Splunk® Enterprise

Release Notes

Download manual as PDF

Splunk Enterprise version 5.0 reached its End of Life on December 1, 2017. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF


Splunk 5.0.7 was released on January 21, 2014.

The following issues have been resolved in this release of Splunk:

Resolved integrated PDF generation issues

  • Integrated PDF generation fails when a dashboard or view contains HTML. (SPL-75106)

Resolved data input issues

  • Pressing "Enter" after creating a new sourcetype for an input causes Splunk Web to exit the workflow instead of proceeding to the next step in the workflow. (SPL-62611)
  • Persistence of stale NFS file handler can cause recent events to not be indexed. (SPL-74973)

Resolved Splunk Web and Manager interface issues

  • Clicking on "Collapse all" doesn't collapse the tree to the root nodes in "view source" mode. (SPL-51328)
  • Changes to search time range do not display in Splunk Web unless page is reloaded. (SPL-70765)
  • HTML linebreaks that occur when editing a dashboard cause an error and will not allow further editing. (SPL-74984)

Resolved cluster issues

  • When a peer is perceived as offline and marked down, Splunk fails to add it back when peer is back online. (SPL-75952)
  • Cluster master not made aware of cluster bundle application failure on peers. (SPL-75999)
  • Apply cluster-bundle fails and indexer restarts with no configuration. (SPL-75466)
  • In some configurations, cluster buckets do not automatically roll from warm to cold. (SPL-74785)
  • Crash in TcpOutEloop on a third node when two other nodes have been taken offline. (SPL-53753)(SPL-53636)

Search, saved search, alerting, scheduling, and job management issues

  • When adding a view, Splunk does not recognize the XML if you provide it before you provide the View Name. (SPL-72941)
  • Session key caching fails when hostname contains a hyphen. (SPL-74146)
  • When editing XML manually, extra indent spaces are automatically added. (SPL-75667)
  • Drilldown functionality fails in searches that contain both subsearches and additional filters (SPL-75252)
  • Having a very large number of learned sourcetypes can cause forwarder and indexers to use too much memory. (SPL-58055)
  • Search heads with many users, apps, and metadata files creates high memory usage. (SPL-76943)
  • Error message for an incomplete search process are not detailed enough. (SPL-65054)
  • When adding data to a summary index using the collect command with commands that create key-value pair (i.e., top, table, stats) Splunk adds an extra to escape special characters: (\) and ("). Splunk does not undo these escapes when a search is run on the summary index, causing a search failure. (SPL-76627) (SPL-77993)
  • Some Typeahead searches cause indexer to crash. (SPL-75569)
  • Search Job inspector does not provide enough useful information for transaction searches. (SPL-74287)
  • Reloaded searches sometimes produce errors that are actually warnings and not errors. (SPL-71736)
  • Cannot go back to first page after deleting Alerts in Alert Manager. (SPL-59888)

Resolved Windows-specific issues

  • After indexer queue blockages are resolved, forwarders cannot connect to indexer without restart. (SPL-69619)
  • Alerts do not fire if a search string sequence contains a quote, pipe, and quote. (SPL-74076)

Resolved unsorted issues

  • Endpoints do not consistently provide eai:attributes/fields information. (SPL-50881)(SPL-50068)
  • On Linux 6.2+ Splunk should check during install/start time if 'Transparent Huge Pages' is turned ON as it causes indexing degradation and high CPU. Recommendation is to turn THP off. (SPL-75912)
  • Adding a role generates warning messages for empty automatically generated attributes. (SPL-74897)
  • Command-line option and matching key has been added to server.conf to exclude/include content from diags with component-based labels. The new flags for diag are --collect, --enable --disable. (SPL-53648)
  • When passwords are updated in inputs.conf, any hashed version in system/local doesn't get refreshed and the password doesn't work. (SPL-75108)
  • Splunk diag command takes too long and generates diag files that are too large. (SPL-74514)

This documentation applies to the following versions of Splunk® Enterprise: 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters