Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.4.1

Splunk Enterprise 6.4.1 was released on May 18, 2016.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Saved search, alerting, scheduling, and job management issues

Publication date Defect number Description
2016-04-22 SPL-117301 Name of scheduled PDF report changed to lowercase.
2016-04-22 SPL-117277 UI does not pass the app name in the back end request for alert actions.
2016-04-22 SPL-115720 Email Alerts: 'null' password gets hashed & breaks email alerts.
2016-04-22 SPL-115964 tstats command inside appendcols returns zero results.
2016-04-12 SPL-115991 Event summary dialog of the add data page shows -1 as events count while uploading the data.

Data input issues

Publication date Defect number Description
2016-04-22 SPL-116478 Setting recursive=false on a monitor stanza which has a direct subdirectory that has its own monitor stanza will prevent the subdirectory from being monitored
2016-04-12 SPL-117328 Some csv files are re-indexed upon restarting the Indexer.

Splunk Web and interface issues

Publication date Defect number Description
2016-04-22 SPL-116263 German dropdowns for Alert Expiration have incorrect wording.
2016-04-15 SPL-116930 The report "save as report" and "edit search" dialogs allow to accelerate a search that uses macros, eventtypes or tags even though we do not fully support that.
2016-04-13 SPL-116944 Scheduled searches with _accelerate in the search query are not visible in the job_management page.
2016-04-12 SPL-117139 HTTPS_PROXY environment variable set causes 500 Internal Server Error after login.
2016-04-12 SPL-117217 When using appServerPorts = 0 and SSL, Splunkweb will not start.

Distributed deployment, forwarder, deployment server issues

Publication date Defect number Description
2016-05-17 SPL-119998 Universal Forwarder exceeds throughput limits - maxKBps not honored.
2016-05-13 SPL-118661 Forwarding to both standalone and indexerDiscovery, only cluster peers have data, nothing on standalone server.
2016-04-21 SPL-118187 Universal Forwarder stops sending events due to TCP failover.
2016-04-20 SPL-118095 Forwarder Management Add data - Unable to add inputs with unique serverclasses and same sourcepath.
2016-04-20 SPL-114320 Socket error communicating with splunkd (error=The read operation timed out), path = /services/deployment/server/config/_reload.

Data model and pivot issues

Publication date Defect number Description
2016-04-22 SPL-115964 tstats command inside appendcols returns zero results.
2016-04-12 SPL-115321 Filter dropdown in pivot ignores the timerange settings while dispatching a search

PDF issues

Publication date Defect number Description
2016-05-04 SPL-116819 The title of the dashboard panel is rendered on a different page when at least one panel has different height as compared to other panels in the exported pdf.
2016-04-12 SPL-115083 Exported pdf shows "year=1 is before 1900; the datetime strftime() methods require year >= 1900" error message when the last row of table does not contain any value for _time column.

Admin and CLI issues

Publication date Defect number Description
2016-04-24 SPL-115715 (Splunk CLI option '-output csv' does not retain the field ordering.
2016-04-22 SPL-117233 Check-path and rename-source throwing invalid key errors.
2016-04-20 SPL-114320 Socket error communicating with splunkd (error=The read operation timed out), path = /services/deployment/server/config/_reload

Security issues

Publication date Defect number Description
2016-05-17 SPL-112718 Missing SAMEORIGIN headers on specific redirects.

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Distributed search and search head clustering issues

Publication date Defect number Description
2016-05-09 SPL-119735 SHC members do not always restart properly after bundle push.
2016-05-03 SPL-118683 Summary index does not populate due to race condition between Tailing and Summary search.
2016-04-22 SPL-116741 Hanging search processes using all available CPUs on the search head.
2016-04-20 SPL-116959 Unable to find existing bundles and thereby required full replications instead every time.
2016-04-19 SPL-118107 Search head cluster captain refuses connections from other SHC members including itself resulting in all scheduled searches stopping.
2016-04-13 SPL-116942 SHC: loadjob fails if the savedsearch name contains spaces.

Indexer and indexer clustering issues

Publication date Defect number Description
2016-04-28 SPL-115121 Crash in PipelineInputChannel::setIndexedExtractionsDestructive on 6.2.6.
2016-04-25 SPL-118720 Events sent to non-existent index cause ERROR EAIOutParameters - invalid entry title in toAtom(): INDEXER_MISSING_INDEX.
2016-04-22 SPL-115554 Index reload failing because of trailing slash in path inside indexes.conf.
2016-04-19 SPL-117258 Crashing thread: indexerPipe when index is readOnly.
2016-04-18 SPL-115946 tstats not honoring earliest/latest and providing diff results depending on Time Picker in index clustering.

Charting, reporting, and visualization issues

Publication date Defect number Description
2016-05-10 SPL-117990 Single value on a long timechart resultset will truncate the results and not display the last value.
2016-04-13 SPL-117655 On iOS devices, the column and bar charts are rendered with an extra tick.
2016-04-12 SPL-114442 When a dashboard containing extension scripts and stylesheets from other app context is cloned, the cloned dashboard does not contain the extension scripts and stylesheets.

Unsorted issues

Publication date Defect number Description
2016-05-13 SPL-116611 Only having a Mint license without an Enterprise license crashes searches.
2016-05-02 SPL-119320 Upgrading indexer 6.3.3 to 6.4 fails to generate audit keys.
2016-04-22 SPL-114479 Misleading, non-actionable messaging when a license slave cannot connect to a license master because of mismatched pass4SymmKeys.
2016-04-22 SPL-117339 Universal Forwarder fails to install on Windows7 workstations via SCCM
2016-04-21 SPL-114637 Crash in Paginator::cmp for thread TcpChannelThread.
2016-04-20 SPL-118123 App Install Failing On Windows ( Error installing application: Failed to copy ).
2016-04-20 SPL-116079 Unable to append to KV Store.
2016-04-19 SPL-118193 Diag fails when duplicate apps exist in peer-apps, apps or a search head pool; diag warns about duplicate app & skipping, but still fails w/stack trace.
2016-04-14 SPL-117865 JsonStreamingParser crashed in SearchResultsInfo::fromSearchResults.

Search issues

Publication date Defect number Description
2016-05-13 SPL-116611 Only having a Mint license without an Enterprise license crashes searches.
2016-04-25 SPL-115934 Incorrect backslash expansion for props.conf source:: stanzas.
2016-04-24 SPL-115715 Splunk CLI option '-output csv' does not retain the field ordering.
2016-04-22 SPL-118570 Joining several loadjob commands in a search fails to find artifacts in Search Head Cluster.
2016-04-21 SPL-116965 The search returns different results when the user switches Preview/No Preview settings
2016-04-21 SPL-118163 Distributed Search Groups not honored when using | tstats command.
2016-04-18 SPL-115946 tstats do not honor earliest/latest and providing diff results depending on Time Picker in index clustering.
2016-04-18 SPL-116878 Wrong results from a search containing a very large number of results that have the same timestamp.
2016-04-15 SPL-116930 The report "save as report" and "edit search" dialogs allow to accelerate a search that uses macros, eventtypes or tags even though we do not fully support that.
2016-04-13 SPL-116944 scheduled searches with _accelerate in the search query are not visible in the job_management page.
2016-04-12 SPL-116060 Visualization tab shows warning messages which are already in the job dropdown.
2016-04-12 SPL-117139 HTTPS_PROXY environment variable set causes 500 Internal Server Error after login.
PREVIOUS
6.4.2
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters