Splunk® Enterprise

Release Notes

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.5.6

Splunk Enterprise 6.5.6 was released on October 26, 2017.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Data input issues

Date resolved Issue number Description
2017-08-23 SPL-130962, SPL-137275, SPL-143682, SPL-147663 Files are not getting ingested if there is missing eol
2017-08-23 SPL-142525, SPL-144297, SPL-144353, SPL-146786 Duplicated events when indexing csv files with INDEXED_EXTRACTIONS
2017-07-03 SPL-141726, SPL-142836, SPL-142837 splunkd_stderr.log.1 is not getting assigned the correct source type

Search issues

Date resolved Issue number Description
2017-10-11 SPL-145398, SPL-144217 searchmatch() without arguments causes crash in search process or main splunkd
2017-08-07 SPL-142569, SPL-142794, SPL-143767 BundlesSetup is taking ~4.5 sec to complete in SHC when lots of folders under etc/users
2017-07-21 SPL-142959 | metadata index limit of 5. Returns 'No results' with 6 indexes

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2017-08-24 SPL-141957, SPL-144361, SPL-144362, SPL-144363 "ERROR datamodel - Found circular dependency when expanding datamodel" crashes splunkd
2017-07-20 SPL-141867, SPL-143250, SPL-143251 Scheduled Report having trailing white space in search query always show no results

Charting, reporting, and visualization issues

Date resolved Issue number Description
2017-08-18 SPL-143183 Token from Dropdown is grabbing previous value

Data model and pivot issues

Date resolved Issue number Description
2017-08-24 SPL-141957, SPL-144361, SPL-144362, SPL-144363 "ERROR datamodel - Found circular dependency when expanding datamodel" crashes splunkd
2017-07-20 SPL-141867, SPL-143250, SPL-143251 Scheduled Report having trailing white space in search query always show no results

Indexer and indexer clustering issues

Date resolved Issue number Description
2017-06-30 SPL-142500, SPL-141884 Meaning of "ERROR ClusteringHandler - handler=clustermastercontrol method expected=POST does not match actual=GET customaction=restart" message

Distributed search and search head clustering issues

Date resolved Issue number Description
2017-09-18 SPL-140260, SPL-144479, SPL-144480, SPL-144481 $SPLUNK_HOME/var/run/searchpeers growing due to latest common bundle in peers being stuck to an old version.
2017-07-26 SPL-141347, SPL-143381, SPL-146109, SPL-146110 Improve error message when peers closing or resetting the connection while searching
2017-07-04 SPL-142528, SPL-132443 Search bundle synchronous replication delayed by pro-active bundle lookup indexing.
2017-07-04 SPL-140831, SPL-142888, SPL-142889 Splunk not cleaning up $SPLUNK_HOME/var/run/searchpeers of .delta files and matching directories whose only non-empty subdirectory has the .index extension

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2017-07-21 SPL-138844, SPL-143300, SPL-143301, SPL-143302 Wrong example is given for handshakeRetryIntervalInSecs in Example 4 : https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Deploymentclientconf

Monitoring Console/DMC issues

Date resolved Issue number Description
2017-08-04 SPL-143253, SPL-133416 DMC: Resource Usage Deployment: Load Average and Deployment-Wide Load Average panels fail to populate in windows

Splunk Web and interface issues

Date resolved Issue number Description
2017-08-30 SPL-142605, SPL-144510, SPL-144511, SPL-144512 Page loads slowly when there are more global saved searches
2017-07-17 SPL-139017, SPL-148608, SPL-148609, SPL-148610 The messages.po file contains French translations of css object when it shouldn't

Windows-specific issues

Date resolved Issue number Description
2017-08-21 SPL-142071, SPL-144219, SPL-144221, SPL-144222 splunk-winevtlog crashes on unregistering wait handle
2017-06-30 SPL-141581, SPL-142830, SPL-142831 "NumberOfProcessors" for WinHostMon is empty

Authentication and Authorization issues

Date resolved Issue number Description
2017-09-03 SPL-141681, SPL-143915, SPL-143916, SPL-144309 Custom web.conf:root_endpoint may cause SAML authentication to fail.
2017-08-28 SPL-142994, SPL-144489, SPL-144490, SPL-146269 SAML User session logout results in infinite loop when SLO is configured to point to SP(Splunk Logout) with ADFS
2017-08-16 SPL-141089, SPL-143593, SPL-142248, SPL-143592 SAML - Users realName and email being dropped from the UI on authentication bounce

Uncategorized issues

Date resolved Issue number Description
2017-08-24 SPL-143398, SPL-147086, SPL-147088, SPL-147089, SPL-147148 Slow license master response times after upgrade to 6.5 due to __tz_convert() bottleneck and extensive debug logging calls for lots of warnings
2017-08-17 SPL-144137, SPL-143846, SPL-143848, SPL-143849 Add warning to splunkd.log if vm.overcommit_memory is set to 2
2017-08-17 SPL-140406, SPL-143730, SPL-143742, SPL-145839 IPV6 env and DC fail to connect to DS using domain name
2017-08-16 SPL-142221, SPL-138909 Ran out of data while looking for end of header- archive file
2017-08-16 SPL-132666, SPL-173290, SPL-143965, SPL-143966, SPL-144174 Exported pdf shows token string for the dashboard element's title property instead of its value
2017-08-09 SPL-142911, SPL-143340, SPL-143473 License Master Performance Degradation After Upgrading to 6.5.3.1
2017-08-02 SPL-142738, SPL-143597, SPL-143598, SPL-143599 timestamps not extracted since they are more than MAX_TIMESTAMP_LOOKAHEAD characters into events
2017-07-31 SPL-134638, SPL-143382, SPL-143400, SPL-144110 Slow license master response times after upgrade to 6.5
2017-07-25 SPL-130818, SPL-143307, SPL-143308 When viewing custom time alert from email, custom time of alert triggered changes to the current time when clicking View Events from results table.
2017-07-06 SPL-141716, SPL-142915, SPL-142916 KVStoreProfilingDataInstrumentThread crash on search head due to malformed json
2017-07-06 SPL-142304, SPL-142293 Windows dev build crashes when setting non existent file to binary
2017-06-29 SPL-142296, SPL-142814, SPL-142815 Edit PDF Schedule dialog is not opening when invalid cron is set
2017-06-29 SPL-141494, SPL-142816, SPL-142817, SPL-145763 Map command in dashboard is sending empty PDF file when scheduling
2017-06-29 SPL-141621, SPL-142821, SPL-142819, SPL-142820, SPL-142822 When "Use Deployment Server" option is selected on Deployment Server, "userDeploymentServer=1" config gets wrong propagated to the Deployment Clients, because of which "HTTP Event Collector" on the clients stop accepting valid tokens
2017-06-26 SPL-141235, SPL-141522 Heavy forwarder is crashing with typing thread
2017-06-22 SPL-141928, SPL-142606, SPL-142607 CSV export results into a HTTP 500 error when the csv lookup file contains non utf-8 characters

Splunk Analytics for Hadoop

Date resolved Issue number Description
2017-09-11 ERP-2085, ERP-2071 Search against archived buckets throws "bad gzip header" errors; getting events outside of the search time range
2017-08-02 ERP-2047, ERP-2096, ERP-2097, ERP-2107 /hdfs/user/hunk/bundles Not Being Reaped
2017-07-24 ERP-2089, ERP-2090, ERP-2091, ERP-2100 Acceleration searches on HUNK are returning java.lang.IllegalArgumentException: No enum constant com.splunk.datasource.WriterFactory.Format exceptions
2017-07-14 ERP-2079, ERP-2103, ERP-2104, ERP-2111 Large splunk_archiver.log causes space problems.
Last modified on 17 July, 2019
PREVIOUS
6.5.7
  NEXT
6.5.5

This documentation applies to the following versions of Splunk® Enterprise: 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters