Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


Splunk Enterprise version 8.2 is no longer supported as of September 30, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 8.2.1 was released on June 22, 2021. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Authentication and authorization issues

Date resolved Issue number Description
2021-05-20 SPL-205257, SPL-203901 Settings in Authentication Extension cause SH to crash
2021-05-18 SPL-205256, SPL-204519 SAML Scripted Auth Extensions login() function uses wrong assertion attribute

Upgrade issues

Date resolved Issue number Description
2021-05-26 SPL-206076, SPL-198052 Upgrading From 8.0.6 to 8.1.0.1 Using a DEB package results in a No such file or directory message.

Data input issues

Date resolved Issue number Description
2021-03-09 SPL-195635, SPL-202178, SPL-206477, SPL-202163, SPL-206534 Splunkd increased memory usage over time when monitoring UDP port(s) with in inputs.conf

Search issues

Date resolved Issue number Description
2021-05-28 SPL-206367, SPL-204793 REST API search fails on 8.1.3, completes on 7.2.6
2021-05-27 SPL-206079, SPL-206048 Search on ES hangs.
2021-05-26 SPL-205975, SPL-205542 SPL command "iplocation" info is out of date
2021-05-26 SPL-205383, SPL-203915 The warning about lookup expansion failure due to a reference cycle is not actionable
2021-05-25 SPL-204188, SPL-203092 Setting server.socket_host in web.conf to 127.0.0.1 on version 8.1.x fail with WARNING: web interface does not seem to be available!
2021-05-25 SPL-206031, SPL-198417 Search & Reporting fails on eventtypes containing macros on deployments with IDXC
2021-05-25 SPL-204131, SPL-200134 Gradually keep increasing memory usage by splunkd_server after an expensive search is done and then, ended up splunk being killed by oom killer because it hits to the limit about 50 GB memory.

Charting, reporting, and visualization issues

Date resolved Issue number Description
2021-05-14 SPL-204934, SPL-201506 strptime function in drilldown does not convert 3 digit millisecond values and shows NAN

Indexer and indexer clustering issues

Date resolved Issue number Description
2021-05-25 SPL-204235, SPL-202519 Configuring coldToFrozenScript in indexes.conf does not restart all the indexers in a cluster

Distributed search and search head clustering issues

Date resolved Issue number Description
2021-05-26 SPL-205383, SPL-203915 The warning about lookup expansion failure due to a reference cycle is not actionable

Universal forwarder issues

Date resolved Issue number Description
2021-05-27 SPL-202998, SPL-198974 AIX: Splunk Universal Forwarder crashing when the scripted input script is failing with an error
2021-03-09 SPL-195635, SPL-202178, SPL-206477, SPL-202163, SPL-206534 Splunkd increased memory usage over time when monitoring UDP port(s) with in inputs.conf

Monitoring Console issues

Date resolved Issue number Description
2021-06-01 SPL-202027 On Search Heads, Search Head Clusters, & Cluster Manager where Monitoring Console is not set to Distributed Mode, the Health Report UI is missing features that exist only on non-local Splunk instances

Splunk Web and interface issues

Date resolved Issue number Description
2021-05-25 SPL-206026, SPL-201713 Main splunkd crashing - thread: TcpChannelThread - Assertion `_redirectReply == REPLY_EATING_NORMAL' failed.
2021-05-25 SPL-204188, SPL-203092 Setting server.socket_host in web.conf to 127.0.0.1 on version 8.1.x fail with WARNING: web interface does not seem to be available!

REST, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2021-05-21 SPL-204488, SPL-203763 savedsearches.conf is not updated after upgrading to 8.1.0 because REST API endpoint is not reloaded.

Admin and CLI issues

Date resolved Issue number Description
2021-05-21 SPL-203308, SPL-199194 ERROR JsonLineBreaker - JSON StreamId:0 had parsing error:Unexpected character while parsing backslash escape: ' '

Uncategorized issues

Date resolved Issue number Description
2021-05-27 SPL-206282, SPL-204489 Many events from internal logs are directed to malformedEventIndex
2021-05-25 SPL-205068, SPL-204207 Federated Search: Federated indexes do not support names that include capital letters
2021-05-23 SPL-205549, SPL-194082 idle_s3_http_client thread crashes splunkd on indexers due to remotestore connectivity issues.
Last modified on 13 August, 2022
PREVIOUS
Field alias behavior change
  NEXT
Deprecated and removed in version 8.2

This documentation applies to the following versions of Splunk® Enterprise: 8.2.1


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters