Splunk Stream

Release Notes

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk Stream. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Known issues

Known issues in Splunk App for Stream 6.0:

Defect number Description
STREAM-2268 imap "password" field is missing.
STREAM-2222 Stream tries to open pcap adapter on inactive interface.
STREAM-2193 The stream id (labeled 'Name' in the Configure Streams UI) is case sensitive. This lets you create a stream with the same name as a default stream, for example, id "HTTP", which you can confuse with the default stream id "http."
STREAM-2190 Stream Forwarder skips IP packets with zero length (ip.len==0) in the IP header.
STREAM-2183 request_time, reply_time, and response_time flow metrics are not populated for all protocols.
STREAM-2179 Sparkline in Configure Streams UI under certain circumstances incorrectly shows zero traffic volume for protocols.
STREAM-2169 SSL key stored in local/directory.
STREAM-2156 streamfwd process may exhibit unbounded memory growth when running on Splunk Universal Forwarder instance that is unable to forward events, most commonly because of incorrect tcpout parameters in outputs.conf configuration.
STREAM-1909 SNMP events not returning key pieces of data due to lack of parsing from original binary format.
STREAM-1834 Inefficient captured packet queueing.
STREAM-1128 depedency_manager.py conflicts with Unix App. When you install Splunk App for Stream on a system that runs Splunk App for Unix, the dependency_manager.py script that comes with App for Stream conflicts with the dependency_manager.py script that comes the Unix app. This prevents Splunk from running the script and breaks the Splunk_TA_stream install process. Workaround: Manually copy the Splunk_TA_stream directory from $SPLUNK_HOME/etc/deployment-apps to $SPLUNK_HOME/etc/apps on your forwarder, as shown in this troublehooting item.
STREAM-1138 When running App for Stream on Splunk Enterprise 6.0: On the Configure Streams page, when you click Add and select a comparison from the drop-down, the filters modal dialog disappears. This forces you to reload the page and makes it impossible to configure filters.
STREAM-1097 dns.response_time returns a timestamp. dns.response_time should be an integer.
STREAM-115 On the Configure Streams page, exiting a modal by clicking on the backdrop instead of cancel causes issues between the different modals. Clicking on the backdrop removes the modal, but then when you open a different modal the old modal is stacked on top.
Last modified on 22 October, 2015
  NEXT
Fixed Issues

This documentation applies to the following versions of Splunk Stream: 6.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters