Splunk® Enterprise

Release Notes

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.5.4

Splunk Enterprise 6.5.4 was released on May 25, 2017.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Upgrade issues

This section lists issues that customers have reported when upgrading from an earlier version of Splunk Enterprise. If you are considering an upgrade, please read "How to upgrade Splunk Enterprise" in the Installation Manual.

Date resolved Issue number Description
2017-04-21 SPL-140935, SPL-142015, SPL-142016 6.4.1 to 6.5.3 upgrade overwrites workflow_actions.conf

Search issues

Date resolved Issue number Description
2017-04-27 SPL-141322, SPL-138381 Lookups with multivalued keys not returning results on Windows
2017-04-27 SPL-141409, SPL-138521 Search failing with: 'Streamed search execute failed because: JournalSliceDirectory: Cannot seek to rawdata offset 0' causing alert to be fired
2017-04-27 SPL-141444, SPL-135787 Periodic Crash On Enterprise Security Search Head
2017-04-20 SPL-141255, SPL-141118 Fix Memory leak in OptimizationDoc
2017-04-20 SPL-140714, SPL-141283, SPL-141284, SPL-141285, SPL-141286 lookup, inputlookup and outputlookup commands work despite lookup table being disabled
2017-04-17 SPL-137766, SPL-136453 user based searchFilter is not applied to tstats queries.
2017-04-04 SPL-140667, SPL-140782, SPL-140783 Wildcard for srchIndexesAllowed does not appear to work for custom indexes.

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2017-05-09 SPL-140886, SPL-130809 Backfill script may cause scheduled search to be re-ran after restart.
2017-04-28 SPL-137029, SPL-142022, SPL-142023 savedsearches.conf action.populate_lookup.dest is unable to populate KV store collections
2017-04-18 SPL-140716, SPL-141196, SPL-141167 With only Splunk 6.5.3, searches using Multikv and associated DMA consuming large amounts of memory
2017-04-05 SPL-140179, SPL-140852, SPL-140853 Email generated by backgrounded search includes incorrect search syntax
2017-03-14 SPL-137740, SPL-138471, SPL-138698 request.ui_dispatch_app parameter is ignored when constructing view link for the report and alert emails

Charting, reporting, and visualization issues

Date resolved Issue number Description
2017-04-04 SPL-140551, SPL-140807, SPL-140828 Spaces between "sort - " and "fields - " are removed upon a Dashboard edit in Splunk Enterprise 6.5.2 on Windows with IE 11
2017-03-31 SPL-136610, SPL-140678, SPL-140679 Dashboard *Convert to HTML* loses refresh attributes from base search.

Data model and pivot issues

Date resolved Issue number Description
2017-04-18 SPL-140716, SPL-141196, SPL-141167 With only Splunk 6.5.3, searches using Multikv and associated DMA consuming large amounts of memory
2017-03-17 SPL-137274, SPL-138967, SPL-138968 Pivot: area/line/bar/column charts showing multiple column values when clicking browser back button

Indexer and indexer clustering issues

Date resolved Issue number Description
2017-04-27 SPL-140333, SPL-141469, SPL-141467, SPL-141468 Disappearing cold bucket directories can wedge IndexerService thread (and others) while calculating bucket checksums
2017-04-14 SPL-138999, SPL-143334, SPL-142017 Change in lookup caused an unexpected indexer cluster rolling restart

Distributed search and search head clustering issues

Date resolved Issue number Description
2017-04-27 SPL-137415, SPL-141816, SPL-141815 SHC member crash with signal 6 (Aborted) in DistributedSearchResultCollectorThread
2017-04-21 SPL-140589, SPL-136953 saved search remove_suppression request becomes bad request when saved search name contains spaces in SHC
2017-04-21 SPL-138783, SPL-136804 Duplicate Scheduled Real Time Searches on Search Head Cluster

Universal forwarder issues

Date resolved Issue number Description
2017-03-31 SPL-140545, SPL-135562 Universal forwarder on AIX attempts to start splunkweb during internally-triggered restart, warns that "SRC did not 'stopsrc splunkweb'".

