Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.2.9

Splunk Enterprise 6.2.9 was released on April 6, 2016.

The following issues have been resolved in this release:

Security issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Data input issues

Publication date Defect number 'Description
2016-04-05 SPL-114348 Duplicate events occur after restart if .gz files are monitored.
2016-04-05 SPL-109032 Splunkd crash on archivereader/.
2016-04-05 SPL-105691 Splunk unable to read and unzip some valid archive files resulting in missing events from these files.
2016-04-05 SPL-92461 In applyPendingMetadata, header processor does not own the indexed extractions .confs.

Windows-specific issues

Publication date Defect number 'Description
2016-04-05 SPL-112996 Plus button for machine type filter on the forwarder management page does not display on IE ver.11. (Clone SPL-111356 )
2016-04-05 SPL-114571 Bundle Replication: file size calculation for *.meta filtering is wrong. (clone SPL-60765)

Indexers and indexer clustering issues

Publication date Defect number Description
2016-04-05 SPL-106537 Unusual (non-utf8) file names monitored by Universal Forwarder causes indexers to crash in Aggregator.
2016-04-05 SPL-115781 Search results link from result sharing workflow don't work on search head cluster members other than the one which ran the search because of two .gzip content encoding added by HTTP Server. (clones: SPL-112543, SPL-111596, SPL-112152, SPL-113762)
2016-04-05 SPL-114818 Index reload failing because of trailing slash in path inside indexes.conf.
2016-04-05 SPL-106802 CMSlave readd[sic] failed error message has clarity problems.
2016-04-05 SPL-110800 Crash in PipelineInputChannel::setIndexedExtractionsDestructive on 6.2.6.

Search, saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
2016-04-05 SPL-113200 Debug log could raise segmentation fault in DispatchManager.
2016-04-05 SPL-105269 Calculated fields fail to expand when preceded by a "NOT" expression without a parenthesized sub-term.
2016-04-05 SPL-112271 CLI search returns 0 results when using a cron-scheduled shell script.
2016-04-05 SPL-111632 Empty skip reason in scheduler.log.
2016-04-05 SPL-58137 Crashing thread: DispatchReaper - assert fail in TimeFormat::render().
2016-04-05 SPL-114824 Filter dropdown in pivot ignores the timerange settings while dispatching a search.

Distributed search and search head clustering issues

Publication date Defect number Description
2016-04-05 SPL-115781 Search results link from result sharing workflow don't work on SHC members other than the one who ran the search because of .gzip content encoding added by HTTP Server. (Clone: SPL-115269)

Forwarder issues

Publication date Defect number Description
2016-04-05 SPL-106205 The remotely collected Windows event logs are reindexed after restarting Universal Forwarder.
2016-04-05 SPL-105754 100% CPU used in Splunk Universal Forwarder during restart when useACK=true.

Deployment server issues

Publication date Defect number Description
2016-04-05 SPL-113201 Socket error communicating with splunkd (error=The read operation timed out), path = /services/deployment/server/config/_reload.
2016-04-05 SPL-111535 Deployment Sever displays warn message when app name contains the word "download".
2016-04-05 SPL-108619 The forwarder management displays an inconsistency result when deployment client has 2 host names with one IP address.

Unsorted issues

Publication date Defect number Description
2016-04-05 SPL-110920 SessionToken::Locked_revalidate_user(time_t): Assertion `_p->refcnt >= 2' failed.
2016-04-05 SPL-115844 Bundle Replication: file size calculation for *.meta filtering is wrong.
2016-04-05 SPL-109285 Workflow Actions will not send more than 9 POST arguments.
2016-04-05 SPL-109387 Universal Forwarder splunkd.log repeats the following every 10 mins: ERROR DiskMon - None such on disk: .../splunkforwarder/var/run/splunk/dispatch.
2016-04-05 SPL-109584 log.cfg allows various log locations to be changed. Causes issues for diag and DMC.
PREVIOUS
6.2.10
  NEXT
6.2.8

This documentation applies to the following versions of Splunk® Enterprise: 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters