Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.4.6

Splunk Enterprise 6.4.6 was released on February 23, 2017.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Data input issues

Date resolved Issue number Description
2017-01-30 SPL-128091, ADDON-10817, SPL-131411, SPL-131412 Modular input data loss during shutdown
2016-11-30 SPL-130819, SPL-132976, SPL-132973, SPL-132974, SPL-132975 CHECK_METHOD = modtime not working as expected

Search issues

Date resolved Issue number Description
2017-02-02 SPL-134622, SPL-135104 Intentions parser should escape quotes
2017-01-31 SPL-134324, SPL-136037, SPL-136038, SPL-136039, SPL-136040 Show Source is throwing "Failed to find the target event with valid host and source values"
2017-01-20 SPL-127061, SPL-135415, SPL-135416 xpath default value always returned and absolute path is not working
2017-01-04 SPL-133218, SPL-133215 IP location is wrongly geo mapped
2016-12-22 SPL-134059, SPL-136306, SPL-136307 Cloning a dashboard does not copy height option
2016-12-13 SPL-133802, SPL-132970 Limit on search process memory usage can result in splunkd crash
2016-11-29 SPL-132384, SPL-122729 Emit a user-facing INFO search message when a wildcard is used as an infix in a term to explain that this could yield unexpected results if the wildcard covers punctuation
2016-11-18 SPL-122219, SPL-137049, SPL-137048 "Orphaned Scheduled Searches" search can fail in a rest call timeout if LDAP, SAML, requests for all users take more than 60 seconds

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2017-02-06 SPL-134527, SPL-136412, SPL-136101, SPL-136102, SPL-136103 Customer is missing email alerts - only message is "ERROR sendemail:1199 - expected string or buffer"
2017-01-31 SPL-129193, SPL-135567, SPL-135568, SPL-135569 Scheduled alert Fails to send email when alert condition has been met
2017-01-31 SPL-123465, SPL-136028, SPL-136029, SPL-136031, SPL-136035 Password cleared in server email settings unless it's entered for every change.
2017-01-04 SPL-131791, SPL-130630 Distributed Search Groups not honored for data model acceleration searches
2017-01-04 SPL-132285, SPL-125345 views using post process searches with subsearches hit user search concurrency and fail to execute vs queueing the search

Charting, reporting, and visualization issues

Date resolved Issue number Description
2016-12-22 SPL-134059, SPL-136306, SPL-136307 Cloning a dashboard does not copy height option

Data model and pivot issues

Date resolved Issue number Description
2017-01-04 SPL-131791, SPL-130630 Distributed Search Groups not honored for data model acceleration searches

Indexer and indexer clustering issues

Date resolved Issue number Description
2016-12-16 SPL-133892, SPL-113104 Misleading log message when Indexer Discovery fails in forwarders due to mismatch in pass4SymmKey.
2016-12-02 SPL-131040, SPL-88000 The Cluster Master produces unclear admin-facing messages when it rejects a Cluster Peer due to stand-alone bucket issues

Distributed search and search head clustering issues

Date resolved Issue number Description
2017-02-01 SPL-130744, SPL-125447 SHC nodes overloaded with jobs waiting at 100% or 0%
2017-01-27 SPL-135748, SPL-132495, SPL-135637, SPL-135638 Improve error logging around the case of a failure to copy a deployed app from the temporary download location to the destination app folder.
2017-01-19 SPL-134619, SPL-123768, SPL-127407 Long file path (>255 characters) can break the tarball creation and lead to snapshot creation failure.
2016-12-06 SPL-131906, SPL-131030 Clarify fetch_remote_search_log in limits.conf.spec
2016-12-02 SPL-132893, SPL-133354, SPL-133355, SPL-133356 SHC - Large number of connections created when a peer is down
2016-12-01 SPL-131861, SPL-127343 SHC issue: S2SFileReceiver - Unable to create destFolder. Show shcluster-status shows some nodes oscillating between Up, Down and Pending status; search performance has degraded
2016-11-29 SPL-131130, SPL-133179 Search Result returns incorrect result sometimes _pq->fetchResults() returns 'true' but !et.isZero()

Universal forwarder issues

Date resolved Issue number Description
2017-01-19 SPL-135019, SPL-134112 Unactionable error message for invalid server URIs in outputs.conf.
2017-01-06 SPL-134071, SPL-117117 Splunk Forwarder Service terminated unexpectedly occurs on several customer's environment
2016-12-06 SPL-132960, SPL-120612 Splunk Universal Forwarder on AIX 7.1 crashes when host not listed in AcceptFrom in inputs.conf file on indexers
2016-12-01 SPL-132620, SPL-128710 Having many forwarders, forwarding to an intermediate forwarder, can result in intermediate crashing in certain scenarios

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2017-01-20 SPL-131510, SPL-134238, SPL-134239, SPL-134240 Forwarder Management interface doesn't show all clients if they have the same hostname and port.
2017-01-10 SPL-134690, SPL-123636 Apps cannot be uninstalled by forwarder management

Monitoring Console/DMC issues

Date resolved Issue number Description
2017-02-01 SPL-135105, SPL-134608 The outdated indexing_volume dashboard is not showing accurate information and should be removed

Splunk Web and interface issues

Date resolved Issue number Description
2016-11-23 SPL-131300, SPL-134160, SPL-132537, SPL-132538 Mssing time change for the -6:00 Time Zone. Guadalajara Mexico City Monterrey

Windows-specific issues

Date resolved Issue number Description
2017-01-04 SPL-133009, SPL-122692 Continuous splunk-winprintmon failures reported
2017-01-04 SPL-132290, SPL-128887 Forwarding Windows Security log is indexing first line only
2016-12-05 SPL-112544, SPL-133514, SPL-133515, SPL-133516 MonitorNoHandle causes BSOD when configured to monitor on a non-existent drive

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2017-01-30 SPL-135558, SPL-123831 LDAPS Auth issue - Cannot establish connection with TLSv1.2 disabled
2016-12-15 SPL-133669, SPL-131060 Roles missing inside SAML Settings While using Chrome

Admin and CLI issues

Date resolved Issue number Description
2017-01-26 SPL-119992, SPL-130547, SPL-130548 btool returns incorrect output for inputs.conf with certain modular and scripted input combinations
2016-12-06 SPL-131906, SPL-131030 Clarify fetch_remote_search_log in limits.conf.spec

Unsorted issues

Date resolved Issue number Description
2017-01-30 SPL-133508, SPL-118161, SPL-141789 Windows Installer fails if wrong version of difxapi.dll already installed
2017-01-26 SPL-130887, SPL-130958, SPL-130957, SPL-133353 Running "yum install splunk" on RHEL6 with FIPS kernel results in error - Splunk RPM uses MD5 for file digest
2017-01-05 SPL-127301, SPL-122994 Crash in TcpChannelThread, MongoStorageProvider, BSONObjFiller, parse, gotNull.
2017-01-05 SPL-133905, SPL-133816 keepAliveIdleTimeout as WARN message is polluting logs causing false alarm
2016-12-13 SPL-133012 Debian installer leaves files owned by unknown user
2016-12-02 SPL-133066, SPL-131647 HTTP Event Collector doesn't start accepting events until debug is turned on (issueReload=true doesn't reload app on Deployment Client)

Uncategorized issues

Date resolved Issue number Description
2017-01-27 SPL-131707, SPL-135270, SPL-135272, SPL-135466 Indexer doesn't immediately sync the ingested events to disk (in a specific scenario)
2017-01-26 SPL-129267, SPL-135709, SPL-135707, SPL-135708 Extra event created when SOURCE_KEY = MetaData:Host|Source|Sourcetype and DEST_KEY=_raw in transforms
2017-01-19 SPL-134241, SPL-133728 Inaccurate description for pollingTimerFrequency in server.conf.spec.
2017-01-13 SPL-134501, SPL-135024, SPL-135025, SPL-135026 Add validation to transforms.conf DELIMS as it does not support non-ASCII delimiters.
2016-12-15 SPL-125450, SPL-132398 Field Transformations with DELIM not searchable via GUI
2016-12-09 SPL-125236, SPL-130828, SPL-130841, SPL-128975 field extraction with delimiter(::) does not match result data
PREVIOUS
6.4.7
  NEXT
6.4.5

This documentation applies to the following versions of Splunk® Enterprise: 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters