Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF


Splunk Enterprise 6.4.3 was released on August 22, 2016.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Data input issues

Date resolved Issue number Description
2016-08-05 SPL-121549, SPL-124544 Sinkhole inputs fail to index file if file is still being written to on first attempt to read
2016-08-02 SPL-102939, SPL-125707, SPL-126848, SPL-126849 Archive Processor cannot handle zip files if they contain Japanese characters in the file name..

Search issues

Date resolved Issue number Description
2016-08-17 SPL-123133, SPL-95575 SortProcessor::getStreamingOp crashes in appendpipe subsearch due to inserting streaming operators into report search

Distributed search and search head clustering issues

Date resolved Issue number Description
2016-07-28 SPL-120037, SPL-115793 Error messaging unclear when there are failures creating replication bundles.
2016-07-28 SPL-123774, SPL-80967 Configuration bundles corrupted during creation might be replicated, causing issues in other servers.
2016-07-22 SPL-124244, SPL-119757 Artifact replication failing due to origin node trying to replicate itself and causing the original artifact to never reap.
2016-07-22 SPL-124762, SPL-121746 Increase default value for max_chunk_queue_size from 1MB to 10MB

Universal forwarder issues

Date resolved Issue number Description
2016-08-01 SPL-123781, SPL-125393 dropped events messages in splunkd are INFO; should be WARN

Monitoring Console/DMC issues

Date resolved Issue number Description
2016-08-03 SPL-121812, SPL-119348 DMC doesn't support Cluster Label with space in it

Windows-specific issues

Date resolved Issue number Description
2016-08-16 SPL-122695, SPL-118920 Windows local user added to domain group does not properly translate SID/GUIDs.

Admin and CLI issues

Date resolved Issue number Description
2016-07-22 SPL-124762, SPL-121746 Increase default value for max_chunk_queue_size from 1MB to 10MB

Unsorted issues

Date resolved Issue number Description
2016-08-16 SPL-123528, SPL-124453 Clarification on where to make squash_threshold changes
2016-07-28 SPL-123338, SPL-125198 When splunk is configured as license slave, the "show all messages" link on the licensing page returns 404 not found
2016-07-28 SPL-119539, SPL-126209 After upgrading 6.3.x/6.2.x HWFs to 6.4.x, queues block and data is heavily delayed.
2016-07-25 SPL-122846, SPL-123882 Forwarder RPM package failing to install due to missing useradd and groupadd binaries.
2016-07-15 SPL-123630, SPL-123723 diag fails when index path directory names are shorter than SPLUNK_HOME
2016-07-15 SPL-123622, SPL-123991, SPL-123987, SPL-123988, SPL-123989, SPL-123990 Clustered indexers frequently crashing in TimeoutHeap::checkClockSkew
2016-06-16 SPL-122438, SPL-121429 License related searches need to use source=*license_usage.log* instead of source=*license_usage.log
2016-06-16 SPL-120527, SPL-118185 When "useDeploymentServer = 1", HttpInputConf does not properly load tokens into memory

Uncategorized issues

Date resolved Issue number Description
2016-08-17 SPL-118842, SPL-124241, SPL-124028 Missing Event Type Color for transaction search results including multiple Event Types.
2016-07-28 SPL-123769, SPL-123262 Crashing thread: indexerPipe on failing to write raw data to a hot bucket due to no space on disk
2016-07-07 SPL-122982, SPL-123842 Embedded report uses oldest search artifact from the history endpoint
2016-06-15 SPL-122426, SPL-122057 DNS Host Matching failure for IPv6 addresses
Last modified on 25 March, 2019
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020

This documentation applies to the following versions of Splunk® Enterprise: 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters