Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF


Splunk Enterprise 6.3.4 was released on April 20, 2016.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Security Issues

Publication date Defect number Description
2016-04-22 SPL-115109 Upgrade to OpenSSL 1.0.2g.

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Data input issues

Publication date Defect number Description
2016-04-22 SPL-111594 On a monitor stanza with a direct subdirectory with it's own monitor stanza, setting recursive=false prevents monitoring.
2016-04-22 SPL-109964 Splunkd crash on archivereader. (Clone: SPL-109032)
2016-04-22 SPL-109966 Indexing duplicate events after restart when .gz files are monitored. (Clone: SPL-106997)
2016-04-22 SPL-110377 Bug during applyPendingMetadata, header processor does not own the indexed extractions confs. (Clone: SPL-92461 )

Search, saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
2016-04-22 SPL-110901 Editing Mail Action in an Alert will delete / uncheck "Summary Indexing" enabled.
2016-04-22 SPL-108971 Only having a Mint license without an Enterprise license crashes searches.
2016-04-22 SPL-112269 CLI search returns 0 results when using a cron-scheduled shell script. (clone: SPL-110866)
2016-04-22 SPL-111629 Splunk crashes on job management page when searches contain NOT clause.
2016-04-22 SPL-111881 Cursor mode returns some duplicate results under certain conditions.
2016-04-22 SPL-112851 Crashing thread: DispatchReaper - assert fail in TimeFormat::render().
2016-04-22 SPL-113907 Cursor mode search results can have missing events under certain conditions.
2016-04-22 SPL-114611 Visualization tab shows warning messages which are already in the job drop down.
2016-04-22 SPL-114334 Event summary dialog of the add data page shows <ode>-1 as events count while uploading the data.
2016-04-22 SPL-112851 Crashing thread: DispatchReaper - assert fail in TimeFormat::render(). (Clone: SPL-58137)
2016-04-22 SPL-110142 null password gets hashed and breaks email alerts.
2016-04-22 SPL-93584 The search job inspector no longer clearly advertises when a search is using a report-acceleration automatic summary.
2016-04-22 SPL-115477 In certain condition, accessing the jobs management dashboard would get one of these errors in the UI:
This EntityLister module could not retrieve its results. A 503 error was returned with the following text "Service Unavailable".
[JobManager module] 'str' object has no attribute 'os_startIndex'

Data model and Pivot issues

Publication date Defect number Description
2-16-04-22 SPL-115318 Filter dropdown in pivot ignores the timerange settings while dispatching a search.
2016-04-22 SPL-110805 Time restrictions not passed when creating new pivot.
2016-04-22 SPL-114765 appendcols returns zero results

Splunk Web, DMC, and Home interface issues

Publication date Defect number Description
2016-04-22 SPL-115356 Slash "/" in the selected directory on Add Data menu is translated to "%2F"
2016-04-22 SPL-112478 +3K savedsearches stanza loads app too slow.
2016-04-22 SPL-113798 Table row numbers in the dashboard panel are not updated when navigating to different pages using the paginator.
2016-04-22 SPL-111513 Chained relative_time offsets do not work in dashboard.
2016-04-22 SPL-112383 "'Search more apps'" feature does not work when using proxy.
2016-04-22 SPL-111488 Line break characters do not work in email messages.
2016-04-22 SPL-110384 Dashboard panel shows "Waiting for data..." message when custom search command is used in the post-process search.
2016-04-22 SPL-110303 The DMC indexing performance views need a note about parallel pipelines compatibility. (Clone: SPL-110299)
2016-04-22 SPL-107999 When a dashboard containing extension scripts and stylesheets from other app context is cloned, the cloned dashboard does not contain the extension scripts and stylesheets.

Charting, reporting, and visualization issues

Indexer and index processor issues

Publication date Defect number Description
2016-04-22 SPL-111079 Crash in PipelineInputChannel::setIndexedExtractionsDestructive.
2016-04-22 SPL-115549 Index reload fails because of trailing slash in path inside indexes.conf.
2016-04-22 SPL-111596 Non-UTF8 file names monitored by universal forwarder causes Indexers to crash. (Clone: SPL-106537)

Distributed deployment, forwarder, and deployment server issues

Publication date Defect number Description
2016-04-22 SPL-113772 DistributedPeerHandler::handleEditCreate() crash adding search peer. (Clone: SPL-112794)
2016-04-22 SPL-112310 Deployment Sever displays warn message when app name contains the word "download". (Clone: SPL-111535)
2016-04-22 SPL-113405 Forwarder Management Add data - Unable to add inputs with unique serverclasses and same sourcepath.

Distributed search and search head clustering issues

Publication date Defect number Description
2016-04-22 SPL-110513 srchJobsQuota and rtSrchJobsQuota are not centralized across search head clusters. (Clone: SPL-101954 )
SPL-112836 Local.meta modtime change for a blacklisted lookup file causes high frequency full bundle replication.
2016-04-22 SPL-114702 After search head update from 6.2.x to 6.3.x, distributed search fails because peer has status = "Down".
2016-04-22 SPL-114354 Hanging search processes using all available CPUs on the search head.
2016-04-22 SPL-114658 Backport fix for crash in DispatchCommand::dumpPipelineSetsFile(). (Clone:SPL-111602)
2016-04-22 SPL-112294 CMPeerJob does not provide an error message describing failures. (Clone: SPL-112217 )
2016-04-22 SPL-115988 Search results link from result sharing workflow don't work on receiving peers.

Windows-specific issues

Publication date Defect number Description
2016-04-22 SPL-111356 "Plus" button for the machine type filter on the forwarder management page does not display on IE ver.11.
2016-04-22 SPL-112734 UF fails to install on Windows7 workstations via SCCM.

Unsorted issues

Publication date Defect number Description
2016-04-22 SPL-113816 Splunk does not report the correct Hardware-CPU information on startup or via REST.
2016-04-22 SPL-114422 Assert in SSLCommon::init() if alternate name in the incoming certificate doesn't match.
2016-04-22 SessionToken::Locked_revalidate_user(time_t): Assertion `_p->refcnt >= 2' failed.
2016-04-22 SPL-113431 Exported PDF shows "year=1 is before 1900; the datetime strftime() methods require year >= 1900" error message when the last row of table does not contain any value for _time column.
Last modified on 23 August, 2016
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020

This documentation applies to the following versions of Splunk® Enterprise: 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters