Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.3.2

Splunk Enterprise 6.3.2 was released on December 16, 2015.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.


Upgrade issues

This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "How to upgrade Splunk Enterprise" in the Installation Manual.

Publication date Defect number Description
2015-12-16 SPL-109050 Crash during upgrade of Enterprise Security app from 3.3.2 to 4.0 on Windows search head.
2015-12-16 SPL-108911, SPL-104384 Splunk startup after an upgrade takes a very long time to complete in NFS environments.
2015-12-16 SPL-108053 After upgrade to 6.3 scheduler.log shows empty skip reason for scenarios where the admin is not allowed to run historical scheduled search
2015-12-16 SPL-107449 After upgrade to 6.3 some Splunk web elements are missing due to cookie arrays failing to be parsed.

Data input issues

Publication date Defect number Description
2015-12-16 SPL-109016, SPL-105359 Oneshot does not use file modtime when indexing data with no timestamps
2015-12-16 SPL-97119, SPL-93979 Incorrect parent name reported for a given file in the tailing processor file status endpoint

Distributed deployment, forwarder, and deployment server issues

Publication date Defect number Description
2015-12-16 SPL-109499, SPL-109473, SQA-2883 On data inputs page, the available hosts and server class list shows only 30 items
2015-12-16 SPL-108920 Universal Forwarder - crashing thread: Tcplistener.
2015-12-16 SPL-108226 Windows universal forwarder wraps JSON output of Powershell modular input in double quotes.
2015-12-16 SPL-108220 Cannot update apps installed from deployment server if app was deployed with an install_source_checksum
2015-12-16 SPL-106003, SPL-105533 The number of deployed client does not count up on the apps tab on forwarder management page

Distributed search and search head clustering issues

Publication date Defect number Description
2015-12-16 SPL-108993, SPL-104439 Deleting a global saved search after cloning also deletes the cloned search.
2015-12-16 SPL-108633, SPL-104204 Some REST-based searches that target the whole SHC group cause the deployer instance to return an error.

Indexers and indexer clustering issues

Publication date Defect number Description
2015-12-16 SPL-109080, SPL-105360 Fixup Tasks in clustering_bucket_details includes tasks that should not and will not be fixed.
2015-12-16 SPL-108584, SPL-107322 Indexer fails to start, with crashing thread: SplunkdSpecificInitThread.
2015-12-16 SPL-108244, SPL-107657 Converting a multisite indexer cluster to single-site breaks clustering due to unmet Replication Factor and Search Factor.

Integrated PDF generation and PDF Report Server issues

Publication date Defect number Description
2015-12-16 SPL-108612, SPL-107168 Values set for reportPaper and reportPaperOrientation in alert_actions conf in the app context are ignored.
2015-12-16 SPL-105853, SPL-105388 Unable to render PDF for a table with sparklines that have empty values.

REST, Simple XML, and Advanced XML issues

Publication date Defect number Description
2015-12-16 SPL-108113, SPL-108083 Dropdown form input fails to render with values when token is used.
2015-12-16 SPL-107326, SPL-103621 Some DB Connect pages fail to load when root_endpoint value starts with splunkd.
2015-12-16 SPL-107325, SPL-104988 Real-time dashboard panel is not updated when there is no matching search result.

Search, saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
2015-12-16 SPL-109562, SPL-103417 When limits are enforced and a new search request would be over the limit, the server returns the wrong HTTP response code of 500 instead of 503.
2015-12-16 SPL-109346, SPL-105638 Performance issue due to realtime_schedule being enabled unexpectedly.
2015-12-16 SPL-109305, SPL-105642 tstat queries using prestats and append do not work when using earliest and latest
2015-12-16 SPL-109132, SPL-107402 Scheduled search skipped with reason message "Out of search disk space" or "maxsearches limit reached".
2015-12-16 SPL-108771, SPL-97756 Searching JSON silently fails to produce complete results
2015-12-16 SPL-108433 Power user having read and write permissions for a saved search owned by an admin user is unable to view results from scheduled email
2015-12-16 SPL-108228, SPL-104263 When an eventtype name contains a space, its labels are removed if its permissions are changed to Global.
2015-12-16 SPL-108156, SPL-106212 Unable to send CSV files through email from Splunk for some transfer protocols
2015-12-16 SPL-108053 After upgrade to 6.3 scheduler.log shows empty skip reason for scenarios where the admin is not allowed to run historical scheduled search
2015-12-16 SPL-107742 Transaction and stats command returns 0 results
2015-12-16 SPL-107582, SPL-107423 Incomplete event detail is rendered on clicking "show all lines" link for a realtime search
2015-12-16 SPL-107449 After upgrade to 6.3 some Splunk web elements are missing due to cookie arrays failing to be parsed.
2015-12-16 SPL-107223 A real-time (all time) search for "index=*" does not return expected results when indexed_realtime_use_by_default is set to 1
2015-12-16 SPL-106687, SPL-105639 WHERE clause of timechart changes last Column header to "OTHER" even if top and bottom criteria is not present
2015-12-16 SPL-106659, SPL-103860 Splunk denial of service when search-time bundles are larger than maxBundleSize in distsearch.conf.
2015-12-16 SPL-106296, SPL-102937 "is_scheduled" parameter does not work when adding saved-search with CLI.
2015-12-16 SPL-106298, SPL-101452 Timechart search return only OTHER and/or NULL columns when the index data sets is large and the split-by field has large distinct values.
2015-12-16 SPL-106279, SPL-104536 As a user I want to know the latest/earliest value of the a string field in pivot editor

Splunk Web and Home interface issues

Publication date Defect number Description
2015-12-16 SPL-108034 Blank Page when loading Field extraction
2015-12-16 SPL-105476, SPL-104482 "Build Event Type" fails in Splunk web when truncating indexed Russian event strings

Unsorted issues

Publication date Defect number Description
2015-12-16 SPL-108651, SPL-105946 Proper day is not extracted when time format includes only day, hour, minute, and second.
2015-12-16 SPL-108369, SPL-96466 UI behavior has changed for SSO authentication login failure
2015-12-16 SPL-107532, SPL-72052 Stats outputs multiple columns for the same field when renaming several different calculations to that field name
2015-12-16 SPL-106327, SPL-103715 Simultaneous "splunk restart splunkweb" and "splunk stop" cause crashing race condition in HTTPDispatch Thread
2015-12-16 SPL-105661, SPL-105660 Include support for TLS 1.2 by default in server.conf and web.conf.
2015-12-16 SPL-105271, SPL-102526 Splunkd fails to load due to symbol gzdirect not exported from libz on AIX

Windows-specific issues

Publication date Defect number Description
2015-12-16 SPL-106847, SPL-103145 MonitorNoHandle.exe uses all available RAM
PREVIOUS
Transparent huge memory pages and Splunk performance
  NEXT
6.3.1

This documentation applies to the following versions of Splunk® Enterprise: 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters