Splunk® Enterprise

Release Notes

This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.1.1 was released on August 30, 2023. This release includes fixes for the following issues. It also delivers relevant updates from the 2023-08-30 Security Advisories list.

Issues are listed in all relevant sections. Some issues might appear more than once.

Search issues

Date resolved Issue number Description
2023-07-11 SPL-241706, SPL-240758 "File Integrity checks found 4281 files that did not match the system-provided manifest." shows in message but does not appear in the "Integrity Check of Installed Files" dashboard.
2023-07-11 SPL-241705, SPL-240758 "File Integrity checks found 4281 files that did not match the system-provided manifest." shows in message but does not appear in the "Integrity Check of Installed Files" dashboard.
2023-04-06 SPL-231830, SPL-239319, SPL-239320 SearchJob sometimes fails and returns error "Search <ID> not found. The search may have been cancelled while there are still subscribers"

Federated search issues

Date resolved Issue number Description
2023-09-25 SPL-241291, SPL-239293 Transparent Mode Federated Search: Check to turn off forwarding DMA or RA summarization search runs causes federated searches to fail
2023-06-21 SPL-239293, SPL-241291 Transparent Mode Federated Search: Check to turn off forwarding DMA or RA summarization search runs causes federated searches to fail
2023-05-04 SPL-239362, SPL-237883 Transparent Mode federated search - Using table and stats in the same federated search causes the search to return empty results , when run in smart or fast mode

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2023-09-25 SPL-241291, SPL-239293 Transparent Mode Federated Search: Check to turn off forwarding DMA or RA summarization search runs causes federated searches to fail
2023-06-21 SPL-239293, SPL-241291 Transparent Mode Federated Search: Check to turn off forwarding DMA or RA summarization search runs causes federated searches to fail

Charting, reporting, and visualization issues

Date resolved Issue number Description
2023-06-22 SPL-240082, SPL-241349, SPL-241350 Classic Simple XML dashboards with HTML panels using external images and tokens show the error "Awaiting User Confirmation".
2023-06-20 SPL-240966, SPL-241284, SPL-241285 Classic Simple XML dashboards parsing error: "Cannot convert undefined or null to object"

Distributed search and search head clustering issues

Date resolved Issue number Description
2023-07-13 SPL-241836, SPL-218169 For alerts with per-result throttling (suppression) in SHC, sometimes, based on timing, the originating SH that ran the seach will show different results (suppressed) than the replicated artefacts on other SHs (unsuppressed)
2023-07-12 SPL-218169, SPL-241835, SPL-241836 For alerts with per-result throttling (suppression) in SHC, sometimes, based on timing, the originating SH that ran the seach will show different results (suppressed) than the replicated artefacts on other SHs (unsuppressed)

Data model and pivot issues

Date resolved Issue number Description
2023-09-25 SPL-241291, SPL-239293 Transparent Mode Federated Search: Check to turn off forwarding DMA or RA summarization search runs causes federated searches to fail
2023-06-21 SPL-239293, SPL-241291 Transparent Mode Federated Search: Check to turn off forwarding DMA or RA summarization search runs causes federated searches to fail

Universal forwarder issues

Date resolved Issue number Description
2023-08-30 SPL-242093, SPL-242240 At upgrade, the Linux RPM/DEB installer creates a default "splunkfwd" account, causing issues when Splunk is already managed by another account
2023-08-08 SPL-240820, SPL-242100, SPL-242101, SPL-242102, SPL-242103 Windows EventLog splunk-winevtlog.exe modular input crashing during AD object resolution

Splunk Web and interface issues

Date resolved Issue number Description
2023-07-11 SPL-241706, SPL-240758 "File Integrity checks found 4281 files that did not match the system-provided manifest." shows in message but does not appear in the "Integrity Check of Installed Files" dashboard.
2023-07-11 SPL-241705, SPL-240758 "File Integrity checks found 4281 files that did not match the system-provided manifest." shows in message but does not appear in the "Integrity Check of Installed Files" dashboard.
2023-04-06 SPL-231830, SPL-239319, SPL-239320 SearchJob sometimes fails and returns error "Search <ID> not found. The search may have been cancelled while there are still subscribers"

Windows-specific issues

Date resolved Issue number Description
2023-08-08 SPL-240820, SPL-242100, SPL-242101, SPL-242102, SPL-242103 Windows EventLog splunk-winevtlog.exe modular input crashing during AD object resolution

Uncategorized issues

Date resolved Issue number Description
2023-05-23 SPL-234643 Splunkd abort - due to 3rd party S2S client unable to process ACKs.
Last modified on 17 November, 2023
Field alias behavior change   Deprecated and removed in version 9.1

This documentation applies to the following versions of Splunk® Enterprise: 9.1.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters