Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.4.5

Splunk Enterprise 6.4.5 was released on December 15, 2016.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Data input issues

Date resolved Issue number Description
2016-11-30 SPL-129395, SPL-130332, SPL-130331 Splunk is crashing while reading *.CSV files
2016-11-14 SPL-130802, SPL-129109 After upgrading from UF 6.3.2 to either UF 6.3.6 or 6.4.3 or 6.5.0/1, monitored files with Structured header are read at the wrong offset by WTF resulting in duplicate, missed, broken events
2016-11-10 SPL-129086, SPL-131945, SPL-131946, SPL-131947 Garbled field name when indexing zip file (UTF-16LE)
2016-10-31 SPL-123413, SPL-135829, SPL-131129, SPL-131124, SPL-131125 FileClassifierManager doesn't take settings from sourcetype for zipped files
2016-10-20 SPL-129603, SPL-111204 Forwarder issues following symbolic links may result in links being deleted
2016-09-28 SPL-128410, SPL-124282 Resolve crashing thread: archivereader

Search issues

Date resolved Issue number Description
2016-11-17 SPL-128702, SPL-132457, SPL-133208 Realtime dashboards crash browser after a time period due to memory leak
2016-11-15 SPL-125932, SPL-130288, SPL-130289 No error showing in dashboards when user's disk quota is reached
2016-11-15 SPL-131514, SPL-122992 Outputcsv used with quoted filenames retains the quotes in the filename causing failures on Windows
2016-10-27 SPL-128797, SPL-129595, SPL-129600 Anomalies command triggers error "A separating field was not found. Carrying on without it."
2016-10-24 SPL-130560, SPL-124350 Search returns "Unknown error for peer.." But peer search artifacts show no error
2016-09-23 SPL-128762, SPL-121380 DispatchManager doesn't use quotes to write the value of the "reason" field in splunkd.log, leads to broken auto field extraction

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2016-11-30 SPL-122468, SPL-130299, SPL-130298 action.email.reportFileName not being honored for csv/pdf attachements
2016-11-15 SPL-130326, SPL-125556 The exported csv filename is garbled when alert title is more than 17 multi-byte characters
2016-11-10 SPL-131672, SPL-129264 Alert fails due to persistant alert_condition when counttype goes from "custom" to "number of events"
2016-10-05 SPL-129421, SPL-125549 False positive alert of realtime schedule search when restarting splunk
2016-09-23 SPL-128760, SPL-124730 No reason is recorded in scheduler.log entries for deferred (status=continued) searches
2016-09-23 SPL-128758, SPL-120021 Scheduler.log reasons are not helpful in understanding why searches are skipped

Charting, reporting, and visualization issues

Date resolved Issue number Description
2016-11-17 SPL-128702, SPL-132457, SPL-133208 Realtime dashboards crash browser after a time period due to memory leak
2016-11-15 SPL-125932, SPL-130288, SPL-130289 No error showing in dashboards when user's disk quota is reached
2016-11-02 SPL-130310, SPL-130966, SPL-130967 When a user has write permission to an app, the same user can delete a dashboard created by other user within the same app from the views manager page but not from the dashboards listing page
2016-09-27 SPL-128210, SPL-129359, SPL-129360 Table Page not refreshed when refreshing search

Data model and pivot issues

Date resolved Issue number Description
2016-10-13 SPL-128282, SPL-125443 "New Pivot" editor doesn't return all results in distributed search env

Indexer and indexer clustering issues

Date resolved Issue number Description
2016-11-18 SPL-130869 PCRE MATCH_LIMIT parameter not applied to index time field extractions
2016-11-15 SPL-130913, SPL-94303 CM did not show an "All Searchable" state even after an extended time with many freezing jobs at peer
2016-11-15 SPL-131856, SPL-122205 Cluster peer down after running delete command
2016-11-11 SPL-130545, SPL-54805 Warm bucket w/ partial slice 0 file confuses slave when brought up
2016-10-24 SPL-128790, SPL-130648, SPL-130649 Inconsistent buckets_to_summarize setting error when restarting cluster master after making changes to SF or RF
2016-10-04 SPL-126850, SPL-129596, SPL-129599, SPL-132781 summary scans can result in peer taking a long time to re-join cluster after rolling restart

Distributed search and search head clustering issues

Date resolved Issue number Description
2016-12-07 SPL-129036, SPL-131361, SPL-131360, SPL-135443 Reduce csv tmp file name length to reduce chance of hitting 260 char path length in Windows NTFS
2016-11-23 SPL-119859, SPL-132605, SPL-132803 Contention holding up incoming search requests if there are a large number of buckets resulting in HTTP server queue drops and potential instability of cluster.
2016-11-22 SPL-126219, SPL-131422, SPL-131423 Log warning when configuration reloads are issued too frequently.
2016-11-22 SPL-129943, SPL-132634, SPL-132780, SPL-132801, SPL-133920 metrics.log Metrics reporting gaps due to contention with bundle replication
2016-11-22 SPL-132807, SPL-131398 Search head cluster contention on Linux due to poor hashing inside OpenSSL's error container.
2016-11-15 SPL-131769, SPL-127407 SHC - Conf replication failures caused by JSON strings exceeding 512KB should provide admins with an actionable recourse
2016-11-15 SPL-131859, SPL-103458 When configuration replication is broken between SHC members, $SPLUNK_HOME/var/run/splunk/snapshot fills up with bundle files until disk space runs out
2016-10-27 SPL-123790, SPL-131005, SPL-131006, SPL-131007 Crashing thread: HttpListener Assertion `_toSendState == TOSEND_VIRGIN || _toSend TOSEND_UNSET' failed.
2016-10-24 SPL-130560, SPL-124350 Search returns "Unknown error for peer.." But peer search artifacts show no error
2016-10-24 SPL-130416, SPL-112240, SPL-130704 Log message for SHC conf replication baseline issue is missing actionable information.
2016-10-21 SPL-129538, SPL-130685, SPL-130686 loadjob on Search Head Cluster (SHC) brings oldest run rather than latest
2016-10-13 SPL-128282, SPL-125443 "New Pivot" editor doesn't return all results in distributed search env
2016-09-23 SPL-128758, SPL-120021 Scheduler.log reasons are not helpful in understanding why searches are skipped
2016-09-23 SPL-129013, SPL-129012 Correct spec file for election_timeout_ms with corrected information about heartbeats
2016-09-23 SPL-121164, SPL-108140 "splunk show shcluster-status" incorrectly mentions "search head pool" instead of "search head cluster"

Universal forwarder issues

Date resolved Issue number Description
2016-11-14 SPL-130802, SPL-129109 After upgrading from UF 6.3.2 to either UF 6.3.6 or 6.4.3 or 6.5.0/1, monitored files with Structured header are read at the wrong offset by WTF resulting in duplicate, missed, broken events

Splunk Web and interface issues

Date resolved Issue number Description
2016-10-26 SPL-120039, SPL-125666, SPL-126385, SPL-126386 Table view in real-time search does not expand the event

Windows-specific issues

Date resolved Issue number Description
2016-11-18 SPL-132420, SPL-129082 Large amount of forwarders connecting to a Windows indexer causes sockets to remain in a CLOSE_WAIT state

Rest, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2016-11-16 SPL-127448, SPL-119588 Credential Manager /services/storage/passwords stops working when decrypted password is not utf8
2016-09-23 SPL-128609, SPL-121332 Error "'NoneType' object has no attribute '_cafile'" when trying to install an app via the REST API

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2016-11-16 SPL-127448, SPL-119588 Credential Manager /services/storage/passwords stops working when decrypted password is not utf8
2016-11-03 SPL-94016, SPL-131336, SPL-131337 Expand TLS Control settings for KV store.
2016-10-12 SPL-129879, SPL-128746 Explicitly disable JavaScript support in KVStore Backend
2016-09-23 SPL-125654, SPL-130064, SPL-130062 Splunk authentication audit logs do not contain the source address of the attempt

PDF issues

Date resolved Issue number Description
2016-11-23 SPL-127297, SPL-129597, SPL-129598 Export pdf for a dashboard ignores the locale for time chart
2016-11-17 SPL-130103, SPL-118166, SPL-132451 When addcoltotals command is used in the search, the chart fails to render in pdf export
2016-11-14 SPL-123604, SPL-131167, SPL-131166 Missing timezone information at PDF footer

Admin and CLI issues

Date resolved Issue number Description
2016-11-11 SPL-130822, SPL-131889, SPL-131890 Splunk startup is delayed by validation of non-essential XML files.
2016-11-07 SPL-129435, SPL-131517, SPL-131518 Clicking save after running out of disk space with empty Indexes searched by default and Indexes list on the manager page will remove all the previously selected indexes
2016-10-20 SPL-130355, SPL-124349 Update display.page.search.mode=verbose description in spec file

Unsorted issues

Date resolved Issue number Description
2016-11-15 SPL-130023, SPL-132013, SPL-132329 High HTTP Response times due to contention for lock in logUserActionInfo
2016-11-03 SPL-131329, SPL-128480 Splunk fails to validate file system on macOS sierra (10.12) with HFS
2016-11-03 SPL-94016, SPL-131336, SPL-131337 Expand TLS Control settings for KV store.
2016-11-01 SPL-127436, SPL-131405, SPL-131210 syslog forwarding does not work with IPv6+UDP connection

Uncategorized issues

Date resolved Issue number Description
2016-11-15 SPL-113906, SPL-131772, SPL-131776 Setting disk object introspection log channels to DEBUG fails to provide detailed information on the objects it iterates on
2016-10-12 SPL-126100, SPL-130181, SPL-130182 Splunk field extraction using delimiter as " (double quote) works in preview but fails to create a valid search extraction
2016-09-30 SPL-128140, SPL-129512, SPL-129513 Cannot save control characters in searches
PREVIOUS
6.4.6
  NEXT
6.4.4

This documentation applies to the following versions of Splunk® Enterprise: 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters