Splunk® Enterprise

Release Notes

Download manual as PDF

Splunk Enterprise version 5.0 reached its End of Life on December 1, 2017. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF


Splunk 5.0.4 was released on July 29, 2013.

The following issues have been resolved in this release:

Resolved security issues

The following security issue has been resolved in version 5.0.4:

  • Lack of enforcing X-Frame-Options allows for “Clickjacking” attack on Splunk Web (SPL-65987)

For information, refer to this posting on the Splunk Security Portal.

Resolved highlighted issues

  • Historical scheduled searches without an explicit "dispatch.latest_time" specified in their savedsearches.conf definition will run out of schedule on 5.0.3 instances which are part of a search-head pool. (SPL-68970)

Resolved index replication issues

  • Files distributed by means of the cluster master configuration bundle may land in the peer's $SPLUNK_HOME/etc/apps/slave-apps with incorrect permissions. Typically, this only affects scripted inputs which lose their executable bit and can't be run by splunkd. (SPL-64308)
  • Clustering status should show the server name along with GUID. (SPL-68151)

Resolved PDF generation issues

  • If you schedule delivery of a PDF report of a dashboard that includes HTML panels, the PDF report will not be attached to the email. You will see the following error in the python.log: No search job available. (SPL-64056)
  • <searchTemplate> is not honored as a way to specify a search in a simple XML view when creating a search in a dashboard. (SPL-65757)
  • Using <searchTemplate> causes PDF generation not to work. (SPL-65757, SPL-64056)

Resolved search, saved search, alerting, scheduling, and job management issues

  • Inline+PDF email alert gets disabled when updating saved searches after upgrading to 5.0.x. (SPL-63477)
  • python.log can grow due to email alerts automatically logged in DEBUG mode: INFO sendemail:mail sendPDF ...DEBUG Preloading from '/opt/splunk/var/run/splunk/merged/server.conf'. (SPL-64933)
  • On Windows, using the rex command with double quotes in the arguments causes scheduled search to not run script. (SPL-61818)
  • Search performance issues when running a short-running search over 100+ search peers that returns data from only a few of those peers. (SPL-70145)
  • Export in raw mode fails when using reverse command. (SPL-70119)
  • Real-time search fails for events without a valid extracted _time. (SPL-66660)
  • When searching, UnboundLocalError: local variable 'rs' referenced before assignment error is shown. (SPL-69933)
  • Splunk Web is slow when there are +3K stanzas in savedsearches.conf. (SPL-67141)
  • After saving a new search in Searches and Reports under Manager, the alert expiration time is always set according to the custom time. (SPL-65246, SPL-64810)
  • Skipped searches due to bandwidth give no indication as to why they were skipped. (SPL-63110)
  • Show message when max_mem_usage_mb is reached. (SPL-62405)
  • "Unable to get viewstate information; formatting may not be correct" error in Splunk Web after cloning a search and changing its permissions. (SPL-61124)
  • Searching for transactions gives different results in CLI vs Splunk Web. (SPL-58103)
  • RT search backfill takes 15x longer than historical search to fetch a given set of events. (SPL-56820)
  • Typeahead doesn't display source values, just Index, Sourcetype and Host. (SPL-55342)

Resolved Splunk Web and Manager interface issues

  • Invalid XML response (500 internal server error) while accessing lookup manager view when lookup file name contains special characters (SPL-66497)
  • IE9 Compatibility mode default setting does not render dashboard edit menus. (SPL-61480)
  • CherryPy instance should serve a robots.txt file. (SPL-67956)
  • Using the Back button after drilling down on a table gives an error in IE9 and earlier. (SPL-66459)
  • 'New Panel' in Edit Dashboard is empty - Only Cancel and Save buttons. (SPL-65847)
  • "List by Tag Name" link displays error "Splunk cannot find "saved/ntags/<tag>" when changing permissions from public to private. (SPL-63548)
  • Full list of fields not displayed in field picker with error "No fields to display for this search." (SPL-58178)

Resolved distributed deployment, forwarder, and deployment server issues

  • The syslogSourceType attribute for syslog routing does not work. (SPL-64400)
  • Forwarder performance with SSL enabled is significantly degraded from 4.3.x. (SPL-67365)
  • Syslog routing transform creates misleading warning: DEST_KEY=_SYSLOG_ROUTING is claimed to be undocumented. (SPL-68932)
  • Universal forwarder continues to try to resolve reverse DNS after setting autoLB=false in outputs.conf. (SPL-68225)
  • When a forwarder is sending with useAcks on, sendQueue (outputs.conf maxQueueSize) does not automatically adjust to recommended value. (SPL-66915)
  • splunk list forwarder-server shows the indexer as inactive. (SPL-65372)
  • Outputs.conf does not include a definition for backoffOnFailure. (SPL-64584)
  • Events specified in syslogSourceType still get timestamp added for SYSLOG_ROUTING. (SPL-64400)
  • Indexer memory growth associated with frequent forwarder disconnects. (SPL-63778)
  • splunkd.log reports ERROR HTTPClient - Invalid URI fragment "": can't find hostname after installing Deployment Monitor app. (SPL-63568)
  • Splunk's sslCommonNameToCheck feature can't validate multiple certs, so doesn't work with search peers in different domains. (SPL-55098)

Resolved Windows issues

  • IE9 Compatibility mode default setting does not render dashboard edit menus. (SPL-61480)
  • Using the Back button after drilling down on a table gives an error in IE9 and earlier. (SPL-66459)
  • The $decideOnStartup variable does not work for [perfmon] input.conf stanza. (SPL-66103)
  • Overriding the automatic assigned sourcetype for a WinEventLog at the forwarder does not work. (SPL-63554)
  • Blank pages added when printing dashboards from Windows IE. (SPL-61979)
  • Add an option to globally force flash rendering (simple_xml_force_flash_charting) of all charts so IE8 users can switch from JavaScript. (SPL-66162)

Resolved unsorted issues

  • Tempfile permission denied error: ERROR BundleArchiver - Cannot create temporary for filtering: $SPLUNK_HOME/etc/apps/<appname>/metadata/local.meta: Permission denied. (SPL-63776)
  • Splunkd.log reports ERROR HTTPClient - Invalid URI fragment "": can't find hostname. (SPL-63568)
  • Reset license may not take effect if you have more than one active license stack. (SPL-67719)
  • Spam in splunkd.log from OneShotWriter when shutting down. (SPL-65744)
  • TcpOutEloop crash Assertion `it != _ackableEventsPerChannel.end()' failed. (SPL-59183, SPL-67365)
  • Memory leaks in PipelineDataRawStoragePool and SQLitePersistentStorageImpl. (SPL-57217)
  • Memory growth issue when search summary page is opened and loading big metadata searches. (SPL-69162, SPL-55163)
  • Deleting an index containing a capital letter (for example, splunk remove index MyIndex) causes crash. (SPL-68995)
  • Wrong location for the list_maxsize in limits.conf.spec. (SPL-68519)
  • useSplunkdClientSSLCompression default is incorrect in server.conf.spec. (SPL-68437)
  • sslAltNameToCheck in server.conf does not handle internal whitespace in list. (SPL-68259)
  • default-mode.conf spec file is inadequate. (SPL-68150)
  • Multiple consecutive delimiters treated as one when using multikv.conf. (SPL-67748)
  • Status_buckets are set unnecessarily and could cause performance issues. (SPL-66510)
  • Invalid XML response/500 error from Splunk Web when lookup file contains special characters. (SPL-66497)
  • Memory leak in ArgList when running large numbers of accelerated searches. (SPL-66152)
  • The $decideOnStartup variable does not work for [perfmon] input.conf stanza. (SPL-66103)
  • Crash in merging thread. (SPL-65117)
  • Discrepancies between app.conf.spec and app.conf.example. (SPL-63822)
  • Running oneshot input on exported Windows events file not working. (SPL-63481)
  • Splunkd crashes on AIX, btree becomes corrupt and needs rebuilding. (SPL-63180)
  • The btool command should be able to create proper output from a diag collected from Splunk with search head pooling enabled. (SPL-57104)
  • [limits.conf.spec] Inaccurate default value specified for subsearch/maxout. (SPL-46228)
  • Default sourcetyping for $SPLUNK_HOME/var/log/splunk/web_(access|service).log files does not account for file rotation, generates lots of entries in learned app. (SPL-66311)
  • Attempting to add a file input monitor with an existing but disabled target index yields error claiming that the index does not exist: "In handler 'monitor': Parameter index: Index 'test' does not exist. Please provide a valid index." (SPL-64709, SPL-53081)
  • Log settings for appender.licenseaudit* in log.cfg do not include maxFileSize and maxBackupIndex properties. (SPL-63431)
  • Bucketmover should log why a bucket is moved from warm to cold. (SPL-62307)

This documentation applies to the following versions of Splunk® Enterprise: 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters