Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF


Splunk Enterprise 6.2.4 was released on July 7, 2015.

The following issues have been resolved in this release:

Security issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal .

Data input issues

Publication date Defect Description
7-7-2015 SPL-99499 XSS via host value for cherrypy (appServerPorts=0) redirects.
7-7-2015 SPL-101718 XSS via host value for splunkd (appServerPorts=8065) redirects.
Publication date Defect number Description
7-7-2015 SPL-100990 Duplicate events occur because of clock skew between source and Splunk (Clone: SPL-98328).
7-7-2015 SPL-99354 props.conf LINE_BREAKER with initial zero-width capture group discards first character of event.
7-7-2015 SPL-98763 When useACK=true, the UF takes 6-7 minutes to restart, and does not forward any log events from that time.
7-7-2015 SPL-98438 recursive=false for one of multiple monitor inputs with overlapping paths causes duplicate events.
7-7-2015 SPL-96167 Inconsistent event merging of iis logs with delimiter containing a double quote followed by a closing curly brace (“}).

Charting, reporting, and visualization issues

Publication date Defect number Description
7-7-2015 SPL-100849 Incorrect drilldown search generated by "fillnull" and "rangemap".
7-7-2015 SPL-100845 SimpleXML dashboard panel raises malformed error when postprocess search contains tabs.

Indexers and indexer clustering issues

Publication date Defect number Description
7-7-2015 SPL-100953 register_replication_address and register_search_address do not work as documented(Clone: SPL-100211).
7-7-2015 SPL-100331 selectiveIndexing does not index events while still forwarding data.
7-7-2015 SPL-99961 Cannot move bloomHomePath to filesystem outside of bucket.
7-7-2015 SPL-99878 Crash on Cluster master manager UI - CMBucketToIndexInfo - Integer division by zero.
7-7-2015 SPL-99820 Splunk does not catch all exceptions in JournalSRReaderThread and handle it safely (Clones: SPL-91274).
7-7-2015 SPL-98823 Splunk Introspection process crashes due to "Assertion failed: minuend.tv_sec >= subtrahend.tv_sec" (Clone:SPL-94942).

Data model and Pivot issues

Publication date Defect number Description
7-7-2015 In the Data Model editor, if user clicks a field in the lookup dropdown, changes the field name and saves the change, when navigating back to the same page, the original field name still displays.
7-7-2015 SPL-101723 In DataPreview, Splunk treats file as a directory and does not allow preview.
2015-01-12 SPL-94277 While creating a Pivot, when I split rows by time and select the format "Year", it returns this value: 2014-01-01 00:00:00.

Integrated PDF generation and PDF Report Server issues

Publication date Defect number Description
7-7-2015 SPL-100303 PDF: Pie chart is missing from the generated PDF (Clone: SPL-98436).

Search, saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
7-7-2015 SPL-102211 CSV attachment sent by the scheduled alert contains line break after 900 characters.
7-7-2015 SPL-101802 Hong Kong timezone abbreviation - HKT - is not recognized from an event.
7-7-2015 SPL-101502 The resize bar of visualization container appears over the search assistant container.
7-7-2015 SPL-100717 OUTPUT option in lookup clears destination fields irrespective of the existence of the input fields.
7-7-2015 SPL-100309 A search with two sets of earliest/latest time modifiers on each side of an OR returns inconsistent results.
7-7-2015 SPL-99985 Drill-down on field returns HandleIntentionsParserDataProvider error.
7-7-2015 SPL-99722 Multikv.conf isn't recognized on an indexer when it is passed as part of the bundle.
7-7-2015 SPL-98841 Y-Axis max value does not reflect correctly on a panel.
7-7-2015 SPL-98742 Time Range Picker doesn't return error message when inputting a wrong time range.
7-7-2015 SPL-98702 Search results might be incomplete error with pre 6.2 search peers.
7-7-2015 SPL-98694 Splunk Web fails to parse huge xml responses from Splunkd.
7-7-2015 SPL-97805 Splunkd Segmentation Fault (Signal 11) in Scheduler thread occurs when re-validating user SessionToken during scheduling of a saved search.
7-7-2015 SPL-95282 auto_summarize.timespan fails to read manual valid ranges, generates error
7-7-2015 SPL-95098 ResultsTable with fieldname 'watch' gets considered as timestamp by default on firefox.
7-7-2015 SPL-95070 Extra Fields Visible And Persisted Across Transforming Commands.

