Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF


Splunk Enterprise 6.3.11 was released on June 6, 2017.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Search issues

Date resolved Issue number Description
2017-05-08 SPL-141460, SPL-138521 Search failing with: 'Streamed search execute failed because: JournalSliceDirectory: Cannot seek to rawdata offset 0' causing alert to be fired
2017-03-30 SPL-138936, SPL-140647, SPL-140648, SPL-140650, SPL-140651 When assureUTF8 is enabled in indexes.conf, errors found in search.log: ERROR RawdataJournal - Converting invalid UTF-8 found in rawdata

Indexer and indexer clustering issues

Date resolved Issue number Description
2017-03-21 SPL-136733, SPL-100516 Events deleted in an index cluster via the delete search operator may be inconsistently deleted on secondaries

Distributed search and search head clustering issues

Date resolved Issue number Description
2017-03-31 SPL-137319, SPL-140664, SPL-140661, SPL-140662, SPL-140663 Search head cluster member can't recover from REMOTE_CHKSUM_UNMATCHED error during bundle replication after SHC captaincy.
2017-03-06 SPL-138167, SPL-137554 mgmt_uri is showing "?" while checking with "splunk show shcluster-status"

Universal forwarder issues

Date resolved Issue number Description
2017-03-31 SPL-140543, SPL-135562 Universal forwarder on AIX attempts to start splunkweb during internally-triggered restart, warns that "SRC did not 'stopsrc splunkweb'".

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2017-04-05 SPL-116884, SPL-141434, SPL-141435, SPL-141500, SPL-141501 When editing forwarded input with same source path, the changes get applied to a different input

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2017-04-27 SPL-137028, SPL-140368, SPL-140370, SPL-140371, SPL-140372 SHC captain crashes after deploying changes in authentication.conf

Unsorted issues

Date resolved Issue number Description
2017-03-22 SPL-104147, SPL-104413, SPL-104969, SPL-140318, SPL-140315, SPL-140316, SPL-140317 Request to disable "splunk instrument-resource-usage" on non-supported platforms

Uncategorized issues

Date resolved Issue number Description
2017-03-07 SPL-137866, SPL-138280, SPL-138281, SPL-138282, SPL-138697 Filter on the listing page is not returning accurate results when splunk contains thousands of dashboards/alerts/reports
2017-03-01 SPL-137211, SPL-136654 PDF Export for line chart does not respect timeline assignment
Last modified on 26 March, 2019

This documentation applies to the following versions of Splunk® Enterprise: 6.3.11, 6.3.12, 6.3.13, 6.3.14

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters