6.5.1
Splunk Enterprise 6.5.1 was released on November 21, 2016.
The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.
Issues are listed in all relevant sections. Some issues appear more than once.
Data input issues
Date resolved
|
Issue number
|
Description
|
2016-10-20 |
SPL-129605, SPL-111204 |
Forwarder issues following symbolic links may result in links being deleted
|
Search issues
Date resolved
|
Issue number
|
Description
|
2016-11-10 |
SPL-131454, SPL-129846 |
The backslash \ character in search terms outside of quote pairs is not working correctly in search strings
|
2016-10-31 |
SPL-130899, SPL-113332 |
Search functions "TERM" & "CASE" misbehave when there is a field alias in use.
|
2016-10-28 |
SPL-130470 |
Merging of a Calculated field with base search gives inconsistent results
|
2016-10-25 |
SPL-130317, SPL-121380 |
DispatchManager doesn't use quotes to write the value of the "reason" field in splunkd.log, leads to broken auto field extraction
|
2016-10-25 |
SPL-130685, SPL-129538 |
loadjob on Search Head Cluster (SHC) brings oldest run rather than latest
|
2016-10-21 |
SPL-126718, SPL-125020 |
Change Role Based Quota Logging to WARN from DEBUG
|
2016-10-20 |
SPL-128638, SPL-126179 |
MultiSelectInput/MultiDropdownView is crashing Internet Explorer 11
|
2016-10-20 |
SPL-129600, SPL-128797 |
Anomalies Command triggers Error "A separating field was not found. Carrying on without it."
|
2016-10-20 |
SPL-127460, SPL-122807 |
selfjoin search command changes the order of search results column when operates on large results sets resulting in wrong search results for the following search pipeline
|
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2016-10-25 |
SPL-130298, SPL-122468 |
action.email.reportFileName not being honored for csv/pdf attachements
|
2016-10-23 |
SPL-130327, SPL-125556 |
The exported csv filename is garbled when alert title is more than 17 multi-byte characters
|
2016-10-12 |
SPL-129870, SPL-130165 |
PDF and CSV attachments don't show up when viewing email on iPhone's default mail application
|
2016-10-10 |
SPL-129422, SPL-125549 |
False positive alert of realtime schedule search when restarting splunk
|
Charting, reporting, and visualization issues
Date resolved
|
Issue number
|
Description
|
2016-11-08 |
SPL-130186, SPL-124997 |
Dashboard Check Boxes Altered From UI Do Not Alter the Source
|
Data model and pivot issues
Date resolved
|
Issue number
|
Description
|
2016-10-13 |
SPL-128283, SPL-125443 |
"New Pivot" editor doesn't return all results in distributed search env
|
Indexer and indexer clustering issues
Date resolved
|
Issue number
|
Description
|
2016-11-09 |
SPL-130544, SPL-54805 |
clustering - warm bucket w/ partial slice 0 file confuses slave when brought up
|
2016-10-25 |
SPL-129599, SPL-126850 |
Slow rolling restart of indexers in an indexer cluster with high number of buckets combined with data model summaries - If summary replication is not being used setting 'summary_replication=disabled' on all peers will improve rolling restart performance.
|
2016-10-25 |
SPL-130648, SPL-128790 |
Inconsistent buckets_to_summarize setting error when restarting cluster master after making changes to SF or RF
|
Distributed search and search head clustering issues
Date resolved
|
Issue number
|
Description
|
2016-11-13 |
SPL-131770, SPL-127407 |
SHC - Conf replication failures caused by JSON strings exceeding 512KB
|
2016-10-25 |
SPL-129014, SPL-129012 |
The spec file for election_timeout_ms need to be updated as the information about HB is wrong
|
2016-10-25 |
SPL-130685, SPL-129538 |
loadjob on Search Head Cluster (SHC) brings oldest run rather than latest
|
2016-10-25 |
SPL-128604, SPL-122602 |
Memory leak triggered by reloading splunkd SSL servers without restarting the process.
|
2016-10-25 |
SPL-130745, SPL-125447 |
SHC nodes overloaded with jobs waiting at 100% or 0%
|
2016-10-25 |
SPL-128149, SPL-123853 |
Show all settings in SHC not functioning properly
|
2016-10-13 |
SPL-128283, SPL-125443 |
"New Pivot" editor doesn't return all results in distributed search env
|
Universal forwarder issues
Date resolved
|
Issue number
|
Description
|
2016-11-01 |
SPL-123436, SPL-123027 |
Deployment client should be able to communicate with DS on SSL or non SSL port - independent of it's management port settings.
|
2016-10-20 |
SPL-129605, SPL-111204 |
Forwarder issues following symbolic links may result in links being deleted
|
Splunk Web and interface issues
Date resolved
|
Issue number
|
Description
|
2016-11-15 |
SPL-127744, SPL-124444 |
user timezone list and add data timezone setting inconsistent
|
2016-10-26 |
SPL-130025, SPL-130888 |
Order of Apps in dropdown menu not consistent from Launcher Home
|
2016-10-25 |
SPL-129359, SPL-128210 |
Table Page not refreshed when refreshing search
|
2016-10-20 |
SPL-128638, SPL-126179 |
MultiSelectInput/MultiDropdownView is crashing Internet Explorer 11
|
Rest, Simple XML, and Advanced XML issues
Date resolved
|
Issue number
|
Description
|
2016-10-25 |
SPL-128610, SPL-121332 |
Getting error "'NoneType' object has no attribute '_cafile'" when trying to install an app via the REST API
|
Authentication and Authorization issues
For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.
Date resolved
|
Issue number
|
Description
|
2016-10-27 |
SPL-130062, SPL-125654 |
Splunk authentication audit logs do not contain the source address of the attempt
|
2016-10-20 |
SPL-126744, SPL-122988 |
Forcing HTTPS on splunkd breaks compatibility with the CLI for reloading auth and deploy-server even with enabling an additional localhost-only httpServerListener with SSL disabled.
|
Admin and CLI issues
Date resolved
|
Issue number
|
Description
|
2016-10-20 |
SPL-126744, SPL-122988 |
Forcing HTTPS on splunkd breaks compatibility with the CLI for reloading auth and deploy-server even with enabling an additional localhost-only httpServerListener with SSL disabled.
|
2016-10-20 |
SPL-130356, SPL-124349 |
Update display.page.search.mode=verbose description in spec file
|
Unsorted issues
Date resolved
|
Issue number
|
Description
|
2016-11-13 |
SPL-95384, SPL-92068 |
Mac OS 10.9.5 does not support the splunk enable boot-start command
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2016-11-17 |
SPL-130104, SPL-118166 |
When addcoltotals command is used in the search, the chart fails to render in pdf export
|
2016-11-04 |
SPL-131070, SPL-131424 |
After changing login page background, additional unrelated settings will be added to the local/web.conf
|
2016-11-03 |
SPL-130181, SPL-126100 |
Splunk field extraction using delimiter as " (double quote) works in preview but fails to create a valid search extraction
|
2016-10-25 |
SPL-129597, SPL-127297, SPL-129598, SPL-131783 |
Export pdf for a dashboard the locale for time chart
|
2016-10-25 |
SPL-129512, SPL-128140 |
Cannot save control characters in Searches
|
2016-10-20 |
SPL-130350, SPL-130285, SPL-130351 |
Chart legend overlay on PDF
|
2016-10-20 |
SPL-127260, SPL-126535 |
Dashboard replace eval-function does not perform a global replacement
|
Feedback submitted, thanks!