Splunk Web and Home interface issues

Publication date Defect number Description
7-7-2015 SPL-100511 404 Not Found after creating a dashboard from the listing page in the manager namespace.

Distributed deployment, forwarder, and deployment server issues

Publication date Defect number Description
7-7-2015 SPL-100694 Huge serverclass.conf file causes the Forwarder Management page to stay blank. (Clone:SPL-94242 )

Distributed search and search head clustering issues

Publication date Defect number Description
7-7-2015 SPL-98251 Throttling setting does not apply to all nodes of the Search Head Cluster.
7-7-2015 SPL-101615 Peers incorrectly report 4 billion replications in high latency environments (Clone: SPL-98488)
7-7-2015 SPL-100910 Search head cluster fails to parse search string when a search string is the same as a control character, increasing size of splunkd_stderr.log 75GB (Clone: SPL-98396)
7-7-2015 SPL-100508 Search Head Pooling on Windows does not allow splunkweb to start when splunk installed on a non C drive
7-7-2015 SPL-100184 modifying lookup table file in-place (outputlookup append=t) while upload is already in-flight triggers assertion in HttpClientConnection::asyncWriteComplete() (Clone: SPL-99958)
7-7-2015 SPL-99279 Search head clustering summary indexing searches run multiple times causing duplicate data
7-7-2015 SPL-98576 DistributedPeerMonitorThread thread on SH Splunkd crashed due to race condition for _myLicenseKeys
7-7-2015 SPL-97805 Splunkd Segmentation Fault (Signal 11) in Scheduler thread when revalidating user SessionToken during scheduling of a saved search.
7-7-2015 SPL-97116 Search error messages are cluttering the search page

Windows-specific issues

Publication date Defect number Description
7-7-2015 SPL-101532 CPU object is shown instead of Processor object in the available objects list for the local performance monitoring
7-7-2015 SPL-98887 Missing browser support message for IE8 when user is accessing splunk through SSO

REST, Simple XML, and Advanced XML issues

Publication date Defect number Description
7-7-2015 SPL-101836 The time ticks on x-axis fails to render when charting.legend.labels option is used in the dashboard xml.

Unsorted issues

Publication date Defect number Description
7-7-2015 SPL-101198 Web.conf privKeyPath and caCertPath are pre-pending $SPLUNK_HOME dir to directories that are an absolute path (Clones: SPL-86733 )
7-7-2015 SPL-99363 KVStore creates files in shared memory.
7-7-2015 SPL-99205 Splunk on AIX fails to start as nonroot user when the user has no read permissions for /etc/inittab.
7-7-2015 SPL-99169 Invalid key 'pass4SymmKey' in stanza [deployment] in /opt/splunk/etc/system/local/server.conf.
7-7-2015 SPL-98426 Error in 'appendcols' command: You can only use appendcols after a reporting command (such as stats, chart, or timechart) (Clone: SPL-93020).
7-7-2015 SPL-98134 CSV logs are broken incorrectly, causing delayed indexing.
7-7-2015 SPL-97825 Splunk web should use the new API directory listing API. (Clone: SPL-98934 )
7-7-2015 SPL-96736 disk_objects.log / group = partitions doesn't show mount points used for volumes on mounted filesystems
7-7-2015 SPL-94540 Unable to Install Splunk 6.2 on SunOS 10 Sparc machines with "`SUNW_1.22.6' not found" error.
7-7-2015 SPL-92618 Splunk Introspection for CPU-time produces incorrectly high values on busy system -- instrument-resource-usage records values > 100% in resource_usage.log for system-wide CPU usage (component=Hostwide / cpu_system_pct and cpu_user_pct). (Clone: SPL-91396)
7-7-2015 SPL-92589 Stats command spends a lot of time in finalizing phase when max_mem_usage_mb = 0.

This documentation applies to the following versions of Splunk® Enterprise: 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15


Fixed the link. Thanks for pointing it out, JoshWhaley!

Andrewb splunk, Splunker
August 20, 2015

The link under "Security Issues" for "Security Portal" needs to be fixed. It incorrectly links to http://www.splunk.com/http://www.splunk.com/page/securityportal instead of http://www.splunk.com/page/securityportal. Just a heads up.

August 20, 2015

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters