Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.1.6

Splunk Enterprise 6.1.6 was released on January 20, 2015.

The following issues have been resolved in this release:

Highlighted issues

Publication date Defect number Description
2015-1-20 SPL-93354 SSL forwarding issue between 6.0.6 and 6.0.7. (Cloned from SPL-93157)

Upgrade or Migration issues

This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "How to upgrade Splunk Enterprise" in the Installation Manual.

Publication date Defect number Description
2015-1-20 SPL-91828 Migration appends extra line to some saved searches by stripping the blank line in between. (Clone from SPL-91600)

Indexer issues

Publication date Defect number Description
2015-1-20 SPL-86441 After upgrading to 6.1.x, Splunkd crashes in Regex::matchBase.
2015-1-20 SPL-93436 Indexing throughput with CSV indexed extractions hits a ~2MB/s ceiling (on recommended hardware) when the data is forwarded.

Data input issues

Publication date Defect number Description
2015-1-20 SPL-84699 Corrupted or Multipart ZIP file causes splunkd to crash.

Charting, reporting, and visualization issues

Publication date Defect number Description
2015-1-10 SPL-94102 [JSChart] legend drill-down does not work after redraw. (Cloned from SPL-94567)
2015-1-10 SPL-90229 Adding a filter to a pivot that has a string with spaces creates an invalid search string once FILTER command is run.
2015-1-10 SPL-92605 In Pivot, field drop-downs do not return sample field values.
2015-1-10 SPL-92071 In multi-series mode, dashboard panels may not show data.
2015-1-20 SPL-92472 Visualization "bar" chart fails to render with Chart Overlay.

Search, saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
2015-1-20 SPL-88093 In the Email Settings page, when password/username is deleted the password remains in alert_actions.conf.
2015-1-20 SPL-91857

"Addcoltotals" does not apply label correctly and instead sums up string "values" in label column.

2015-1-20 SPL-92572

Scheduled searches are sometimes slow, and data collected to track search concurrency is sometimes calculated incorrectly.

2015-1-20 SPL-91999

Unable to save summary searches when a summary index is created in search peer.

2015-1-20 SPL-90387

When event is too long, the event processor fails to process events.

2015-1-20 SPL-93068

Too many search errors are generated and recorded into info.csv.

2015-1-20 SPL-90711

For Alert actions, CSV files that are attached to emails create line breaks after 900 characters.

2015-1-20 SPL-90800

After upgrade from 5.0.5 to 6.1.1, email alerts are missing line break for multi-line events.

2015-1-20 SPL-88624

Search timeliner bucketed incorrectly in certain timezones

2015-1-20 SPL-91999 Unable to save summary searches when a summary index is created in search peer

Splunk Web and Home interface issues

Publication date Defect number Description
2015-1-20 SPL-93845

Time range picker does not reflecting settings in ui-prefs.conf when searching from "Data Summary".

2015-1-20 SPL-94510

No restart popup appears when user clicks on "restart" after updating the license.

2015-1-20 SPL-93429 Splunk Web updated to reflect new timezones for Moscow and Yekaterinburg. (cloned from SPL-93339).
2015-1-20 SPL-90989 Manager page user drop down truncates list to 250 users

Deployment server

Publication date Defect number Description
2015-1-20 SPL-92074

Deployment Server crashes while updating serverclasses.conf via REST API calls

2015-1-20 SPL-74255

Upon client unpack: Deployment Server throws an error that local.meta cannot be found.

Windows-specific issues

Publication date Defect number Description
2015-1-20 SPL-85389 Splunk Installer was unable to set the CACLS on the Splunk files. Exitcode='13'
2015-1-20 SPL-92068 Mac OS 10.10 does not support the "splunk enable boot-start" command.
2015-1-20 SPL-92533 In 6.1.1 universal forwarders on Windows 2008 are unable to properly send events to IDX.

Forwarding Issues

Publication date Defect number Description
2015-1-20 SPL-94030 Universal forwarder crashes due to nfs file system glitch: "WatchedFile - About to assert due to: destroying state while still cached."

REST, Simple XML, and Advanced XML issues

Publication date Defect number Description
2015-1-20 SPL-92587 FlashTimeline on a dashboard disappears after double clicking on or zooming to selection.

PDF Issues

Publication date Defect number Description
2015-1-20 SPL-90361 PDF reports display black boxes when there is a Chinese character in html tags in dashboard xml.
2015-1-20 SPL-91707 PDF generation fails when a blank field (tmp="") is used for charting.
2015-1-20 SPL-92782 Scheduled PDF in email attachments do not respect the paper size setting in dashboard.
2015-1-20 SPL-92532 Chart with Predict command does not properly render in PDF.
2015-1-20


Unsorted issues

Publication date Defect number Description
2015-1-20 SPL-93577 Pool selector in the License Usage view does not filter names containing spaces.
2015-1-20 SPL-93095 sslVersions missing from default inputs.conf (cloned from SPL-93093)
2015-1-20 SPL-88209 Django framework: token value in panel drop-down not passed into search
2015-1-20 SPL-92620 High number of duplicate events with "useACK=true".
2015-1-20 SPL-92619 Shutdown generates thousands of warnings: TcpOutputProc - "The event is missing source information"
2015-1-20 SPL-91525 "splunk disable boot-start" doesn't cleanly remove all previously created files in rc.d
PREVIOUS
6.1.7
  NEXT
6.1.5

This documentation applies to the following versions of Splunk® Enterprise: 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters