Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


Splunk Enterprise version 8.2 is no longer supported as of September 30, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 8.2.8 was released on September 7, 2022. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Authentication and authorization issues

Date resolved Issue number Description
2022-08-19 SPL-227406 Local Splunk logins get logged in audit.log incorrectly
2022-06-09 SPL-224646, SPL-223997 Unnecessary ERROR AuthenticationManagerSplunk message when deleting users

Search issues

Date resolved Issue number Description
2022-09-13 SPL-229278 Search crashes with "StatsBuffer found inconsistent row" after upgrading
2022-08-18 SPL-227729, SPL-226351 Mcatalog subsearch hitting maxout limit preventing metric rollup from populating results correctly.
2022-08-16 SPL-228047, SPL-217977 Splunk crashes on Crashing thread: BucketSummaryActorThread for specific users and searches related to lookups
2022-07-28 SPL-226447, SPL-223897 Mstat breaks with multivalue "asset" dimension,
2022-07-11 SPL-225388, SPL-223099 Job completion emails aren't received while sending the job to background
2022-06-20 SPL-223897, SPL-226446, SPL-226447 Mstat breaks with multivalue "asset" dimension,
2022-06-10 SPL-223099, SPL-225388, SPL-225955 Job completion emails aren't received while sending the job to background
2022-06-05 SPL-223053, SPL-224804, SPL-231441 eventstats will generate less results when time range is large
2022-06-02 SPL-224680, SPL-224870 Remote search process on indexers randomly crash on RunDispatch thread in 8.2.5

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2022-07-14 SPL-226269 $SPLUNK_HOME/etc/apps/search/local/alert_actions.conf is created when an email is sent via an alert Regression (SPL-194487)
2022-07-11 SPL-225388, SPL-223099 Job completion emails aren't received while sending the job to background
2022-06-10 SPL-223099, SPL-225388, SPL-225955 Job completion emails aren't received while sending the job to background
2022-06-09 SPL-220119, SPL-222259, SPL-227226 DMA with custom search command causes acceleration search to crash on the indexers
2022-05-24 SPL-224511, SPL-224397 Scheduled alerts with custom actions containing subsearches generate all-time `subsearch_AlertActionsRequredFields` searches, block the scheduler.
2022-05-16 SPL-222471, SPL-223246 Email Alert: PDF report does not honor "for each results" option and contains multiple results

Charting, reporting, and visualization issues

Date resolved Issue number Description
2022-08-04 SPL-218939 classic new dashboard is not showing data/search results from default token, but the first one on the list
2022-05-05 SPL-223215, SPL-218611, SPL-224947 Drilldown in dashboards works only once for dashboard token update

Data model and pivot issues

Date resolved Issue number Description
2022-06-09 SPL-220119, SPL-222259, SPL-227226 DMA with custom search command causes acceleration search to crash on the indexers

Indexer and indexer clustering issues

Date resolved Issue number Description
2022-06-10 SPL-222958, SPL-213804 DigestProcessor - Failed signature match

Distributed search and search head clustering issues

Date resolved Issue number Description
2022-07-08 SPL-225653, SPL-225560 Can't work around slow failure issues in SHC proxied /search/jobs requests because timeouts are not configurable.

Universal forwarder issues

Date resolved Issue number Description
2022-05-19 SPL-223501, SPL-224109, SPL-224531, SPL-224532 Splunk UF stops forwarding Windows Security events when Windows event log service is restarted

Splunk Web and interface issues

Date resolved Issue number Description
2021-08-31 SPL-207573 The "../" characters are removed from the search string when used through Splunk Web UI.

Windows-specific issues

Date resolved Issue number Description
2022-05-19 SPL-223501, SPL-224109, SPL-224531, SPL-224532 Splunk UF stops forwarding Windows Security events when Windows event log service is restarted

PDF issues

Date resolved Issue number Description
2022-05-16 SPL-222471, SPL-223246 Email Alert: PDF report does not honor "for each results" option and contains multiple results

Uncategorized issues

Date resolved Issue number Description
2022-09-08 SPL-219397, SPL-223028, SPL-229884 Workload Management causing splunkd to hang for minutes when enabled. WorkloadManagementRunnerThread - performMonitoringAction_locked trans.runSync() failed
2022-08-16 SPL-221105, SPL-224813, SPL-226206 Increased memory consumption after upgrade from 8.0.x to 8.2.x when using stats with values()
2022-07-08 SPL-225650, SPL-225490 Splunk's REST API HTTP server can be blocked for long periods of time by internally proxied "/search/jobs" requests.
2022-06-01 SPL-225038, SPL-217161 Verify regressions for jQuery UI to 1.13.0 update
2022-05-12 SPL-221089, SPL-222954, SPL-223791 realtime search not working with update=true of lookup command when using with subsearches
Last modified on 19 May, 2023
PREVIOUS
Field alias behavior change
  NEXT
Deprecated and removed in version 8.2

This documentation applies to the following versions of Splunk® Enterprise: 8.2.8


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters