Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Known issues

The following are issues and workarounds for this version of Splunk Enterprise.

Issues are listed in all relevant sections. Some issues appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Refer to the "System requirements" in the Installation Manual for a list of supported platforms and architectures.

For a list of deprecated features and platforms, refer to "Deprecated features" in this manual.

Highlighted upgrade issues

This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "About upgrading to 6.1 READ THIS FIRST" in the Installation Manual.

Publication date Defect Description
03/02/2015 TAG-8484 If you use Splunk App for VMWare or Splunk App for NetApp, upgrade those applications to Splunk App for VMware 3.1.3 (or later) and Splunk App for NetApp 2.0.2 (or later) before you upgrade to Splunk Enterprise version 6.1.6.
Pre-6.1.5 SPL-89640 If you run Splunk Enterprise on Linux as a non-root user, and use an RPM to upgrade, the RPM writes the $SPLUNK_HOME/var/log/introspection directory as root. This can cause errors when you attempt to start the instance later. To prevent this, chown the $SPLUNK_HOME/var/log/introspection directory to the user Splunk Enterprise runs as after upgrading and before restarting Splunk Enterprise.
Pre-6.1.5 SPL-83988 Text field on the top of "dropdown" input is missing. For a workaround, see "Drop Down list using populating search in 6.1" in Splunk Answers.
Pre-6.1.5 SPL-75354, SPL-75647 Opening saved searches for editing or running CLI searches are very slow. Workaround: disable fetch_remote_search_log in limits.conf.
Pre-6.1.5 SPL-73797 Bundle replication fails when serverName or search head pool GUID has a final segment containing only digits. This can affect users upgrading from pre 6.0.x versions of Splunk.
Pre-6.1.5 SPL-73386 Admin users can't schedule saved searches of users unless the saved searches are shared. To work around this problem:

1. Create a special power/admin user who can run scheduled searches.

2. Assign this user ownership of the scheduled searches.

3. Share the searches at the app level and grant read/write permission to the correct set of users.

Upgrade issues

This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "How to upgrade Splunk Enterprise" in the Installation Manual.

Date filed Issue number Description
2014-08-20 SPL-89640 When running Splunk on Linux as non-root user and using RPM to upgrade, the RPM writes $SPLUNK_HOME/var/log/introspection as root, causing errors upon restarts

Workaround:
Chown the $SPLUNK_HOME/var/log/introspection directory to the user Splunk Enterprise runs as after upgrading and before restarting Splunk Enterprise.
2013-08-19 SPL-73386 Users are not allowed to run historical scheduled search

Workaround:
1. Create a special power/admin user who can run scheduled searches.

2. Assign this user ownership of the scheduled searches.

3. Share the searches at the app level and grant read/write permission to the correct set of users.

Data input issues

Date filed Issue number Description
2014-03-10 SPL-81637 Splunkd preview runs indefinitely on any file preview with "DATETIME_CONFIG=none".
2013-10-29 SPL-75764 Forwarder forwards duplicate data after props.conf is in place for cross platform scenario/when the forwarder is on Solaris and the indexer is on Linux.
2013-10-11 SPL-75116 The UI does not show configured items of some newly converted windows modular inputs that contain the name "default" in the stanza

Workaround:
Edit inputs.conf: in stanzas that contain WinRegMon://default, replace "default" with something else, then restart splunk.
2013-09-10 SPL-74209, SPL-74167 Persistent queues are not created on Windows for stanzas that contain unusual characters (such as < and >).

Workaround:
Specify the persistentQueue explicitly in the input definition.

Search issues

Date filed Issue number Description
2015-04-20 SPL-99985, SPL-110948, SPL-105277, SPL-106091, SPL-107257 Drill-down on field returns HandleIntentionsParserDataProvider error
2014-12-22 SPL-94910 The replace function does not apply to fields names with an underscore in them.

Workaround:
Rename the fields before the replace.

... | rename *_* AS *-* | replace "something" by "somethingelse"

2014-10-22 SPL-92298, SPL-98390 Workflow action event menu does not encode _raw field when used in link.uri
2014-04-16 SPL-83129 Eval function strptime does not return results when 1970 date is used.
2014-04-14 SPL-83052 Drilldown search broken for scatter charts
2014-04-11 SPL-82972 Search bar is disabled if already selected timerange is selected again
2014-04-07 SPL-82702 Clicking Report Name in Report Acceleration Summaries page will open 404 page for user names containing white spaces
2014-04-04 SPL-82650 A report created and scheduled by admin cannot be embedded by a power user.
2014-04-02 SPL-82566 Workflow action: special characters are not escaped properly
2014-03-27 SPL-82357 The splunk clean all -f CLI command doesn't remove data from the main index on Windows systems.
2014-03-27 SPL-82359 timestamp rendered by Safari is off by 1 hour around DST changes
2014-03-25 SPL-82288, SPL-84457 Windows: process cannot access the file because it is being used by another process - search errors in the splunkd.log
2014-03-15 SPL-81934 For clusters, may be unable to open search results output file for search results in a cluster.

Workaround:
Write to a temp file and rename to the target file.
2014-03-13 SPL-81851 Data Model Editor - Select lookup dropdown allows user to select empty lookups, fails to provide useful feedback when that occurs
2014-02-21 SPL-80942 Flashtimeline: 500 Internal Server Error when pasting long URL into panel name.
2014-02-21 SPL-80966 eval function commands() fails search when a search can't be parsed
2014-01-30 SPL-79738, SPL-81136 The iconify command fails to render icons in the event viewer.
2013-12-18 SPL-78179 REST /saved/searches App names with special characters have invalid links.
2013-11-27 SPL-77126 The Registry data input incorrectly handles events with different cases in their paths.
2013-10-17 SPL-75354 Opening saved searches for editing or running CLI searches are very slow.

Workaround:
Disable fetch_remote_search_log in limits.conf.
2013-09-06 SPL-74151 When using SimpleXML, an extra pipe in the search post process of a form runs fine on the dashboard but shows errors when linked to the search page.
2013-09-03 SPL-74028 "splunk list wmi" doesn't show active WMI collections, but "splunk cmd btool wmi list" does
2013-08-19 SPL-73386 Users are not allowed to run historical scheduled search

Workaround:
1. Create a special power/admin user who can run scheduled searches.

2. Assign this user ownership of the scheduled searches.

3. Share the searches at the app level and grant read/write permission to the correct set of users.

Saved search, alerting, scheduling, and job management issues

Date filed Issue number Description
2014-05-01 SPL-83686 Data Model Pivot: Extra NULL column displays in Pivot with big data and Numbered Attribute in Split Columns.

Workaround:
The workaround is to add filter status=*, or make a more refined Data Model that has an object for events with status.
2014-03-31 SPL-82440 DM Pivot: Empty Pivot page displays for DM with "_time" field in Search Object
2014-03-24 SPL-82262, SPL-82241 Pivot search command fails for an admin trying to pivot on a Private Data Model created by a User.
2014-03-20 SPL-82164 Migrating invalid data models from 6.0 to 6.x fails.
2014-03-19 SPL-82133 Data model allows users to upload a JSON file which has Field names with spaces but will not validate it.
2014-03-11 SPL-81701 Data Model Pivot, "Legend Position" and "Stack Mode" change to default settings if you change the X/Y-Axis more than once.
2014-03-10 SPL-81645 Data model exhibits sticky UI when "transaction group by object" name has a single (x) character.
2014-03-07 SPL-81538 When using Pivot, stack mode is lost when "Scatter Chart" is selected.
2014-02-20 SPL-80918 Datapreview: endpoint doesn't allow for deleting sourcetype properties
2013-11-26 SPL-77054, SPL-77055 Data model objects that have names starting with an underscore character ("_") do not work correctly and cannot be used in Pivot.

Charting, reporting, and visualization issues

Date filed Issue number Description
2017-07-24 SPL-143311, SPL-78612 Deleting a dashboard with a scheduled PDF does not also delete the scheduled view on stand alone SH
2014-01-27 SPL-79562 Cloned dashboard is not scheduled but "Schedule PDF Delivery" link indicates that the schedule was cloned.
2013-11-20 SPL-76824 Dashboard returns 400 error and invalid message if "maxLines" and "count" is empty for Panel Type: Event.
2013-09-06 SPL-74151 When using SimpleXML, an extra pipe in the search post process of a form runs fine on the dashboard but shows errors when linked to the search page.
2013-08-28 SPL-73846 New reports are not displayed in the report list until you refresh the window.

Data model and pivot issues

Date filed Issue number Description
2014-05-01 SPL-83686 Data Model Pivot: Extra NULL column displays in Pivot with big data and Numbered Attribute in Split Columns.

Workaround:
The workaround is to add filter status=*, or make a more refined Data Model that has an object for events with status.
2014-03-31 SPL-82440 DM Pivot: Empty Pivot page displays for DM with "_time" field in Search Object
2014-03-24 SPL-82262, SPL-82241 Pivot search command fails for an admin trying to pivot on a Private Data Model created by a User.
2014-03-20 SPL-82164 Migrating invalid data models from 6.0 to 6.x fails.
2014-03-19 SPL-82133 Data model allows users to upload a JSON file which has Field names with spaces but will not validate it.
2014-03-11 SPL-81701 Data Model Pivot, "Legend Position" and "Stack Mode" change to default settings if you change the X/Y-Axis more than once.
2014-03-10 SPL-81645 Data model exhibits sticky UI when "transaction group by object" name has a single (x) character.
2014-03-07 SPL-81538 When using Pivot, stack mode is lost when "Scatter Chart" is selected.
2014-02-20 SPL-80918 Datapreview: endpoint doesn't allow for deleting sourcetype properties
2013-11-26 SPL-77054, SPL-77055 Data model objects that have names starting with an underscore character ("_") do not work correctly and cannot be used in Pivot.

Indexer and indexer clustering issues

Date filed Issue number Description
2016-12-07 SPL-133712, SPL-100516 Events deleted in an index cluster via the "| delete" search operator reappear after primary is restarted
2014-12-11 SPL-94250 Rolling restart takes out maintenance mode
2014-10-13 SPL-91861 On Windows indexer on an ec2 instance, splunk-optimize main thread can crash on buckets on the temporary drive z:\>.
2014-05-01 SPL-83693 Clustering manager reports data not searchable though search factor is met
2014-04-18 SPL-83279 Clustering: metadata seach returns different results on searchhead and master
2014-04-09 SPL-82868 Clustering: metasearch search not returning right event count with multisite enabled
2014-03-17 SPL-81972, SPL-81963 For a multisite cluster, you must roll the peers' hot buckets if you change the values of any of these attributes: site_replication_factor, site_search_factor, or available_sites.

Workaround:
For a multisite cluster, you must roll the peers' hot buckets if you change the values of any of these attributes: site_replication_factor, site_search_factor, or available_sites, and then restart the master. Otherwise, the buckets might not meet the new site_replication_factor or site_search_factor or be fully searchable. You can roll the buckets manually or by issuing a rolling-restart command.
2014-03-17 SPL-81955 Multisite: Peer takes approximately 6 minutes to restart when its site configuration is changed.
2014-03-14 SPL-81913 Changing your configuration from multi site to non-multisite can result in unsearchable buckets.
2014-01-07 SPL-78797, SPL-103251 Buckets with a corrupted journal.gz are stuck in a PendingDiscard state with continuous fsck retries

Workaround:
Manually freeze all copies of the corrupted bucket(s) following this procedure -> https://confluence.splunk.com/display/SUP/Index+replication+delete+buckets

This work-around is now also documented [on Splunk Answers|http://answers.splunk.com/answers/184484/what-should-i-do-with-bad-buckets-in-a-clustered-e.html].

2013-12-11 SPL-77792 Different # events returned for identical buckets on different sites because partial uncompressed slice exists on one peer's bucket but not on others
2013-09-11 SPL-74253 Clustering - Maintenance mode does not carry over across master restarts.
2013-09-05 SPL-74103 Changing the server name on search head doesn't get reflected in the cluster master's cluster management page.
2013-09-03 SPL-74001 Clustering: remove excess buckets doesn't remove excess hot buckets
2013-08-23 SPL-73652 "splunk offline -enforce-counts" incorrectly fails to stop the peer (splunk does not exit)

Workaround:
How to avoid this issue

=> Do not use "--enforce-count" option

How to fix this issue when this already happened and got stuck with "Decommissioning" ? 1) Stop the Cluster Peer ("splunk stop") => CM should show the CP as "down" 2) Make sure searchable factor and replication factor are met in the view of Cluster Management => If not, there is another issue happening in addition to this bug. This bug happens even when all buckets have no problem. 3) Option: If you need to remove the 'decommissioned' CP from Cluster Management view, you need to restart Cluster Master. In dash, we can remove a down-ed peer or Graceful shutdown peer from master's list with out restarting the master. At CM, you have to do something like: $SPLUNK_HOME/bin/splunk remove cluster-peers -peers GUID1,GUID2,GUID3 ( SPL-86868 )

2013-08-06 SPL-72484 You cannot use the CLI to delete an index with a capital letter in its name.
2013-07-03 SPL-70433 Clustering error "unexpected duplicate app" for apps in both $SPLUNK_HOME/etc/apps and $SPLUNK_HOME/etc/slave-apps.
2013-03-20 SPL-63687 Clustering dashboard displays the removed peer list for ever
2012-06-25 SPL-52901, SPL-54729 Disabling a slave leaves the hot bucket treated incorrectly

Distributed search and search head clustering issues

Date filed Issue number Description
2015-02-26 SPL-97352 $SPLUNK_HOME/var/run/splunk/lookup_tmp is filling up on search-head, no reaping seems to occur
2014-04-11 SPL-82988 DistributedPeerMonitorThread: crash due to resource unavailable
2014-03-28 SPL-82386 Cluster master with distributed search disabled still dispatches searches to cluster peers.
2013-08-27 SPL-73797 Bundle Replication: serverName or search head pool GUID ending with 10 digits confuses /admin/bundles on indexers
2012-08-17 SPL-54982 Lookups large enough to index with distributed searches cause problems sometimes

Universal forwarder issues

Date filed Issue number Description
2013-09-18 SPL-74427, SPL-74448 The Splunk universal forwarder installer for Solaris 10 does not add the splunk user when you attempt to install it using the pkgadd command. This results in the script generating lots of errors.

Workaround:
To work around this issue, create a splunk user on your system before attempting to run the installer.

Distributed deployment, forwarder, deployment server issues

Date filed Issue number Description
2014-03-24 SPL-82258 One or more apps are still being downloaded banner never goes away
2013-12-13 SPL-77905 "./splunk list deploy-clients" limited to 30
2010-11-10 SPL-35308 Any app that updates its lookup table files can't be pushed out/managed using Deployment Server

Monitoring Console/DMC issues

Date filed Issue number Description
2014-05-05 SPL-83783, SPL-86152, SPL-90130 Crashing thread: DispatchReaper -- 'ComponentException: Failed to get LDAP user="" from any configured servers'

Splunk Web and interface issues

Date filed Issue number Description
2015-08-20 SPL-105490 Django app page redirects to Splunk login screen when accessed directly using SSO but authenticates when visiting a non django page first.
2014-12-22 SPL-94886 Dashboard panels are inconsistent when referencing the same SID
2014-10-22 SPL-92298, SPL-98390 Workflow action event menu does not encode _raw field when used in link.uri
2014-04-17 SPL-83226 Logging in with User with non English characters will make Splunk unusable
2014-04-11 SPL-82972 Search bar is disabled if already selected timerange is selected again
2014-04-07 SPL-82702 Clicking Report Name in Report Acceleration Summaries page will open 404 page for user names containing white spaces
2014-04-04 SPL-82650 A report created and scheduled by admin cannot be embedded by a power user.
2014-04-02 SPL-82566 Workflow action: special characters are not escaped properly
2014-02-26 SPL-81103 Username surrounded by dollar signs cannot create saved searches.
2014-01-30 SPL-79738, SPL-81136 The iconify command fails to render icons in the event viewer.
2013-11-20 SPL-76798 Time range picker is not customizable via times.conf the same as version 5 or as suggested by docs.
2013-10-17 SPL-75354 Opening saved searches for editing or running CLI searches are very slow.

Workaround:
Disable fetch_remote_search_log in limits.conf.
2013-08-19 SPL-73386 Users are not allowed to run historical scheduled search

Workaround:
1. Create a special power/admin user who can run scheduled searches.

2. Assign this user ownership of the scheduled searches.

3. Share the searches at the app level and grant read/write permission to the correct set of users.

2013-01-01 SPL-59980 No horizontal scroll bar in AD browser
2012-11-14 SPL-58476 Login screen shows expired license, before it is expire (on same day)

Windows-specific issues

Date filed Issue number Description
2018-11-07 SPL-162659, SPL-80589 On Windows Server 2012 and Server 2012 R2, an external bug causes the %_Processor_Time counter to display 100 for multiple processes, even when the number of available CPU cores precludes that possibility.
2015-01-05 SPL-95004, SPL-97080 Large delays in Windows Event Logs due to low network thruput caused by ~250ms pause after tcp sends 6-7 packets.
2014-10-20 SPL-92192, SPL-92193, SPL-96184, SPL-100199, SPL-105086 When evt_dc_name is not specified for Wineventlog input (and SID resolution) is enabled, use the local DC (not PDC) for SID resolution
2014-09-25 SPL-91279 Splunk Universal Forwarder on Windows (specifically, the splunk-perfmon.exe process) does not release key handles.

Workaround:
See "Handle leak when an application collects performance data in Windows Vista, in Windows 7, in Windows Server 2008 or in Windows Server 2008 R2" on the Microsoft Support website for a hotfix download.
2013-10-11 SPL-75116 The UI does not show configured items of some newly converted windows modular inputs that contain the name "default" in the stanza

Workaround:
Edit inputs.conf: in stanzas that contain WinRegMon://default, replace "default" with something else, then restart splunk.

Rest, Simple XML, and Advanced XML issues

Date filed Issue number Description
2013-05-15 SPL-67453 When sending the following XML data as a GET or POST param to a custom splunkd endpoint: <dashboard>&lt;foo&gt;</dashboard>, the endpoint actually receives:<dashboard><foo></dashboard>.

Authentication and Authorization issues

Date filed Issue number Description
2014-06-04 SPL-85036, SPL-97734 roleMap attributes are removed in $SPLUNK_HOME/etc/system/local/authentication.conf when user reloads auth (splunk reload auth or restarts Splunk.
2012-02-22 SPL-48342 LDAP strategy host field cannot work with ipv6 format address but computer name is okay

Admin and CLI issues

Date filed Issue number Description
2015-03-11 SPL-97942 Capability defined in an app does not take effect when assigned to a role

Workaround:
The workaround is to change the ui-prefs in ./etc/users/username/local/ui-prefs.conf to look like this:

[search] display.events.fields = ["description","except_extract_1","except_extract_2","except_extract_3","sap_order_status","sourcetype","source","status","request_mode","request_id","request_status_id","object_id","BillToCity_","Airline_","BillToName_","BillToCountry_","City_"] display.events.type = table

2014-11-19 SPL-93339, SPL-93428, SPL-93429 Splunk Web updated to reflect new timezones for Moscow and Yekaterinburg.

Workaround:
Update appropriate TZ in:

$SPLUNK_HOME/etc/apps/search/default/data/ui/manager/authentication_change_user_password.xml

$SPLUNK_HOME/etc/apps/search/default/data/ui/manager/authentication_users.xml

2014-06-04 SPL-85036, SPL-97734 roleMap attributes are removed in $SPLUNK_HOME/etc/system/local/authentication.conf when user reloads auth (splunk reload auth or restarts Splunk.
2014-04-07 SPL-82699 SSO: Acceleration icon fails to display in Searches, Reports, and Alerts page.
2014-03-20 SPL-82145 Messages about missing lookup tables referring to "lookups.conf" in splunkd.log

Workaround:
Known issue:
  • False positive lookup warning in splunkd.log when searching "WARN TransformsExtractionHandler - Unable to find stanza=XXXX.csv in lookups.conf, cannot enumerate fields list".workaround (SPL-82145)


workaround : The warning is harmless (except for consuming disk space and I/O when being written). You can suppress it by setting this in log.cfg: category.TransformsExtractionHandler=ERROR However, you'd lose other warning messages from that category via that solution; caveat emptor.

