Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.3.5

Splunk Enterprise 6.3.5 was released on June 6, 2016.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Data input issues

Date resolved Issue number Description
2016-05-05 SPL-119573, SPL-115015 Powershell Script stops running randomly until Splunk restart
2016-05-05 SPL-113737, SPL-109285 Workflow Actions will not send more than 9 POST arguments

Search issues

Date resolved Issue number Description
2016-05-10 SPL-119195, SPL-119918, SPL-119917 Default_partitions limit causes "no results found" for "| stats count"
2016-05-09 SPL-109359, SPL-122084, SPL-119860, SPL-113555 "| rest /services/search/jobs" search fails when the output of "/services/search/jobs" is greater than 10MB
2016-05-09 SPL-109308, SPL-110966, SPL-119847, SPL-110102 timechart range broken for timezones with daylight savings transitions that occur at midnight
2016-05-06 SPL-109717, SPL-119750, SPL-119751, SPL-119749 Incorrect Audit Logs for REST API Searches: completed searches shown as cancelled (info=cancelled result_count=0)
2016-05-06 SPL-108774, SPL-105581 (6.3.5) - Search with an eval or calculated field which calls the tostring(..., "duration") function fails with: "Invalid number"
2016-05-05 SPL-119254, SPL-104555 Multi-search returns different results than both single searches
2016-05-05 SPL-112485, SPL-105269 (6.3.5) - Calculated fields fail to expand when preceded by a NOT expression without a parenthesized sub-term
2016-04-28 SPL-115712, SPL-109222 splunk CLI option '-output csv' does not retain the field ordering
2016-04-22 SPL-116961, SPL-113915 The search returns different results when the user switches Preview/No Preview settings
2016-04-22 SPL-114811, SPL-118571, SPL-118570, SPL-120653 joining several loadjob commands in a search fails to find artifacts in SHC
2016-04-21 SPL-117213, SPL-118164, SPL-118165, SPL-118163 Distributed Search Groups not honored when using | tstats command
2016-04-19 SPL-116619, SPL-113383 Using "split" in calculated fields returns error in UI when trying to save.
2016-04-05 SPL-114861, SPL-116092, SPL-116094, SPL-116088, SPL-116089, SPL-116090, SPL-116091, SPL-116093 cache-control header is missing from the response headers for the /api/lists/entities/ requests
2016-04-01 SPL-102845, SPL-117012, SPL-122091, SPL-115933, SPL-115934 Incorrect backslash expansion for props.conf source:: stanzas
2016-03-31 SPL-111939, SPL-116929, SPL-116931, SPL-116930 The report "save as report" and "edit search" dialogs allow to accelerate a search that uses macros, eventtypes or tags even though we do not fully support that
2016-03-31 SPL-103762, SPL-116876, SPL-116875, SPL-116878, SPL-116879, SPL-121205 Wrong search results for high cardinality events if stats fields are in non-lexicographical order

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2016-05-06 SPL-110282, SPL-105134 (6.3.5) - sendemail fails due to invalid control characters in the result
2016-04-07 SPL-114407, SPL-117276, SPL-117360, SPL-117277 UI does not pass the app name in the backend request for alert actions
2016-04-01 SPL-114703, SPL-116945, SPL-116946, SPL-116944, SPL-121839 scheduled searches with _accelerate in the search query are not visible in the job_management page

Charting, reporting, and visualization issues

Date resolved Issue number Description
2016-05-27 SPL-115970, SPL-114823, SPL-118852, SPL-118857, SPL-118856 Number of values returned to a sparkline for a 7-day range search does not have enough granularity
2016-05-10 SPL-114781, SPL-117991, SPL-117992, SPL-117990 single value on a long timechart resultset will truncate the results and not display the last value
2016-05-03 SPL-113709, SPL-118853, SPL-118855, SPL-118854 Tick values on y-axis exceeds the max value limit when other y-axis has higher max value limit set
2016-04-22 SPL-117006, SPL-118573 Browser crashes on loading a chart when the dataset contains null values
2016-04-17 SPL-107741 Dashboard editor automatically change base search for post-process search from "BaseSearch" to "global"
2016-04-12 SPL-114091, SPL-117653, SPL-117656, SPL-117655 On iOS devices, the column and bar charts are rendered with an extra tick

Indexer and indexer clustering issues

Date resolved Issue number Description
2016-05-09 SPL-109416, SPL-108130 (6.3.5) - Empty hot bucket stays forever and causes issues with bucket replication
2016-05-06 SPL-119185, SPL-108603 Splunk Enterprise hanging on startup due to index configuration
2016-04-25 SPL-115979 IndexerTPoolWorker-1 crashed in PipelineInputChannel::drop_reference
2016-04-25 SPL-116920, SPL-118719, SPL-118722, SPL-118720 Events sent to non-existent index cause ERROR EAIOutParameters - invalid entry title in toAtom(): INDEXER_MISSING_INDEX
2016-04-11 SPL-115814, SPL-117259, SPL-117260, SPL-117258 Crashing thread: indexerPipe when index is readOnly

Distributed search and search head clustering issues

Date resolved Issue number Description
2016-05-23 SPL-121172, SPL-117758 searches were killed but SHC captain thinks they are still running and won't schedule more jobs
2016-05-09 SPL-113189, SPL-119829, SPL-119735, SPL-119830, SPL-120081 SHC members do not always restart properly after bundle push
2016-05-06 SPL-119653, SPL-102909 Remove description of CLI "splunk shcluster-maintenance-mode" from the CLI help
2016-04-26 SPL-113346, SPL-118758, SPL-118759 Search Head Clustering - Scheduled Searches not able to be delegated due to usernames from AD with spaces
2016-04-19 SPL-118102, SPL-114605 Search head cluster captain refuses connections from other SHC members including itself resulting in all scheduled searches stopping
2016-04-13 SPL-116547, SPL-116976, SPL-116942, SPL-116943, SPL-116977 In search head clustering, loadjob fails if the savedsearch name contains spaces
2016-04-01 SPL-115032, SPL-116974 alert action manager not visible on Search Head Cluster
2016-04-01 SPL-114888, SPL-116960, SPL-116973, SPL-116959 Unable to find existing bundles and thereby required full replications instead every time on windows

Universal forwarder issues

Date resolved Issue number Description
2016-05-11 SPL-119283, SPL-119998, SPL-120007, SPL-120014 Universal Forwarder's exceeding throughput limits - maxKBps not being honored
2016-04-20 SPL-118152, SPL-114212 UF stops sending events, tcp failover issue
2016-04-12 SPL-117326, SPL-116103 Some csv files are reindexed after restarting the Indexer

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2016-05-09 SPL-118506, SPL-108619 The forwarder management display an inconsistency result when deployment client has 2 host name with one IP address

Data Management Console Issues

Date resolved Issue number Description
2016-05-05 SPL-116846, SPL-119546, SPL-119547 User name must be "admin" to apply changes in distributed mode DMC.

Splunk Web and interface issues

Date resolved Issue number Description
2016-04-05 SPL-114861, SPL-116092, SPL-116094, SPL-116088, SPL-116089, SPL-116090, SPL-116091, SPL-116093 cache-control header is missing from the response headers for the /api/lists/entities/ requests
2016-03-31 SPL-111939, SPL-116929, SPL-116931, SPL-116930 The report "save as report" and "edit search" dialogs allow to accelerate a search that uses macros, eventtypes or tags even though we do not fully support that

Windows-specific issues

Date resolved Issue number Description
2016-05-08 SPL-119730, SPL-117235 Event log fields not extracted properly, majority of field extractions are missing

Rest, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2016-05-06 SPL-109717, SPL-119750, SPL-119751, SPL-119749 Incorrect Audit Logs for REST API Searches: completed searches shown as cancelled (info=cancelled result_count=0)
2016-05-05 SPL-113737, SPL-109285 Workflow Actions will not send more than 9 POST arguments

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2016-05-04 SPL-106219, SPL-106184 (6.3) - Splunkd crashes with bad kvstore query

PDF issues

Date resolved Issue number Description
2016-04-07 SPL-117143, SPL-117300, SPL-117359, SPL-117301 Name of scheduled PDF report changed to lowercase
2016-04-05 SPL-116240, SPL-116818, SPL-116820, SPL-116819 The title of the dashboard panel is rendered on a different page when at least one panel has different height as compared to other panels in the exported pdf

Admin and CLI issues

Date resolved Issue number Description
2016-05-05 SPL-118898, SPL-116182 btprobe Not Working On Windows System
2016-04-22 SPL-112214, SPL-117233, SPL-117234 check-path and rename-source throwing invalid key errors due to missing values in *.spec files
2016-04-18 SPL-111489, SPL-109584 (6.3.5) - log.cfg allows various log locations to be changed. Causes issues for diag and DMC

Unsorted issues

Date resolved Issue number Description
2016-12-13 SPL-116968, SPL-119459, SPL-119458 Only default squash_threshold value(2000) is taken in consideration on LicenseSlave
2016-05-13 SPL-116651, SPL-118661, SPL-118662 forwarding to both standalone and indexerDiscovery, only cluster peers have data, nothing on standalone server.
2016-05-06 SPL-118425, SPL-118191 diag stores index files at the wrong name if the index path contains a non-directory literal prefix of the index path. e.g. SPLUNK_HOME=/foo SPLUNK_DB=/foobar
2016-05-05 SPL-114478, SPL-112839 Misleading, non-actionable messaging when a license slave cannot connect to a license master because of mismatched pass4SymmKeys
2016-05-04 SPL-106219, SPL-106184 (6.3) - Splunkd crashes with bad kvstore query

Uncategorized issues

Date resolved Issue number Description
2016-06-06 SPL-114585, SPL-117366 Columns don't always move properly in the event table view.
2016-05-18 SPL-114849, SPL-117127, SPL-117125, SPL-117126 When "useDeploymentServer = 1" is configured, the HTTP Event Collector gui breaks
2016-05-06 SPL-115877, SPL-119774, SPL-119773 Getting list of users on hitting "en-US/api/lists/entities/admin/users" endpoint first time after restart takes a long time
2016-04-18 SPL-116745, SPL-116662 Splunk Fails to Start and Crash After Windows OS Crash
2016-04-18 SPL-117777, SPL-117866, SPL-117864, SPL-117865 JsonStreamingParser crashed in SearchResultsInfo::fromSearchResults
2016-04-15 SPL-117543, SPL-117683, SPL-117684, SPL-117685, SPL-117690 Supportability- Splunk in DEBUG suddenly misses timezone in logs.
2016-04-08 SPL-113893 No available & free disk space recorded in /services/server/status/partitions-space & disk_objects.log / component=Partitions for a specific disk device
2016-03-31 SPL-116110, SPL-116264, SPL-116261, SPL-116263 German dropdowns for Alert Expiration have incorrect wording
PREVIOUS
6.3.6
  NEXT
6.3.4

This documentation applies to the following versions of Splunk® Enterprise: 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters