Splunk® Enterprise

Release Notes

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF


Splunk 6.0.1 was released on December 17th, 2013.

The following issues have been resolved in this release:

Resolved security issues

The following security issue has been resolved in version 6.0.1:

  • Malformed network input crashes Splunk Enterprise (SPL-75668)

For more information, refer to the Splunk Security Portal.

Upgrade advisory

  • A code change made to resolve an issue in this release unfortunately requires that all data model summaries be rebuilt upon upgrade. Splunk instances that make use of accelerated data model searches will experience this when upgrading from version 6.0 to version 6.0.1 or later.

Resolved highlighted issues

  • Monitoring of certain log formats that worked with Splunk 4 and 5 can fail. In particular, Cisco csv formats (including 'cdr' and 'cmr'), Microsoft Exchange logs, and Microsoft DHCP server logs are affected. Other logs types with nearly identical headers may also fail. Symptoms include splunk.log error messages about seekptr not matching or the file length being too short, as well as mentions of initCRC being the same for multiple files. As a short term workaround, monitor these files with a 5.x forwarder. An alternate strategy is to use a large initCrcLen value for these source types, although this may force some amount of reindexing. (SPL-75066)
  • Searching indexes where homePath or coldPath are specified with a trailing slash character (/ or \ depending upon platform) will fail, returning no results for warm and cold buckets in these locations. A search.log for these searches will show a message similar to "WARN DatabaseDirectoryManager::Bucket - idx=your_index id=your_bucket_id Bucket directory disappeared mid-query. Abandoning results". To work around this problem, remove the trailing slash from homePath or coldPath for your index configurations. (SPL-76516)

Resolved data input issues

  • Setting sourcetype=IIS for data that is not both W3C-formatted AND utf-8-encoded results in significant memory growth on the indexer. (SPL-74967)
  • A toggle has been added that allows the disabling of the AccessCheck() call used by Splunk input processing to validate readability of files. (AccessCheck() is not reliable in network filesystem scenarios). To disable AccessCheck() this, set TAILING_SKIP_READ_CHECK=1 in $SPLUNK_HOME/etc/splunk-launch.conf. (SPL-74889)

Resolved charting, reporting, and visualization issues

  • The drilldown option for table doesn't work with values of "off" or "all", and the charting.legend.labelStyle.overflowMode for chart doesn't work with a value of "default". (SPL-73831)
  • Cell drilldowns for report tables with split columns display event counts from the row drilldown results. (SPL-74681)
  • Error message appears when navigating back from Drilldown results to Report page with timechart used in search. (SPL-74688)
  • Sparkline doesn't work for max() function. (SPL-74995)

Resolved index replication issues

  • When Splunk freezes a summary (either via summary size retention, or via bucket freezing), its 12KB inflight- directory remains on the file system. To work around this issue, delete the inflight directories by hand. (SPL-74644)
  • Cluster migration python scripts are now included in the package. For more information about migrating indexer clusters, refer to "Upgrade a cluster" in the Managing Indexers and Clusters Manual. (SPL-75616)
  • Replicated bucket (rb_) only contains journal.gz and optimize.result files | Errors: (CMRepJob - Failed to sync search files for bid=) and (Fsck - Repair (entire bucket)...failed: non-EXDEV error renaming tmpDir to stageDir). (SPL-76563)
  • "Config validation failure" at Peers when an index db defined in a peer's app in "etc/apps", and "repFactor=auto" is applied to it. (SPL-74578)

Resolved data model and Pivot issues

  • Splunk Web erroneously allows acceleration of data models with only search-based objects. (SPL-74286, SPL-75410)
  • After sharing a report with All/All Apps and then editing the report in the Pivot editor, an In handler 'savedsearch': Error in 'PivotProcessor': In handler 'datamodelreport' error is generated and the report is not saved. (SPL-74393)
  • Report drilldown not working if search contains tstats with capital letter in data model. (SPL-76571)
  • Pivoting on an object with spaces in eval Field Name shows error "In handler 'datamodelreport': Pivot Error in buildSearchWithModel: error building non-tstats searchString" (SPL-74789)

Resolved search, saved search, alerting, scheduling, and job management issues

  • In rare cases, running continuous real-time CLI searches can cause the splunkd process to hang, and block logins. (SPL-74822)
  • Realtime searches with historical indexed-based backfill (typically time-windowed realtime searches run from Splunk Web) may have some duplication. This happens when the realtime updates and historical backfill searches both return the same data. If this is a significant issue, possible workarounds include temporarily disabling the 6.0x-specific indexed-realtime feature; avoiding realtime search; or disabling backfill. (SPL-74656)
  • Backgrounding a search job does not make the job globally readable, so emails to users without privileges to read a search see a "Job not found" message when clicking on the link. (SPL-75070)

Resolved Splunk Web and Home interface issues

  • Splunk Web does not show Show all X lines if linecount field is not present. (SPL-74637)
  • Other than the default available translated/localized language, the search will not return results or show loading. (SPL-75244)
  • Workflow actions are not restricted to the specified event type and fields, are shown for all results. (SPL-69481)
  • The Roles manager page is not able to display the list of selected indexes if the list in authorize.conf contains spaces. (SPL-74258)
  • New button missing in the Settings > User interface > Navigation management page. (SPL-75199)
  • Clicking the in timerange picker scrolls to the top of the page and adds a # to the URL. (SPL-74410)

Resolved distributed deployment, forwarder, and deployment server issues

  • Search head pooling: unnecessary "duplicate" replications cause spurious untar failures on search peers. (SPL-74416)
  • Bundle Replication: nonsense modtimes on bundle files cause premature reaping and errors in distributed search. (SPL-74894)
  • Unable to define multiple receiving indexer with CLI silent install of universal forwarder. (SPL-74176)

Resolved Windows-specific issues

  • In environments with malware and end-point scanning activities occurring, some network events can cause Splunk to generate TcpChannel - Error trying to begin socket accept: An invalid argument was supplied. messages in splunkd.log. (SPL-74902, SPL-76208)
  • Windows Server 2003 R2 incorrectly reports that the splunkd.exe binary in the Splunk version MSI package is an invalid application and forces the MSI to roll back the installation and exit with 'Error Code 1'. (SPL-77131)
  • Crashing thread: TcpChannelThread -or- HTTPDispatch due to non-thread-safe setlocale usage on Windows platform (SPL-75537, SPL-75557)
  • If you install the Splunk Add-on for Windows into a Splunk 6.0 instance and subsequently restart from the CLI, you might receive Possible typo in stanza syntax warnings. While these warnings can be safely ignored, if you want to get rid of them, edit %SPLUNK_HOME%\etc\apps\splunk_TA_windows\default\inputs.conf and remove the [WinEventLog://] stanzas. This issue was resolved in the 4.6.5 version of the Windows TA. (MSAPP-1275)
  • Setting sourcetype=IIS for data that is not both W3C-formatted AND utf-8-encoded results in significant memory growth on the indexer. (SPL-74967)
  • [IE9] - In compatibility view, the events viewer's "time" column is not properly resized. (SPL-74936)
  • After indexer queue blockages resolved, forwarders cannot connect to indexer. (SPL-75007)

Resolved REST, Simple XML, and Advanced XML issues

  • eval $foo$ tokens don't work in Simple XML, searches fail with error Search query is not fully resolved. (SPL-74498)
  • Invalid XML prevents dashboard listing page from showing all dashboards. (SPL-74529)
  • AppLogo does not always get displayed in Simple XML dashboards. (SPL-74368)
  • If you create a workflow-action and leave the 'Apply only to the following event types' field blank you will not get the workflow-action in the dropdown as expected. (SPL-74757)
  • REST HTTP server threads and sockets limits are based on soft file descriptor ulimit even when the hard limit is higher. (SPL-74989)
  • Splunk.Module.ViewRedirectorLink or Splunk.Module.ViewRedirector popup parameter do not open a new window. (SPL-74516)

Resolved Web Framework issues

  • Using Django on Splunk Free doesn't work and displays an infinite redirect loop. To work around this issue, use the trial version of Splunk Enterprise. (DVPL-3006, SPL-75072)
  • Using Django from a locale other than en-us will most likely result in errors. For a code workaround, contact devinfo@splunk.com. (DVPL-3033)
  • On non-universal forwarder Splunk installs, the diag command will not work when passed any arguments or flags. (SPL-75535)
  • Web Framework redirect does not respect URLs with root_endpoint. (SPL-75587)

Resolved Hunk issues

  • When running a search against a Hunk search head that is also configured to search Splunk indexers, reporting searches that are ran in "verbose mode" show errors in later pages of results. (SPL-75588)
  • When a search is run that specifies a virtual index in a subsearch, it fails with "Permission denied:License does not allow execution of searches for virtual_index" error, even though Hunk License is already installed. (SPL-74861)
  • Searches against high cardinality data can yield incorrect results. (SPL-75105)

Resolved unsorted issues

  • A dashboard table with a "fields" element does not render in PDF. (SPL-74876)
  • Upgrading causes crash in "Crashing Thread: archivereader". (SPL-74873)
  • diag on FreeBSD runs isainfo which is not usually available. (SPL-63092)
  • Command-line option and matching key has been added to server.conf to exclude/include content from diags with component-based labels. The new flags for diag are --collect, --enable --disable. (SPL-53648)
  • Launcher mangles diag command line when any flags are used on non-universal forwarder. (SPL-75535)
  • Following the instructions in http://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/TranslateSplunk to create a new translate language causes no results to be returned when running a search. (SPL-75244)
  • Setting srchDiskQuota in default stanza does not take effect when creating roles from Splunk Web. (SPL-75058)
  • For Japanese and Chinese language, when you hit an enter key to select a word from the suggestions dropdown, the report is immediately saved. (SPL-74996)
  • sendemail command does not support sendpdf=true. (SPL-74968)
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters