit related warning "The search you ran returned a number of fields that exceeded the current indexed field extraction limit."
2021-02-01 SPL-199337, SPL-199928 ProcessDispatchedSearch - PROCESS_SEARCH - Failed opening "": No such file or directory

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2021-02-24 SPL-201299, SPL-192339, SPL-201683 Continuously scheduled searches are not running.
2021-02-22 SPL-201182, SPL-200328, SPL-201232 Scheduler rerunning previously successful scheduled searches.

Distributed search and search head clustering issues

Date resolved Issue number Description
2021-02-25 SPL-200357, SPL-198850 ScriptedAuthentication: UPGR 7.3.5 >> 8.0.7 Saved Searches in User Directories not Executing
2021-02-24 SPL-201299, SPL-192339, SPL-201683 Continuously scheduled searches are not running.
2021-02-01 SPL-199337, SPL-199928 ProcessDispatchedSearch - PROCESS_SEARCH - Failed opening "": No such file or directory

Indexer and indexer clustering issues

Date resolved Issue number Description
2021-02-17 SPL-198272, SPL-192216 Show detailed log message when Workload failed moving processes to cgroups.
2021-02-01 SPL-199337, SPL-199928 ProcessDispatchedSearch - PROCESS_SEARCH - Failed opening "": No such file or directory

Universal forwarder issues

Date resolved Issue number Description
2021-03-05 SPL-199409, SPL-204579, SPL-199691 Windows EventLog SIDs no longer resolving after upgrade to 8.1

Windows-specific issues

Date resolved Issue number Description
2021-03-05 SPL-199409, SPL-204579, SPL-199691 Windows EventLog SIDs no longer resolving after upgrade to 8.1

Uncategorized issues

Date resolved Issue number Description
2021-03-02 SPL-199608, SPL-200661 Indexer is not starting up because of locktest failure after upgrade to 8.1.0
2021-02-26 SPL-199897, SPL-200082 Splunk Analytics for Hadoop and Hadoop Data Roll MapReduce-based (report-/mix-mode) searches fail
2021-02-26 SPL-200571, SPL-198354 SmartStore: Ungraceful shutdown can cause re-upload, overwriting the existing remote bucket
2021-02-10 SPL-200154, SPL-194635 SmartStore starts new upload jobs as soon as the current job failed with no back off
2021-02-09 SPL-198714, SPL-199317, SPL-199494, SPL-199495 tcp-ssl input stanza individual ssl certificates not working as documented
2021-01-31 SPL-199561, SPL-198752 Index time extraction length limitation
Last modified on 12 August, 2024
Field alias behavior change   Deprecated and removed in version 8.1

This documentation applies to the following versions of Splunk® Enterprise: 8.1.3


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters