Release notes for the Splunk Add-on for Unix and Linux
Version 8.3.0 of the Splunk Add-on for Unix and Linux was released on February 3, 2021.
Version 8.3.0 of the Splunk Add-on for Unix and Linux is compatible with the following software, CIM versions, and platforms:
|Splunk platform versions||7.2.x, 7.3.x, 8.0.x, 8.1.x|
|Supported OS for data collection||All supported Unix operating systems. See Unix operating systems.|
|Vendor products||All supported Unix operating systems. See Unix operating systems.|
See the Scripted input reference for the Splunk Add-on for Unix and Linux page in the Reference chapter of this manual to learn more about scripted inputs and their operating system compatibility.
The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.
For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.
Version 8.3.0 of the Splunk Add-on for Unix and Linux has the following new features:
- Support of CentOS 8, RHEL 8.3, Solaris 11.4, Ubuntu 20.10, FreeBSD 12.2, macOS 10.15
- Common Information Model (CIM) version 4.18 compatibility
- Enhanced CIM mappings and extractions for 'linux_secure' and 'aix_secure' sourcetypes
- Enhanced CIM mappings and extractions for 'dhcpd' sourcetype
- Mapped Endpoint.FileSystem data model to 'fs_notification' sourcetype
- Mapped Performance.CPU data model to 'ps' sourcetype
- Mapped Perfomance.Storage data model to 'nfsiostat' sourcetype
- Mapped Endpoint.Ports data model to 'netstat' sourcetype
- Removed DM mappings from 'top' and 'Unix:ListeningPorts' sourcetypes
- Added the
reasonCIM field for the 'Authentication.Failed_Authentication' data model
Version 8.3.0 of the Splunk Add-on for Unix and Linux has the following fixed issues:
|Date resolved||Issue number||Description|
|2021-01-28||ADDON-31685||The 'top.sh' script that Splunk_TA_nix app uses does not correctly extract the fields of the 'top' linux command in FreeBSD|
Version 8.3.0 of the Splunk Add-on for Unix and Linux has the following known issues. If no issues appear here, no issues have yet been reported:
|Date filed||Issue number||Description|
|2021-01-20||ADDON-33139||Input netstat.sh and openPorts.sh gives error in splunkd.log when add-on is installed on macOS v10.15.7|
|2020-06-18||ADDON-27321||nfsiostat.sh fails with ImportError: This package should not be accessible on Python 3|
|2020-04-24||ADDON-26293||Field values gets broke when values has space for 'lsof' and 'userswithloginprivs' source types|
|2020-04-24||ADDON-26292||Additional error of broken pipe is getting logged under splunkd.log along with correct data for cpu.sh on Solaris OS|
|2020-04-20||ADDON-26130||When there is no new data available to be ingested in audit.log, rlog.sh script throws error in splunkd.log|
|2020-04-20||ADDON-26131, ADDON-33138||Input protocol.sh gives error in splunkd.log when add-on is installed on macOS|
Third-party software attributions
The Splunk Add-on for Unix and Linux does not use third-party software or libraries.
Source types for the Splunk Add-on for Unix and Linux
Release history for the Splunk Add-on for Unix and Linux
This documentation applies to the following versions of Splunk® Supported Add-ons: released