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2017-04-27 SPL-138691, SPL-141462, SPL-141461 Deployment Server crashes due to deleted app still being used in memory

Monitoring Console/DMC issues

Date resolved Issue number Description
2017-03-17 SPL-137673, SPL-138969, SPL-138970 When running Health check on 6.5.2 Some linux items check on window some are skipped

Splunk Web and interface issues

Date resolved Issue number Description
2017-04-28 SPL-138546, SPL-141498, SPL-141499 Incorrect "Cron schedule description" for Powershell v3 Modular Input
2017-04-04 SPL-140667, SPL-140782, SPL-140783 Wildcard for srchIndexesAllowed does not appear to work for custom indexes.
2017-03-31 SPL-140449, SPL-140680, SPL-140681 Unable to expand syntax highlighted JSON
2017-03-16 SPL-135977, SPL-138886, SPL-138887 Improve error message on SSL errors on "browse more apps" page

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2017-05-05 SPL-140472, SPL-134858 CLI auth token, under certain conditions, not removed on logout if the system name reported by the "hostname" command differs from the Splunk server name set in server.conf
2017-05-02 SPL-141491, SPL-141341 Customer getting intermittent HTTP 401 & Rejecting expired token Errors
2017-04-28 SPL-140901, SPL-142018, SPL-142019 user-seed.conf.spec "how to" steps do not work
2017-04-27 SPL-140370, SPL-137028 SHC captain crashes after deploying changes in authentication.conf
2017-04-17 SPL-137766, SPL-136453 user based searchFilter is not applied to tstats queries.
2017-04-04 SPL-140667, SPL-140782, SPL-140783 Wildcard for srchIndexesAllowed does not appear to work for custom indexes.

Admin and CLI issues

Date resolved Issue number Description
2017-05-05 SPL-141226, SPL-141085 Default value "perc_method" for in limits.conf is incorrect

Unsorted issues

Date resolved Issue number Description
2017-04-27 SPL-137035, SPL-141466, SPL-141464, SPL-141465 MSI hangs when a DS is specified
2017-04-19 SPL-140847, SPL-141262, SPL-141260, SPL-141261 instrument-resource-usage fails to collect any information when /proc/diskstats is not available

Uncategorized issues

Date resolved Issue number Description
2017-05-23 SPL-139016, SPL-138897 Initial data is not using the correct columns
2017-05-16 SPL-133405, SPL-140769, SPL-140814, SPL-140820, SPL-142014 Working real-time searches are listed as skipped in scheduler implying there is a problem
2017-05-11 SPL-137156, SPL-141472, SPL-141473 Navigation drop-down menu of an app does not return all the saved searches when they exceed 500
2017-05-09 SPL-141326, SPL-140865 Unactionable error message when Splunk fails to move a file: renameTo failed in 1 attempt(s)... .
2017-05-04 SPL-141531, SPL-141625, SPL-141626, SPL-142506, SPL-142507 Dashboard 'Description' does not take empty string when changed with "Edit Title or Description"
2017-04-28 SPL-138873, SPL-138805 Adding columns in initial data after adding a stats command results in the incorrect columns in stats
2017-04-21 SPL-140704, SPL-141270, SPL-141271 Syntax highlighting stops working when backslash character is used between the double quotes
2017-03-31 SPL-140275, SPL-140214 Checking a column in initial data with a stats command gives the wrong columns
2017-03-17 SPL-138331, SPL-138939, SPL-138940 Search syntax highlighting stops working event if one command does not have syntax property in searchbnf.conf
2017-03-17 SPL-138803, SPL-138758 Removing a command before a stats command results in too many columns in stats
2017-03-14 SPL-133918, SPL-132355 "Edit Job Settings" doesn't work in splunkjs searchbar view
2017-03-14 SPL-138281, SPL-137866 Filter on the listing page is not returning accurate results when splunk contains thousands of dashboards/alerts/reports
Last modified on 26 March, 2019
PREVIOUS
6.5.5
  NEXT
6.5.3

This documentation applies to the following versions of Splunk® Enterprise: 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters