Splunk® Enterprise

Release Notes

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF


Splunk 6.0.4 was released on May 9, 2014.

The following issues have been resolved in this release:

Clustering Issues

  • The generation ID for peers shown in the clustering UI is their original base generation ID, not that the current/latest generation. (SPL-71264)
  • Simple XML dashboards can take significantly longer to load on a pooled search-head in Splunk 6. A work-around is available upon request to Splunk Support. (SPL-80944)
  • rb_* buckets in .bucketManifest sizes don't match up w/ actual size, causing errors. (SPL-79441)

Data model and Pivot issues

  • Accelerated data models only return results in Pivot for objects in the first event object hierarchy. All other objects in subsequent object hierarchies (whether event-based or not) erroneously return 0 results. (SPL-74415)
  • Expanding the App drop-down menu in the Create New Data Model dialog box will create data model. (SPL-74648)

Search, saved search, alerting, scheduling, and job management issues

  • Silent failure: No warning recorded when a shared scheduled search's scheduled time changes to None due to the owner/user being deleted (SPL-79341)
  • Indexer high memory usage: unbounded memory growth by indexer for search Process until system is locks up.(SPL-80748)
  • Savedsearches with at the end of the line "a linebreak" or "a space and a linebreak", may cause parsing errors when retrieved from the search using the command "| savesearch". It may trigger a warning in the UI, but not in all cases. (SPL-80985, SPL-79069, SPL-87261)

Splunk Web and Home interface issues

  • Data Model Editor, Reports, Alerts, Dashboards > Actions > Edit Permissions display for App or All Apps only list first 31 roles (SPL-78961)
  • Web server generates error: 'list' object has no attribute 'startswith.' (SPL-82274)
  • Show source on any time bucket other than the latest one, fails to show the right raw log line. (SPL-81413/SPL-83692)

Distributed deployment, forwarder, and deployment server issues

  • In a deployment server with SSL disabled, deployment clients still attempt SSL communication and fail. (SPL-82207)

Windows-specific issues

  • When you upgrade your Splunk forwarders to version 6.0, the indexers that those forwarders send data to begin crashing. You can work around this issue by following the instructions in "I upgraded my distributed environment to Splunk 6.0 and now my indexers are crashing" on Splunk Answers. (SPL-75796)
  • On Windows Server 2003, the WinEventLog input generates sourcetypes in all lower case, for example, WinEventLog:security versus WinEventLog:Security. This can cause filters that have been set up in props.conf to not match, which can ultimately result in unexpected indexing of data. To work around the problem, follow the instructions in "Windows Event Log filters fail" on Splunk Answers. (SPL-78726)
  • Windows 32-bit new Universal Forwarder default installation directory will be C:\SplunkUniversalForwarder vs 64-bit at C:\Program Files\SplunkUniversalForwarder (SPL-79572, SPL-83067)
  • Show source on any time bucket other than the latest one, breaks and fails to show the right source line. (SPL-81413)
  • Universal forwarder stops forwarding Windows security and application event logs when anti-virus is running on the forwarder. (SPL-80680)

Unsorted issues

  • Stats gives unexpected results because of either maxresultrows or max_mem_usage_mb but not error or warning is logged. (SPL-82103)
  • Charts are broken for empty field names. (SPL-78900)
  • When using the Data Model Manager in Firefox, user not able to check Accelerate check-box. (SPL-76804)
  • When using the Data Model Manager in Firefox, expanding App drop-down menu in Create New Data Model dialog box creates a new Data Model. (SPL-74648)
  • No way to refresh results on View Report page. (SPL-75139)
  • Splunk 6.0 deployment server does not seem to allow for apps of the same name to exist in other server classes. (SPL-77735)
Last modified on 25 September, 2014

This documentation applies to the following versions of Splunk® Enterprise: 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters