Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF


Splunk Enterprise 6.5.7 was released on January 17, 2018.

For information about other security fixes, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Data input issues

Date resolved Issue number Description
2017-10-18 SPL-144794, SPL-133461 Compressed files are deleted from sinkhole even if decompression fails

Search issues

Date resolved Issue number Description
2017-11-10 SPL-144369, SPL-143331 default_match is not honoured when lookup matches is 0 (using a kvstore collection)
2017-09-18 SPL-142263, SPL-164845, SPL-172819, SPL-172820, SPL-144706, SPL-144707, SPL-144708 TAB character in Search string causes splunk to throw error - ERROR bucket - Error in 'bucket' command: Invalid argument: ' '

Indexer and indexer clustering issues

Date resolved Issue number Description
2017-10-26 SPL-144862, SPL-145960, SPL-145961, SPL-145962 Make cluster stop attempting to replicate thawed buckets but keep them searchable

Distributed search and search head clustering issues

Date resolved Issue number Description
2017-12-04 SPL-146671, SPL-143060 Rename/Untar errors - over 100,000 errors across all peers
2017-10-27 SPL-145000 Improve messaging for bundle throttling introduced in SPL-140260.
2017-09-26 SPL-142756, SPL-145195, SPL-145196, SPL-145197 Large number of bundles in var/run/searchpeers when the latest common bundle in distributed search doesn't progress.

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2017-11-01 SPL-144798, SPL-146111, SPL-146112, SPL-146113 uiStatusPage doesn't respect root_endpoint in SAML deployments.

Uncategorized issues

Date resolved Issue number Description
2018-01-02 SPL-145193, SPL-146744, SPL-146745, SPL-146746 Field extractor UI ignores escaping on delimiters, inconsistent with backend.
2017-12-04 SPL-146286, SPL-130415 Deadlock during shutdown
2017-09-27 SPL-143141, SPL-145248, SPL-145249, SPL-145250 SSL error for validation of self-signed certificates is not actionable.
Last modified on 05 July, 2019

This documentation applies to the following versions of Splunk® Enterprise: 6.5.7, 6.5.8, 6.5.9, 6.5.10

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters