6.3.2
Splunk Enterprise 6.3.2 was released on December 16, 2015.
The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.
Upgrade issues
This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "How to upgrade Splunk Enterprise" in the Installation Manual.
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-109050 |
Crash during upgrade of Enterprise Security app from 3.3.2 to 4.0 on Windows search head.
|
2015-12-16 |
SPL-108911, SPL-104384 |
Splunk startup after an upgrade takes a very long time to complete in NFS environments.
|
2015-12-16 |
SPL-108053 |
After upgrade to 6.3 scheduler.log shows empty skip reason for scenarios where the admin is not allowed to run historical scheduled search
|
2015-12-16 |
SPL-107449 |
After upgrade to 6.3 some Splunk web elements are missing due to cookie arrays failing to be parsed.
|
Data input issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-109016, SPL-105359 |
Oneshot does not use file modtime when indexing data with no timestamps
|
2015-12-16 |
SPL-97119, SPL-93979 |
Incorrect parent name reported for a given file in the tailing processor file status endpoint
|
Distributed deployment, forwarder, and deployment server issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-109499, SPL-109473, SQA-2883 |
On data inputs page, the available hosts and server class list shows only 30 items
|
2015-12-16 |
SPL-108920 |
Universal Forwarder - crashing thread: Tcplistener.
|
2015-12-16 |
SPL-108226 |
Windows universal forwarder wraps JSON output of Powershell modular input in double quotes.
|
2015-12-16 |
SPL-108220 |
Cannot update apps installed from deployment server if app was deployed with an install_source_checksum
|
2015-12-16 |
SPL-106003, SPL-105533 |
The number of deployed client does not count up on the apps tab on forwarder management page
|
Distributed search and search head clustering issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-108993, SPL-104439 |
Deleting a global saved search after cloning also deletes the cloned search.
|
2015-12-16 |
SPL-108633, SPL-104204 |
Some REST-based searches that target the whole SHC group cause the deployer instance to return an error.
|
Indexers and indexer clustering issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-109080, SPL-105360 |
Fixup Tasks in clustering_bucket_details includes tasks that should not and will not be fixed.
|
2015-12-16 |
SPL-108584, SPL-107322 |
Indexer fails to start, with crashing thread: SplunkdSpecificInitThread.
|
2015-12-16 |
SPL-108244, SPL-107657 |
Converting a multisite indexer cluster to single-site breaks clustering due to unmet Replication Factor and Search Factor.
|
Integrated PDF generation and PDF Report Server issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-108612, SPL-107168 |
Values set for reportPaper and reportPaperOrientation in alert_actions conf in the app context are ignored.
|
2015-12-16 |
SPL-105853, SPL-105388 |
Unable to render PDF for a table with sparklines that have empty values.
|
REST, Simple XML, and Advanced XML issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-108113, SPL-108083 |
Dropdown form input fails to render with values when token is used.
|
2015-12-16 |
SPL-107326, SPL-103621 |
Some DB Connect pages fail to load when root_endpoint value starts with splunkd.
|
2015-12-16 |
SPL-107325, SPL-104988 |
Real-time dashboard panel is not updated when there is no matching search result.
|
Search, saved search, alerting, scheduling, and job management issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-109562, SPL-103417 |
When limits are enforced and a new search request would be over the limit, the server returns the wrong HTTP response code of 500 instead of 503.
|
2015-12-16 |
SPL-109346, SPL-105638 |
Performance issue due to realtime_schedule being enabled unexpectedly.
|
2015-12-16 |
SPL-109305, SPL-105642 |
tstat queries using prestats and append do not work when using earliest and latest
|
2015-12-16 |
SPL-109132, SPL-107402 |
Scheduled search skipped with reason message "Out of search disk space" or "maxsearches limit reached".
|
2015-12-16 |
SPL-108771, SPL-97756 |
Searching JSON silently fails to produce complete results
|
2015-12-16 |
SPL-108433 |
Power user having read and write permissions for a saved search owned by an admin user is unable to view results from scheduled email
|
2015-12-16 |
SPL-108228, SPL-104263 |
When an eventtype name contains a space, its labels are removed if its permissions are changed to Global.
|
2015-12-16 |
SPL-108156, SPL-106212 |
Unable to send CSV files through email from Splunk for some transfer protocols
|
2015-12-16 |
SPL-108053 |
After upgrade to 6.3 scheduler.log shows empty skip reason for scenarios where the admin is not allowed to run historical scheduled search
|
2015-12-16 |
SPL-107742 |
Transaction and stats command returns 0 results
|
2015-12-16 |
SPL-107582, SPL-107423 |
Incomplete event detail is rendered on clicking "show all lines" link for a realtime search
|
2015-12-16 |
SPL-107449 |
After upgrade to 6.3 some Splunk web elements are missing due to cookie arrays failing to be parsed.
|
2015-12-16 |
SPL-107223 |
A real-time (all time) search for "index=*" does not return expected results when indexed_realtime_use_by_default is set to 1
|
2015-12-16 |
SPL-106687, SPL-105639 |
WHERE clause of timechart changes last Column header to "OTHER" even if top and bottom criteria is not present
|
2015-12-16 |
SPL-106659, SPL-103860 |
Splunk denial of service when search-time bundles are larger than maxBundleSize in distsearch.conf.
|
2015-12-16 |
SPL-106296, SPL-102937 |
"is_scheduled" parameter does not work when adding saved-search with CLI.
|
2015-12-16 |
SPL-106298, SPL-101452 |
Timechart search return only OTHER and/or NULL columns when the index data sets is large and the split-by field has large distinct values.
|
2015-12-16 |
SPL-106279, SPL-104536 |
As a user I want to know the latest/earliest value of the a string field in pivot editor
|
Splunk Web and Home interface issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-108034 |
Blank Page when loading Field extraction
|
2015-12-16 |
SPL-105476, SPL-104482 |
"Build Event Type" fails in Splunk web when truncating indexed Russian event strings
|
Unsorted issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-108651, SPL-105946 |
Proper day is not extracted when time format includes only day, hour, minute, and second.
|
2015-12-16 |
SPL-108369, SPL-96466 |
UI behavior has changed for SSO authentication login failure
|
2015-12-16 |
SPL-107532, SPL-72052 |
Stats outputs multiple columns for the same field when renaming several different calculations to that field name
|
2015-12-16 |
SPL-106327, SPL-103715 |
Simultaneous "splunk restart splunkweb" and "splunk stop" cause crashing race condition in HTTPDispatch Thread
|
2015-12-16 |
SPL-105661, SPL-105660 |
Include support for TLS 1.2 by default in server.conf and web.conf.
|
2015-12-16 |
SPL-105271, SPL-102526 |
Splunkd fails to load due to symbol gzdirect not exported from libz on AIX
|
Windows-specific issues
Publication date
|
Defect number
|
Description
|
2015-12-16 |
SPL-106847, SPL-103145 |
MonitorNoHandle.exe uses all available RAM
|
Feedback submitted, thanks!