Splunk® Enterprise

Release Notes

Download manual as PDF

Splunk Enterprise version 5.0 reached its End of Life on December 1, 2017. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF


Splunk 5.0.6 was released on November 20th, 2013.

The following issues have been resolved in this release:

Resolved security issues

The following security issue has been resolved in version 5.0.6:

  • Reflected XSS in Splunk Web (SPL-74327)

For more information, refer to this posting on the Splunk Security Portal.

Resolved migration issues

  • Adding an invalid saved search manually to savedsearches.conf causes splunkd to crash. (SPL-70756)

Resolved data input issues

  • Splunk file monitoring makes use of AccessCheck() call to validate readability, which is not reliable in network filesystem scenarios. (SPL-74889)
  • Chinese month could not be identified in timestamp. (SPL-67688)

Resolved index replication issues

  • Master thinks peer has a bucket which has already been frozen - cluster never searchable since bucket cannot be made primary. (SPL-72447)
  • Crash in DispatchReaper when removing peers. (SPL-74158)
  • Cluster-bundle: "Config validation failure" at peers when an index db defined in a peer's app in "etc/apps", and "repFactor=auto" is applied to it. (SPL-73545)
  • Hot bucket replication on Windows can generate renaming errors. (SPL-71987)

Resolved integrated PDF generation issues

  • reportIncludeSplunkLogo parameter only takes effect for Admin user not the normal Users. (SPL-72467)

Resolved search, saved search, alerting, scheduling, and job management issues

  • Distributed searches can intermittently fail on certain search peers with an error banner indicating Streamed search execute failed because: User could not act as: <username>. The affected peer will not return results for this search. (SPL-66763)
  • Search head pooling: concurrent CLI search fails due lock failure. (SPL-73520)
  • The timeline and field explorer disappear after double-clicking on the timeline. (SPL-72857)
  • Multiple crashes in TSUM after enabling report acceleration causing corrupt csv files with incorrect fields, leading to inconsistent summary index search results. (SPL-74833, SPL-72858, SPL-74211, SPL-70751)
  • Search head pooling: quota enforcement delays search dispatch with 1k+ artifacts present. (SPL-73518)
  • eval command fails to create field names containing an umlaut. (SPL-73231)
  • Charting polls for first 500 results only, should show a message explaining truncated results. (SPL-72985)
  • Multiline macros are not correctly parsed from macros.conf. (SPL-72399, SPL-72398, SPL-71671)
  • The sendemail command does not support sendpdf=true. (SPL-70983)
  • Summary index searches do not appear in the history endpoint on 5.x, causing history retrieval to fail. (SPL-70746)
  • When summary index is enabled, alert condition is reset to 'always' even it has condition already set. (SPL-71973)

Resolved Splunk Web and Manager interface issues

  • Adding messages to session queue during authentication resets the user session (using SSO to access a page which has errors/warning causes a 'user' not found error). (SPL-72081, SPL-73304)
  • If you have multiple alerts checked in the Alert Manager, and click Delete for one of the alerts, all checked alerts are deleted. (SPL-73804)
  • Pie charts don't show up correctly on dashboard when using Safari. (SPL-71972)
  • srchDiskQuota in default stanza is not taking effect when creating roles from Manager. (SPL-71911)
  • Removing a bulletin message throws an "Error occured attempting to remove MessageHandler:restart_required_reason_0" error. (SPL-71508)
  • Erroneous "Encountered the following error while trying to save: In handler 'lookup-table-files': File is binary and not gzipped" error when uploading a lookup file via Manager, works when copying manually to lookups directory. (SPL-71474)
  • Job manager's "Loading job data" message keeps displaying when using IE6. (SPL-70766)
  • the Roles manager is not able to display list of selected indexes if the list in authorize.conf contains spaces. (SPL-59910)
  • Clicking on some of the menus in Manager resets your app context to Search. (SPL-73793)
  • Tags with special chars cannot be edited/deleted from Manager, throws an error: "error In handler 'fvtags': Could not find object". (SPL-72013)
  • The paginator calculates the number of pages based on oldest buckets instead of the most recent which causes some pages to be inaccessible or blank. (SPL-73077)

Resolved distributed deployment, forwarder, and deployment server issues

  • Search head pooling: concurrent CLI search fails due lock failure. (SPL-73520)
  • Search Head Pooling: unnecessary "duplicate" replications cause spurious untar failures on search peers. (SPL-60740, SPL-62238)
  • Crashes in TcpOutELoop and MainTailingThread on universal forwarder. (SPL-74196)
  • targetRepositoryLocation does not work if outside of apps directory. (SPL-73867)
  • The 'removedTimedOutServers' attribute is missing from distsearch.conf.spec. (SPL-73768)
  • Unable to define multiple receiving indexers with CLI silent install of universal forwarder using msi. (SPL-73237, SPL-75009)
  • Converting and upgrading a heavyweight forwarder to a universal forwarder will cause it to lose its place and resend data it's already sent. (SPL-72446)
  • DistributedBundleReplicationManager needs to break down subtask duration when warning that bundle replication took too long. (SPL-70757)
  • Bundle Replication: nonsense modtimes on bundle files cause premature reaping and errors in distributed search. (SPL-66763)
  • "Deployment Server Class Status" cannot keep deployment clients when phoneHomeIntervalInSecs is 900 sec. (SPL-62024)

Resolved Windows-specific issues

  • splunk-regmon.exe using a lot of cpu. (SPL-73927, SPL-73145)
  • Unable to define multiple receiving indexers with CLI silent install of universal forwarder using msi. (SPL-73237, SPL-75009)
  • With IE8 users cannot get the correct result by drilling down in the Search app if there are multiple white spaces in event's data. (SPL-74661)
  • Job manager's "Loading job data" message keeps displaying when using IE6. (SPL-70766)

Resolved unsorted issues

  • Panel editor: The button for opening panel editor is gone. (SPL-74853)
  • Splunkd fails to start on HP-UX v2 11.23 with Unsatisfied code symbol '__cxa_get_exception_ptr' in load module. (SPL-72290)
  • Deleting an index when the index queue is blocked leaves the index in "disabled" state. (SPL-72197)
  • Splunk.Module.ViewRedirectorLink or Splunk.Module.ViewRedirector popup parameter do not open a new window when setting up a dynamic drilldown. (SPL-73979)
  • When you click on a json event that has a field called "timestamp", the subsequent drilldown search returns 0 results. (SPL-73649)
  • Cached LDAP results not mapping all eligible groups to all their roles for some users. (SPL-71872)
  • GET /services/messages triggers false action=restart_splunkd lines to be logged to audit.log. (SPL-70903)
  • Crashing thread: DispatchReaper > ThreadException: pthread_cond_timedwait: Invalid argument;. (SPL-70680)
  • log-local config should include log permission controls. (SPL-51634)
  • Diag generation fails when SPLUNK_DB has mixed slashes on windows, eg C:\Splunk/var\lib/splunk. (SPL-74084)
  • No panel time count if there are the panels with the same title name. (SPL-58705)

This documentation applies to the following versions of Splunk® Enterprise: 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters