Splunk® Enterprise

Release Notes

Splunk Enterprise version 9.0 will no longer be supported as of June 14, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.0.1 was released on August 16, 2022. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Authentication and authorization issues

Date resolved Issue number Description
2022-07-19 SPL-224645, SPL-223997 Unnecessary ERROR AuthenticationManagerSplunk message when deleting users

Data input issues

Date resolved Issue number Description
2022-07-14 SPL-226791, SPL-223270 Time format misconfiguration leads to indexer crashes
2022-07-13 SPL-226624, SPL-226408 SmartStore configuration of AWS S3 bucket is rejected with IAM credentials and a custom endpoint
2022-07-11 SPL-226381, SPL-221387 When a non-IAM user sends only `path` as param the UI become non-responsive for approximately 4 mins

Search issues

Date resolved Issue number Description
2022-09-13 SPL-229278 Search crashes with "StatsBuffer found inconsistent row" after upgrading
2022-07-11 SPL-225955, SPL-223099 Job completion emails aren't received while sending the job to background
2022-07-06 SPL-226021, SPL-224456 stash_new files for apps using summary indexes, like ITSI, are not being deleted from splunk/var/spool/splunk because TailReader is hung
2022-06-10 SPL-223099, SPL-225388, SPL-225955 Job completion emails aren't received while sending the job to background

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2022-07-14 SPL-226269 $SPLUNK_HOME/etc/apps/search/local/alert_actions.conf is created when an email is sent via an alert Regression (SPL-194487)
2022-07-11 SPL-225955, SPL-223099 Job completion emails aren't received while sending the job to background
2022-07-08 SPL-224512, SPL-224397 Scheduled alerts with custom actions containing subsearches generate all-time `subsearch_AlertActionsRequredFields` searches, block the scheduler.
2022-06-10 SPL-223099, SPL-225388, SPL-225955 Job completion emails aren't received while sending the job to background

Charting, reporting, and visualization issues

Date resolved Issue number Description
2022-08-04 SPL-226337, SPL-224661 Custom table cell renderer doesn't work consistently on refresh or when switching back from Edit -> Source view
2022-07-13 SPL-222826, SPL-221489 Find search bar in Splunk toolbar only returns Classic dashboards
2022-07-07 SPL-224661, SPL-226337, SPL-230467 Custom table cell renderer doesn't work consistently on refresh or when switching back from Edit -> Source view
2022-04-19 SPL-221489, SPL-222825, SPL-222826 Find search bar in Splunk toolbar only returns Classic dashboards

Indexer and indexer clustering issues

Date resolved Issue number Description
2022-07-15 SPL-226596, SPL-226423 Indexer cluster bundle status stuck in "Bundle Creation is in progress" following error to apply the bundle with message "User '<name>' with roles { <roles> } cannot write".
2022-07-14 SPL-226791, SPL-223270 Time format misconfiguration leads to indexer crashes
2022-07-12 SPL-226423, SPL-226596, SPL-226662, SPL-226829 Indexer cluster bundle status stuck in "Bundle Creation is in progress" following error to apply the bundle with message "User '<name>' with roles { <roles> } cannot write".
2022-07-08 SPL-222872, SPL-221802 Indexer cluster with SmartStore will continue freezing buckets after entering maintenance mode if it started a bucket-freezing cycle before the mode change.
2022-03-28 SPL-221431, SPL-216614 Searchable Rolling Restart stuck reassigning primacy when indexers take more than streaming_replication_wait_secs to roll their buckets when being decommissioned.

Distributed search and search head clustering issues

Date resolved Issue number Description
2022-07-20 SPL-227012, SPL-225689 crashed in NewTransamProcessor NewTransam.cpp:290: bool NewTransaction::isCompatible(SearchResultWrapper&, bool&): Assertion `_opened' failed.
2022-07-08 SPL-225654, SPL-225560 Can't work around slow failure issues in SHC proxied /search/jobs requests because timeouts are not configurable.

Universal forwarder issues

Date resolved Issue number Description
2022-07-15 SPL-226795, SPL-222481, SPL-231443 Splunk UF Windows Event Log Stopped Being Ingested

Uncategorized issues

Date resolved Issue number Description
2022-09-12 SPL-225455 Splunk Assist: On indexer cluster managers, an "Error loading assist: try the operation again or contact Splunk support" message appears
2022-08-09 SPL-227579, SPL-226751 SSG Modular Inputs Stuck in Enable-Disable Loop
2022-07-15 SPL-226855 modify server roles check on splunk-assist
2022-07-14 SPL-225807, SPL-219749 Indicator 'ingestion_latency_gap_multiplier' exceeded configured value.
2022-07-13 SPL-226485, SPL-226400 Queues blocked infinitely with useACK.
2022-07-13 SPL-226248, SPL-217286 Monitoring Console : Runtime Statistics mvexpand command runs into excessive memory usage
2022-07-11 SPL-223791, SPL-221089 realtime search not working with update=true of lookup command when using with subsearches
2022-07-08 SPL-225649, SPL-225490 Splunk's REST API HTTP server can be blocked for long periods of time by internally proxied "/search/jobs" requests.
2022-06-09 SPL-223086 SH/SHC - KVStore restore from a backup created with guaranteed consistency causes unexpected "don't know what to do with file" messages
2022-04-18 SPL-217286, SPL-222648, SPL-226248 Monitoring Console : Runtime Statistics mvexpand command runs into excessive memory usage
Last modified on 14 June, 2023
Field alias behavior change   Deprecated and removed in version 9.0

This documentation applies to the following versions of Splunk® Enterprise: 9.0.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters