Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.2.2

Resolved issues

Splunk Enterprise 6.2.2 was released on February 23, 2015.

The following issues have been resolved in this release:


Highlighted issues

Publication date Defect number Description
2015-2-23 SPL-93096 sslVersions missing from default inputs.conf (clone: SPL-93093).
2015-2-23 SPL-93355 Communication between 6.0.6 UF and 6.0.7 indexer fails with SSL (clone: SPL-93157).

Upgrade issues

This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "How to upgrade Splunk Enterprise" in the Installation Manual.

Publication date Defect number Description
2/23/2015 SPL-93258 On HP-UX ia64 and FreeBSD, upon upgrading universal forwarder from 6.0.2 to 6.2, Splunk CLI commands fail with "Couldn't complete HTTP request" errors.
2/23/2015 SPL-91829 Migration appends extra line to some saved searches by stripping the blank line in between (clone: SPL-91600).

Data input issues

Publication date Defect number Description
2015-2-23 SPL-93291 Corrupted or Multipart ZIP file causes splunkd to crash
2015-2-23 SPL-92388 When symlinks present in sinkhole batch inputs, splunkd crashes (introduced by 6.1.4 fix to SPL-88387)
2015-2-23 SPL-96299 Splunkd assertion failure during uploading w3c file: CsvLineBreaker::parser::gotEol() -> PipelineData::removeStartOfRaw(), n <= rawSize()' failed

Charting, reporting, and visualization issues

Publication date Defect number Description
2015-2-23 SPL-95091 Accelerated reports are not recognized as same summary ID when there are more than 2 line breaks in the search query (clone: SPL-84494).
2015-2-23 SPL-93294 In multi-series mode, dashboard panels may not show data (clone:SPL-92071).
2015-2-23 SPL-94569 [JSChart] legend drill-down does not work after redraw (clone: SPL-94102).

Indexers and indexer clustering issues

Publication date Defect number Description
2015-2-23 SPL-93244 ERROR message in Tailing Processor : "Bug: tried to check/configure STData processing but have no pending metadata".
2015-2-23 SPL-93308 Batch primary jobs are scheduled last (clone: SPL-91567).
2015-2-23 SPL-93727 Splunk Web fails to restart indexer with error "CMSlave - failed on move bundle".

Data model and Pivot issues

Publication date Defect number Description
2015-2-23 SPL-93912 Data Model acceleration status shows "Building" although tsidx files have been built.
2015-2-23 SPL-95127 Datamodel Acceleration + Macro in datamodel causes errors in pivot (clone: SPL-91856).
2015-2-23 SPL-92610 Adding filter to pivot that is a string with spaces will result in invalid search string after FILTER command (clone: SPL-90229).
2015-2-23 SPL-92608 In Pivot, field drop-downs do not return sample field values (clone: SPL-92605).
2015-2-23 SPL-92595 Pie chart labels changes to undefined upon browser resize.

Integrated PDF generation and PDF Report Server issues

Publication date Defect number Description
2015-2-23 SPL-92796 Size of scheduled PDF in email attachment does not respect the setting in dashboard (clone: SPL-92782).
2015-2-23 SPL-93672 PDF generation fails when a tmp="" field is used for charting (clone: SPL-91707).
2015-2-23 SPL-92635 PDF reports display black boxes when there is a Chinese character in html tags in dashboard xml. (clone: SPL-90361).
2015-2-23 SPL-95528 Inadequate messaging when rendering PDF report of A5 size if the table is too big (clone: SPL-80872).

Search, saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
2014-12-01 SPL-92736 Scheduler ignores user/owner user_pref time zone setting for cron scheduled searches, runs cron scheduled search in relation to system time.
2015-2-23 SPL-91207 After upgrade from 5.0.5 to 6.1.1, email alert missing line break for multi-line event (cloned from SPL-90800)
2015-2-23 SPL-93730 For Alert Actions, CSV files Attached emails create line breaks after 900 characters (clone: SPL-90711).
2015-2-23 SPL-93955 timechart $function$(x) by y" drops several days worth of data during the search finalization stage (clone: SPL-96033, SPL-92509).
2015-2-23 SPL-93862 Addcoltotals does not apply label correctly and instead sums up string "values" in label column (clone: SPL-91857).
2015-2-23 SPL-93734 AUTO_KV_JSON conf parameter missing spec (clone: SPL-93251).
2015-2-23 SPL-93431 Scheduled searches are sometimes slow, and data collected to track search concurrency is sometimes calculated incorrectly (clone: SPL-92572).
2015-2-23 SPL-93057 Changing the Date in "Date & Time Range" Search Resets Time to 00:00:00.
2015-2-23 SPL-94951 When event is too long, the event processor fails to process events (clone: SPL-90387).
2015-2-23 SPL-94261 Extras spaces appear in search after clicking on "interesting fields" (clone: SPL-92474).
2015-2-23 SPL-92535 head " command is used.

Splunk Web and Home interface issues

Publication date Defect number Description
Pre-6.1.5 SPL-86219 Too many custom timeranges in the UI, can cause the default ranges to not be displayed in the droplist.
2015-2-23 SPL-93732 Search timeliner bucketed incorrectly in certain timezones (Clone: SPL-88624).
2015-2-23 SPL-93564 Manager page user dropdown truncates list to 250 users. (Clone: SPL-90989)
2015-2-23 SPL-93660 Manager page user dropdown truncates list to 250 users. (Clone: SPL-90989)
2015-2-23 SPL-94514 Add Data: All sourcetypes do not appear in list.
2015-2-23 SPL-93846 Locale other than en-US still use the US format in the datepicker.
2015-2-23 SPL-94588 Time range picker does not reflect settings in ui-prefs.conf when searching from "Data Summary" (clone: SPL-93845).

Distributed deployment an forwarder issues

Publication date Defect number Description
Pre-6.2 SPL-80215 Duplicate entries in Forwarder Management for some of the Deployment Clients.
2015-2-23 SPL-94913 Universal Forwarder crashes due to nfs file system glitch. (Clones SPL-95954, SPL-94030)

Deployment server issues

Publication date Defect number Description
2015-01-12 SPL-93988 Deployment server misleadingly records an attempt to uninstall an app. "Updating record action=Install result=Ok". "Updating record action=Install result=Fail"
2015-2-23 SPL-94036 Upon client unpack the deployment server throws an error that local.meta cannot be found (clone: SPL-74255).
2015-2-23 SPL-93239 Deployment Server crashes while editing serverclasses.conf with REST API calls (clone: SPL-92074).
2015-2-23 SPL-93988 Deployment server misleadingly records an attempt to uninstall an app.

Distributed search and search head clustering issues

Publication date Defect number Description
2015-01-12 SPL-93913 Scheduling PDF delivery for Report on a Search Head Cluster crashes search head.

Windows-specific issues

Publication date Defect number Description
2015-02-09 SPL-96452 IE9: select Upload files in Settings > Add Data displays: Your browser does not support file uploads. Please download and install the latest version or use another supported browser to access this feature.
2015-2-09 SPL-94244 Indexing throughput with CSV indexed extractions hits a ~2MB/s ceiling (on recommended hardware) when the data is forwarded (SPL-93436).
2015-2-23 SPL-94459 Splunk-perfmon.exe leaks memory on Windows 8.1 (clone: SPL-80972).
2015-2-23 SPL-94582 Splunk 6.2 log in page does not load on IE 11 with compatibility mode enabled for intranet.
2015-2-23 SPL-93412 Universal forwarders on Windows 2008 are unable to properly send events to IDX (clone: SPL-92533).

REST, Simple XML, and Advanced XML issues

Publication date Defect number Description
2014-11-14 SPL-63024 SPL-91858 SPL-92595 The series names in a piechart panel may turn to "undefined" if the panel is resized. The workaround is to reload the page.

Web Framework issues

Publication date Defect number Description
Pre-6.2
If you do not set the "value" property when you first create a TimeRange view, you get an error if you try to change "earliest_time" and "latest_time" properties later.

Unsorted issues

Publication date Defect number Description
2014-12-29 SPL-94954 Enabling boot-start in AIX gives 'Failed to set effective and real user to value of env var SPLUNK_OS_USER.
2015=2=23 SPL-95333 Login Page - Splunkd should set X-UA-Compatible: IE=edge response header for the login page.
2015-2-23 SPL-93308 Batch primary jobs are scheduled last (clone: SPL-91567).
2015-2-23 SPL-94414 KV Store (FIPS enabled) - caCertPath does not expand environment variables (clone: SPL-93813).
2015-2-23 SPL-94291 Pool selector in the License Usage view does not filter names containing spaces (clone: SPL-93577).
2015-2-23 SPL-93468 High number of duplicate events with "useACK=true" (clone: SPL-92620).
2015-2-23 SPL-93824 Users can control error messages on 404 error page.
2015-2-23 SPL-92963 Splunk on AIX fails to start as nonroot when it is installed in boot start (clone: SPL-96032).
2015-2-23 SPL-94507 Deploying an app with incorrect index settings crashes Splunkd deployment client (clone: SPL-94299).
2015-2-23 SPL-92438 "splunk disable boot-start" doesn't cleanly remove all previously created files in rc.d (clone: SPL-91525).
2015-2-23 SPL-94954 AIX - With boot-start enabled seeing 'Failed to set effective and real user to value of env var SPLUNK_OS_USER'
2015-2-23 SPL-93105 Path Disclosed by CherryPy for static URLs (clone: SPL-89246).
2015-2-23 SPL-93944 Running splunk as "non root" user with shell - /bin/false.
2015-2-23 SPL-92736 Scheduler ignores user/owner user_perf time zone settings for cron scheduled searches.
2015-2-23 SPL-93754 Nessus scan of Splunk ports causes Splunk to crash: Change of behavior from 6.1.
PREVIOUS
6.2.3
  NEXT
6.2.1

This documentation applies to the following versions of Splunk® Enterprise: 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters