Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF


Splunk Enterprise 6.3.1 was released on November 4, 2015.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Upgrade issues

This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "How to upgrade Splunk Enterprise" in the Installation Manual.

Publication date Defect number Description
2015-11-04 SPL-107253 After upgrade searches fail due to vector::_M_range_check exception because of Malformed lookup CSV files.

Distributed deployment, forwarder, and deployment server issues

Publication date Defect number Description
2015-11-04 SPL-102412, SPL-83461 UFs receive ACKs out of order causing huge memory growth.
2015-11-04 SPL-103257, SPL-100887 20k+/hr forwarder connections cause deployment server to become unresponsive
2015-11-04 SPL-104953, SPL-99702 UI: Data Inputs > Forwarded Inputs serverclass name is truncated / incomplete
2015-11-04 SPL-104976, SPL-104626 outputs.conf comments are stripped from file when encrypting SSL password
2015-11-04 SPL-106305, SPL-100624 Very large serverclass.conf causes the Forwarder Management page to stay blank
2015-11-04 SPL-106972 Installing Apps on a Universal Forwarder using the CLI results in the forwarder crashing
2015-11-04 SPL-107738 Forwarder management page displays with incorrect formatting

Distributed search and search head clustering issues

Publication date Defect number Description
2015-11-04 SPL-104474, SPL-103056 Scheduled searches after upgrading from 5.0.6 to 6.2.3 are delayed significantly leading to reports of "skipped" searches due to search processes making additional calls to the /admin/summarization endpoint
2015-11-04 SPL-104672 GenerationGrabberThread asserts on "ita_thread == ThreadToken::self" due to shutdown race condition
2015-11-04 SPL-104885, SPL-103012 Undefined props.acl causes JavaScript SDK to error and stop executing script
2015-11-04 SPL-107053 Unable to start the Web Server under Windows when search head pool is enabled
2015-11-04 SPL-107106 When SAML is enabled, SHC captain becomes unresponsive during periods with high scheduled search activity
2015-11-04 SPL-107524, SPL-106842 SHC Captain crash due to seg fault in CallbackRunnerThread

Indexers and indexer clustering issues

Publication date Defect number Description
2015-11-04 SPL-103900, SPL-103464 Buckets with invalid timebounds cause cluster peer to crash
2015-11-04 SPL-104701, SPL-102940 Assertion raised by archivereader thread while indexing tar log files
2015-11-04 SPL-104835, SPL-104735 Error message thrown in retrieving filesystem for UNC path
2015-11-04 SPL-104955, SPL-104738 Indexer incorrectly stops indexing due to out of disk or too many tsidx files

Integrated PDF generation and PDF Report Server issues

Publication date Defect number Description
2015-11-04 SPL-105152, SPL-104867 Scheduled PDF generation fails when XML encoding does not match content encoding
2015-11-04 SPL-106303, SPL-100294 PDF delivery fails for specific scheduled searches

Search, saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
2015-11-04 SPL-103271, SPL-103270, SPL-100183 Warn when a large lookup table is loaded into memory!
2015-11-04 SPL-103705, SPL-103704, SPL-82385 default remote_timeline_fetchall = 1 in limits.conf causes searches spending long time in Finalizing status
2015-11-04 SPL-104232, SPL-104227, SPL-103419 Indexed lookup returns NULL result when the lookup table has large number of duplicate rows
2015-11-04 SPL-104425, SPL-104427 Role is automatically mapped back to user and LDAP group even after the role is deleted then re-introduced.
2015-11-04 SPL-104475, SPL-103381 Test email contains incorrect subject and message values
2015-11-04 SPL-104560, SPL-103416 Splunk add saved-search with -email parameter creates the typo with action.emai (missing the 'L') in savedsearches.conf
2015-11-04 SPL-104660, SPL-103527 The "fields" command cannot remove "row*" fields created by "transpose" command
2015-11-04 SPL-104884, SPL-104023 Show source displays blank page with message "Show source not available for this event"
2015-11-04 SPL-104951, SPL-104591 Regex in IFX does not allow multiline match in an event
2015-11-04 SPL-105277, SPL-99985 Drill-down on field returns HandleIntentionsParserDataProvider error
2015-11-04 SPL-105405, SPL-103836 Datamodel acceleration status needs to show the correct percentage when backfill parameter is configured
2015-11-04 SPL-107200 Splunk Search Process Crashes - Integer division by zero
2015-11-04 SPL-107253 After upgrade searches fail due to vector::_M_range_check exception because of Malformed lookup CSV files.
2015-11-04 SPL-107263 Backfill script does not accept wildcard for name attribute
2015-11-04 SPL-107270, SPL-103546 Same regex may behave differently between rex command and props.conf.

Splunk Web and Home interface issues

Publication date Defect number Description
2015-11-04 SPL-104471, SPL-103137 Job management view selects an incorrect app when an app name contains another app's appid
2015-11-04 SPL-104473, SPL-103538 Improve messaging for the form input dropdown when there are duplicate values
2015-11-04 SPL-104677, SPL-103168 Cursor jumps to end of line when typing anywhere inside the login form input fields
2015-11-04 SPL-104861, SPL-96663 GDI File directory browser breaks when running behind Apache proxy
2015-11-04 SPL-104883, SPL-104327 HTTP response header provides CherryPy version
2015-11-04 SPL-104886, SPL-97319 In Chrome, the Time field in time picker sizes incorrectly.
2015-11-04 SPL-104952, SPL-100036 GDI Index dropdown displays default index even if write access is not available
2015-11-04 SPL-106302, SPL-103938 Information in Splunk Web and inputs.conf is inconsistent when enabling or disabling TCP input
2015-11-04 SPL-107390 DMC Forwarders: Deployment page shows wrong figure of average events

Unsorted issues

Publication date Defect number Description
2015-11-04 SPL-103614, SPL-103613, SPL-81391 splunkd.log needs to continue to report a authentication forwarding error beyond restart. ERROR TcpOutputProc - Error initializing SSL context - invalid sslCertPath
2015-11-04 SPL-104078, SPL-104017 Splunkd crash due to assertion failure in Tailing.
2015-11-04 SPL-104515 The default value of max_count should be 500000 in limits.conf.spec. (Clones: SPL-104440, SPL-104512, SPL-104513, SPL-104514)
2015-11-04 SPL-104881, SPL-103335 Site minder proxy using unsupported “Content-type” case in XHR response headers cause GET requests to have undefined job id.
2015-11-04 SPL-105147, SPL-103293 support for https protocol when using googlemapview lib
2015-11-04 SPL-106838, SPL-105362 Corrupt/truncated info.csv causes crash in IdataDO_Collector after throwing an instance of JsonStreamingParser::error
2015-11-04 SPL-107105 Splunkd crashes when a SAML Attribute Query receives a bad response
2015-11-04 SPL-107563 SimpleXML chart data count option does not work

Windows-specific issues

Publication date Defect number Description
2015-11-04 SPL-104831, SPL-100643 In Windows, Data Model Acceleration fails to run due to inaccessible distributed search keyfiles.
2015-11-04 SPL-104905, SPL-94305 Windows Security Event Logs are missing when there is a burst of events
2015-11-04 SPL-105113, SPL-101716 Whitelist values ignored when configured in multiple whitelists
2015-11-04 SPL-106785, SPL-104595 perfmon counters at the end of input have an extra tab character at the end of their indexed value
2015-11-04 SPL-107244, SPL-104915 Windows events forwarded as syslog data display hostname before timestamp
Last modified on 23 August, 2016
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters