Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF


Resolved issues

Splunk Enterprise 6.2.1 was released on December 16, 2014.

The following issues have been resolved in this release:

Highlighted issues

Publication date Defect number Description
2014-11-03 SPL-92500 Windows installer fails on non-English Windows systems.

Upgrade issues

This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "How to upgrade Splunk Enterprise" in the Installation Manual.

Publication date Defect number Description
2014-10-28 SPL-92490 web.conf setting for updateCheckerBaseURL=0 now displays "Your Browser could not connect to Splunk.com...need to be connected to the Internet to find out when updates to your Splunk software are available". It does not disable Splunk automatic checking for new versions.

Data input issues

Publication date Defect number Description
Pre-6.2 SPL-92168 Batch reader picks up files that have already been rolled
2014-11-19 SPL-93063 Index list is incomplete under Input Settings, not all index names display.

Charting, reporting, and visualization issues

Publication date Defect number Description
2014-11-21 SPL-93439 Username containing a "." or "@"character fails to create private dashboard

workaround: creating non-private dashboards continues to work, if the role allows it

Search, saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
Pre-6.2 SPL-91390 The return search command does not support field names that contain a period.

Splunk Web and Home interface issues

Publication date Defect number Description
Pre-6.2 SPL-90610 Splunk Web presents incorrect list of field alias entries.
Pre-6.2 SPL-92757 Password is not removed from alert_actions.conf when user is deleted.
Pre-6.2 SPL-93339 Splunk Web updated to reflect new timezones for Moscow and Yekaterinburg.
Pre-6.2 SPL-92565 When user edits a server class via Splunk Web Forwarder Management, Splunk Web may fail to update with the latest list.

Distributed search and search head clustering issues

Publication date Defect number Description
Pre-6.2 SPL-92793 Auto key-value based field extraction may fail.
2014-10-28 SPL-92773 Upon completion of setup in distributed mode, the setup page fails to display instances due to a javascript error.
2014-10-28 SPL-93723 Report Acceleration Summaries don't work in shared context.

Windows-specific issues

Publication date Defect number Description
Pre-6.2 SPL-92480 Messaging errors for failed upgrade to 6.2 are confusing.
Pre-6.2 SPL-92320 When drilling-down in a JSON object (using Internet Explorer), the object disappears behind checkbox panel
Pre-6.2 SPL-91667 After an upgrade from 6.0.3, the splunkd service main thread crashes on start-up.
Pre-6.2 SPL-92597 Rename Splunk Web service description to Splunk Web Service Legacy. Splunkd now handles all Web Service operations and the Splunk Web Service is no longer used. For more information, see "Start Splunk Enterprise on Windows in legacy mode" in the Admin manual.
Pre-6.2 SPL-92121 In Windows, if a user specifies a monitor input that uses a wildcard at the root level, Splunk logs an error and fails to index the desired files.

REST, Simple XML, and Advanced XML issues

Publication date Defect number Description
Pre-6.2 SPL-92314 Input created via REST API on a universal forwarder does not honor disabled=true setting.
Pre-6.2 SPL-91787 /services/data/indexes endpoint outputs blank value for tsidxstatshomepath attribute.

Web Framework issues

Publication date Defect number Description
Pre-6.2 SPL-92729 The time range preset in web-framework view is ignored.

Unsorted issues

Publication date Defect number Description
2014-12-05 SPL-92740 The app key value store (KV store) is not available with a free license.
Pre-6.2 SPL-92160 If user manually adds a new indexer while Splunk with bootstart is enabled, Splunk may crash due to OS user permissions mismatch.
Pre-6.2 SPL-93640 Splunk command line displays errors regarding /etc when the rebuild command is initiated. These errors can be disregarded.
Pre-6.2 SPL-93328 Universal Forwarders that use ACK receive acknowledgments out of order.
Pre-6.2 SPL-92962 Issues installing and starting Splunk as a non-root user.
Pre-6.2 SPL-93418 Setting cipherSuite to most ciphers results in a failed session.
Pre-6.2 SPL-93639 datetime.xml may not recognize AM and PM properly.
2014-10-28 PL-92730 Splunk 6.2 appears to break reverse proxy.
2014-10-28 SPL-91766 KV store does not run if FIPS is enabled.
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters