Splunk® Enterprise

Release Notes

Splunk Enterprise version 8.1 will no longer be supported as of April 19, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 8.1.4 was released on May 11, 2021. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Authentication and authorization issues

Date resolved Issue number Description
2021-04-23 SPL-203946, SPL-204620, SPL-204420, SPL-204691 Extremely huge increase in LDAP query sent from Splunk SHs after upgrade from 8.0.7 to 8.1.3
2021-04-21 SPL-204513, SPL-192277 After upgrade can't modify Metadata XML contents.

Data input issues

Date resolved Issue number Description
2021-03-31 SPL-202163, SPL-195635 Splunkd increased memory usage over time when monitoring UDP port(s) with in inputs.conf
2021-03-29 SPL-202919, SPL-195024 sometimes a HEC bundle reload can introduce HEC server DOS.

Search issues

Date resolved Issue number Description
2021-04-21 SPL-203092, SPL-203190, SPL-204188 Setting server.socket_host in web.conf to 127.0.0.1 on version 8.1.x fail with WARNING: web interface does not seem to be available!
2021-04-21 SPL-204015, SPL-200134 Gradually keep increasing memory usage by splunkd_server after an expensive search is done and then, ended up splunk being killed by oom killer because it hits to the limit about 50 GB memory.
2021-03-23 SPL-202831, SPL-198417 Search & Reporting fails on eventtypes containing macros on deployments with IDXC
2021-03-17 SPL-201924, SPL-200335 Lookup definition with filter not working in Splunk 8.X
2021-03-17 SPL-201979, SPL-200035 Change in mvexpand behavior from 7.3 to 8.0

Indexer and indexer clustering issues

Date resolved Issue number Description
2021-04-21 SPL-204236, SPL-202519 Configuring coldToFrozenScript in indexes.conf does not restart all the indexers in a cluster
2021-03-11 SPL-197930 Splunk 8.1.0 post-upgrade indexer high memory usage with tsidxWritingLevel=4

Universal forwarder issues

Date resolved Issue number Description
2021-03-31 SPL-202163, SPL-195635 Splunkd increased memory usage over time when monitoring UDP port(s) with in inputs.conf
2021-03-24 SPL-198974, SPL-201704, SPL-202998, SPL-202659 AIX: Splunk Universal Forwarder crashing when the scripted input script is failing with an error (ProcessRunner - child's last words: 9cannot find portable_pid_t <tid> in _pidToUni)

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2021-03-09 SPL-201518, SPL-184113 when targetRepositoryLocation is set in a  stanza in serverclass.conf, invalid key error is thrown on startup

Monitoring Console issues

Date resolved Issue number Description
2021-03-23 SPL-201989, SPL-199827 DMC overview is showing N/A
2021-03-11 SPL-201388, SPL-199534 "DMC Alert - Total License Usage Near Daily Quota" does not work in case of fixed-sourcetype license

Splunk Web and interface issues

Date resolved Issue number Description
2021-04-21 SPL-203092, SPL-203190, SPL-204188 Setting server.socket_host in web.conf to 127.0.0.1 on version 8.1.x fail with WARNING: web interface does not seem to be available!
2021-04-08 SPL-203321 Splunk 8.1.* UI Focus jumps to the "Health Status of Splunkd" icon/link
2021-04-01 SPL-201713, SPL-206026, SPL-202687 Main splunkd crashing - thread: TcpChannelThread - Assertion `_redirectReply == REPLY_EATING_NORMAL' failed.

REST, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2021-04-21 SPL-203763, SPL-204069, SPL-204488 savedsearches.conf is not updated after upgrading to 8.1.0 because REST API endpoint is not reloaded.

Admin and CLI issues

Date resolved Issue number Description
2021-04-16 SPL-203821, SPL-182510, SPL-204154 Splunk anonymize will crash in certain Python 2 and Python 3 environments.
2021-04-07 SPL-203309, SPL-199194 ERROR JsonLineBreaker - JSON StreamId:0 had parsing error:Unexpected character while parsing backslash escape: ' '

Uncategorized issues

Date resolved Issue number Description
2021-04-26 SPL-194923 Mongo service stopping with, "immediate exit due to unhandled exception"
2021-03-25 SPL-201348, SPL-198032 MC - Daily License Usage reports pool size incorrectly when filtered by pool
2021-03-16 SPL-201709, SPL-201938, SPL-202422 Command help instruction error
Last modified on 12 August, 2024
Field alias behavior change   Deprecated and removed in version 8.1

This documentation applies to the following versions of Splunk® Enterprise: 8.1.4


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters