Known issues for Splunk App for Infrastructure
The Splunk App for Infrastructure version 2.0.3 has the following known issues.
Date filed | Issue number | Description |
---|---|---|
2020-08-06 | SII-7027 | When the search head cluster is restarted the following error message appears on the search head: "SAI failed to migrate to version <version> (SAI migration logs)" Workaround: This error message is benign. To suppress the error message, you can disable the [em_migration_controller] modular input. However, you must re-enable it manually the next time upgrade otherwise the app will be in a broken state. |
2020-06-04 | SII-6992, ITSI-7334 | Alerts break if the underlying data is moved to a different index. |
2020-05-15 | SII-6957 | Splunk Add-on for Infrastructure has performance issues with em_metrics regex. |
2020-03-23 | SII-6871 | The Kubernetes "Download Config Only" option attempts some configuration of the Kubernetes cluster. |
2020-02-19 | SII-6972 | The Entity Analysis dashboard shows the following error: 'Cannot read property "hasBeenChecked" of undefined' Workaround: This issue occurs when you have more than 30 roles. Reduce the number of roles in your system to 30 or less. |
2020-01-28 | SII-6534 | On Solaris 10, the install_uf.sh script fails to download the universal forwarder from splunk.com. Workaround: Install cacertificates on Solaris: pkgadd -d http://get.opencsw.org/now /opt/csw/bin/pkgutil -U /opt/csw/bin/pkgutil -y -i cacertificates /usr/sbin/pkgchk -L CSWcacertificates # list files |
2020-01-28 | SII-6536 | On Solaris 11.4, collectd fails to start because it's missing the libldap.so.5 library. Workaround: Run this command to create a symlink, then restart collectd.
|
2019-11-04 | SII-5988 | __pycache__ is included in the SAI app build. |
2019-10-14 | SII-5853 | Manually adding an entity_type for a different type of entity can break dashboards. |
2019-10-12 | SII-5824 | An error occurs when saving panels on the Analysis tab to a dashboard. |
2019-10-07 | SII-5724 | Upgrading the Splunk Add-on for Amazon Web Services to version 5.0.0 breaks compatibility with SAI. Workaround: 1. Delete $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin. 2. Upgrade the Splunk Add-on for Amazon Web Services to version 5.0.0. |
2019-09-23 | SII-5623 | The AWS Add Data page doesn't load all elements on the first page visit. Workaround: Reload the page. |
2019-09-23 | SII-6971 | VMWare event correlation generates weird commands in groups. |
2019-09-13 | SII-5553 | Duplicate entities are imported into ITSI from SAI when host values are the same. |
2019-08-28 | SII-5401, MAW-3073 | The tooltip on the Analysis tap doesn't work when any "Events" panel is expanded. |
2019-06-26 | SII-4776 | The uninstall script might not delete the SplunkForwarder.service file. Workaround: Run this command: rm -rf /etc/systemd/system/multi-user.target.wants/SplunkForwarder.service |
Fixed issues for Splunk App for Infrastructure | Third-party software credits for Splunk App for Infrastructure |
This documentation applies to the following versions of Splunk® App for Infrastructure (Legacy): 2.0.3
Feedback submitted, thanks!