2013-12-13 SPL-77905 "./splunk list deploy-clients" limited to 30
2013-05-25 SPL-68010 The error thrown when your Splunk instance cannot connect to splunkbase/.../checkforupdate is not an ERROR, should be lowered to INFO.

Workaround:
Set server.conf [applicationsManager] allowInternetAccess = false
2013-05-02 SPL-66511 If $SPLUNK_HOME/etc is located on a case-insensitive filesystem, creating a new view with the same name as an existing view but with different case (capital letters vs lowercase, etc) silently overwrites the existing view.
2013-01-22 SPL-60765, SPL-114571, SPL-115844 Bundle Replication: file size calculation for *.meta filtering is wrong

Workaround:
To quiet the warnings, you can disable delta replication in distsearch.conf: allowDeltaUpload = false.

This does not delta replication work. The underlying problem is still present.

Uncategorized issues

Date filed Issue number Description
2015-04-26 SPL-100331, SPL-100343, SPL-100344, SPL-100926 selectiveIndexing does not index events while still forwarding data
2015-01-08 SPL-95144, SPL-107317, SPL-101986, SPL-101987, SPL-106884, SPL-142789 Indexed message for Windows security event logs shows "FormatMessage error"

Workaround:
Splunk believes this was introduced in a Microsoft Windows patch. The workaround is to configure a delayed start of the Splunk service(s) so that it starts after the Windows Event Log service.
2014-11-24 SPL-93662, SPL-92587 FlashTimeline disappears after zooming to selection or double click (: SPL-92587 ).
2014-09-26 SPL-91396, SPL-92618 Splunk Introspection for CPU-time produces incorrectly high values on busy system -- instrument-resource-usage records values > 100% in resource_usage.log for system-wide CPU usage (component=Hostwide / cpu_system_pct and cpu_user_pct)
2014-09-24 SPL-91273, SPL-92617 splunkd instrument-resource-usage mis-identifies remote scheduled searches as historical searches
2014-09-17 SPL-90958 Unexpected duplicate app: _cluster caused due to password hashing
2014-06-16 SPL-85497 Unable to save generated PDFs using Chrome internal PDF viewer.

Workaround:
Workaround: Enable Adobe Acrobat or Acrobat Reader as the default PDF viewer in Chrome. For more information, seehttps://support.google.com/chrome/answer/142056.


2014-05-15 SPL-84210 In 6.1, "Add attributes with a lookup" page in Data Model Editor fails to handle built-in scripted lookup "dnslookup"
2014-05-12 SPL-83988, SPL-87323 Search filter is missing for the form dropdown input
2014-04-22 SPL-83365 Splunk Enterprise on Windows does not show an error message when a user without the edit_license capability tries to add a license through the CLI.
2014-04-14 SPL-83068 Default index can be set to random index.
2014-04-04 SPL-82620 Panel is not rendering in PDF
2014-04-04 SPL-82636, SPL-82617 root_endpoint: Not able to use "Edit Source" menu from Dashbord list
2014-04-01 SPL-82517 Paper Size and Layout in PDF Schedule dialog do not respect Paper Size and Layout in Email Settings.
2014-03-28 SPL-82411, SPL-82897 Script input with absolute path (c:\program files\splunk\bin\scripts\getData.bat) fails to start on Windows, Error: incorrect path to script
2014-03-23 SPL-82238 Datamodel fails to drill down further when the same attribute for Split Rows and Split Columns are selected.
2014-03-21 SPL-82233 Dashboard returns 400 error and invalid message if "maxLines" and "count" is empty for Panel Type: Event.
2014-03-19 SPL-82130 Resizing a chart in a dashboard will clear the selection.
2014-03-13 SPL-81856 Show all lines does not work in data model editor preview.
2014-03-12 SPL-81810 Licensing - license pool warning at license master keeps coming back after deleting it.

Workaround:
Delete the warnings on the peers first, then the License Manager.
2014-03-12 SPL-81781 In the Data Model Manager, "Acceleration Status" and "Access Count" fail to update when you click "Update".
2014-03-07 SPL-81544 Changing form input token within editor does not update URL correctly
2014-03-07 SPL-81489 Version 6.* of the universal forwarder always installs the Splunk Add-on for Windows (Splunk_TA_Windows), regardless of whether you disable the WINEVENT_*installation flags.
2014-02-13 SPL-80568 Highcharts determines Y-axis values based on first point outside visible range.
2014-02-07 SPL-80285 In the Data Model Editor, the Edit Lookup page is blank if Lookup is shared only in Lookup Definitions.

Workaround:
For more information, see Add lookup files to Splunk.
2014-02-06 SPL-80187 In the Data Model Editor, lookup pages open with options displayed for other Lookup when the data model definition is private but the file is app or globally shared.

Workaround:
Share the definition. For more information, see Add lookup files to Splunk.
2014-01-31 SPL-79842 On Windows, Indexer doesn't accept new connections on splunktcpin port after queue blockage is resolved
2014-01-13 SPL-79026 PDF Export result does not display latest unsaved changes to viz report
2014-01-10 SPL-78984 The 32 bit Windows version of the universal forwarder fails to properly upgrade from non-default location. Note: Installing a 32-bit version of any Splunk software on top of 64-bit version is neither supported nor recommended.
2013-12-30 SPL-78462 homePath.maxDataSizeMB and coldPath.maxDataSizeMB being ignored on Windows
2013-12-13 SPL-77954 Primary copy of bucket left in strange state with chunk of data not added to journal.gz causing event counts to be off between peers with a common bucket
2013-11-27 SPL-77139 Licenser pool usage gets reflected only after restarting splunkd.
2013-11-11 SPL-76208, SPL-74902 TCPChannel Issue - Find/Fix root cause
2013-09-13 SPL-74337, BETA-496 You cannot specify a destination folder when installing on OSX.
2013-09-03 SPL-73981 Improve handling of FIPS flag on Windows x86 - error instead of crash
2013-08-28 SPL-73826 Windows: hostname override not working properly
2013-08-28 SPL-73818 Early versions of IE10 on some Windows 8 systems will not load some pages in Splunk Web if Splunk Web is configured to use SSL.

Workaround:
To work around this issue, update IE to the latest version or update Windows to at least version 10.0.9200.16521.
2013-08-27 SPL-73798 An error occurred while generating a PDF of scheduled search with quotes in the title
2013-08-23 SPL-73636 If your license master is down at midnight, it will not generate a rolloverSummary event in license_usage.log, and the license usage report view > Previous 30 days dashboard will have a gap in the data for the previous day.
2013-08-13 SPL-73029 heatmaps not shown in pdf
2013-07-25 SPL-71645 Report acceleration Summary folders (summaryHomePath) cannot be created if thehomePath of the index is at the root of the filesystem, (homePath=D:\myindex orhomePath=/myindex).

Workaround:
Create the folder manually.
2013-07-17 SPL-71149, SPL-71561 Search head pooling - Unknown SID error on search page instead of "splunkd timed out" error message
2013-06-13 SPL-69304 If license slaves are running <6.0 version, they do not have the idx field and in theLicense Usage view, the split by index field will show a field named UNKNOWN.
2013-05-14 SPL-67268 Not able to "Export PDF" if Dashboard has no row or empty row
2013-04-30 SPL-66213 PDF server app is not working with latest Xvfb
2013-04-12 SPL-65124 Sorting as "asc" does not work for Dashboard of Panel Type: List.
2013-04-03 SPL-64489 HiddenPostProcess *silently* discards input events when the parent search is non-reporting and matches more than 10,000 events.
2011-09-30 SPL-43791 Incorrect server status reported when there is a problem with the SSL/TLS configuration
2011-03-18 SPL-38082 Block signature reports YES gaps, NO tampering for data when the source is not well ordered in time
2010-10-08 SPL-34347 wmi input default fields - with value including newlines doesn't search properly becasue of \r\n issue
PREVIOUS
Welcome to Splunk Enterprise 6.1
  NEXT
Splunk Enterprise and anti-virus products

This documentation applies to the following versions of Splunk® Enterprise: 6.1.14


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters