Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF


Splunk Enterprise 6.5.3 was released on March 30, 2017.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Data input issues

Date resolved Issue number Description
2017-03-06 SPL-136177, SPL-131278 Forwarder-to-indexer ping causing increase in duplicate events
2017-01-26 SPL-130547, SPL-119992 btool returns incorrect output for inputs.conf

Search issues

Date resolved Issue number Description
2017-03-23 SPL-136892, SPL-112368 Search process memory tracker not performing as expected, allows the memory usage of search processes to grow well over the configured limit
2017-03-17 SPL-133970, SPL-138535 PCRE_ERROR_MATCHLIMIT errors in search using rex
2017-03-06 SPL-135284, SPL-138274 Bad function error when saving valid eval for a calculated field
2017-02-27 SPL-136386, SPL-137263, SPL-137264, SPL-137265, SPL-137266 stats table with reltime breaks the Sparkline
2017-02-08 SPL-130393, SPL-136348, SPL-136347, SPL-136349 When searching over multiple indexes using disjoint time ranges in fast mode, commands which trigger batch search mode, such as stats and table, return 0 results
2017-01-07 SPL-134715 Long-running searches using Safari browser terminate with "Unknown sid" error
2017-01-06 SPL-131699, SPL-134631, SPL-134632 lookup command doesn't match CIDR event fields to all matching fields in the lookup table

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2017-03-08 SPL-136101, SPL-134527 (Ivory) - Customer is missing email alerts - only message is "ERROR sendemail:1199 - expected string or buffer"
2017-01-23 SPL-131111, SPL-134375 Sporadically, scheduled searches delayed or skipped on search-head cluster
2017-01-06 SPL-131173, SPL-138169 Alert emails fail when custom SSL cert uses $SPLUNK_HOME

Charting, reporting, and visualization issues

Date resolved Issue number Description
2017-02-15 SPL-135805 Allow dashboard chart height limits to be greater than 1000 pixels
2017-02-10 SPL-133981, SPL-136640 Drilldown search is not displaying results upon initial page load

Data model and pivot issues

Date resolved Issue number Description
2017-03-08 SPL-135452, SPL-135023 (6.5.x) - Pivot Query builder hardcodes num_of_rows to 100 when sorted by _time

Indexer and indexer clustering issues

Date resolved Issue number Description
2017-03-24 SPL-138304, SPL-119165 (6.5.x) - fsck scan command return "Corrupted" for unsearchable buckets
2017-03-09 SPL-136735, SPL-100516 Events deleted in an index cluster via the delete search operator may be inconsistently deleted on secondaries
2017-03-06 SPL-135498, SPL-136771, SPL-146686, SPL-146687 tsidx file disappeared
2017-03-06 SPL-135394, SPL-137076 Fix-up tasks for several buckets are stuck with status "cannot fix search count as the bucket hasn't rolled yet"
2017-01-26 SPL-135193, SPL-135667, SPL-135668 Indexer peers down after 6.4-to-6.5 upgrade
2017-01-06 SPL-134515, SPL-138448, SPL-138472 v6.5.1 Freezing bucket failed with the following errors for thousands of buckets over all Cluster Peers

Distributed search and search head clustering issues

Date resolved Issue number Description
2017-03-20 SPL-135855, SPL-125047 Search head getting 502 while starting remote search on the peer.
2017-03-09 SPL-133968, SPL-138467, SPL-138468, SPL-138191, SPL-138477 Searches fail with "Reading error while waiting for peer" despite search completing for that peer. "HTTP client error: Connection closed by peer" observed in search.log.
2017-03-09 SPL-134395, SPL-135069 Callout member names in the error message logged on detecting version mismatch
2017-03-06 SPL-138105, SPL-137554 mgmt_uri is showing "?" while checking with "splunk show shcluster-status"
2017-02-27 SPL-137284, SPL-137661, SPL-137663, SPL-137665 Captain is throwing ERROR SHCArtifactId due to guid mismatch
2017-02-21 SPL-135941, SPL-136243, SPL-136245, SPL-136246 Subsearch ignores default distributed search group in distsearch.conf
2017-01-27 SPL-134836, SPL-133482, SPL-135741, SPL-135742 SHC captain with captain_is_adhoc_searchhead=1 delegates skipping of searches after cluster-wide concurrency limit reached.
2017-01-27 SPL-135367, SPL-135743, SPL-135744 Total concurrency deals with only scheduler-enabled peers in an SHC, leading to lower concurrency limits cluster-wide.
2017-01-23 SPL-131111, SPL-134375 Sporadically, scheduled searches delayed or skipped on search-head cluster
2017-01-19 SPL-134620, SPL-123768 Long file path (>255 characters) can break the tarball creation and lead to snapshot creation failure.

Universal forwarder issues

Date resolved Issue number Description
2017-01-19 SPL-135020, SPL-134112 Unactionable error message for invalid server URIs in outputs.conf.

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2017-03-06 SPL-134238, SPL-131510 Forwarder Management interface doesn't show all clients if they have the same hostname and port.
2017-01-06 SPL-123636, SPL-134688, SPL-134689, SPL-134690, SPL-134692, SPL-134693 Apps cannot be uninstalled by forwarder management

Monitoring Console/DMC issues

Date resolved Issue number Description
2017-01-04 SPL-134175, SPL-134591 The Monitoring Console's "Search Head Clustering: Status & Configuration" page incorrectly calculates cluster-wide search concurrency limits

Splunk Web and interface issues

Date resolved Issue number Description
2017-03-01 SPL-136556, SPL-137861 Syntax highlighting is not working for the "from" keyword of a command when it has a syntax of accepting multiple fields
2017-02-16 SPL-136980, SPL-136116 Post 6.5.1 upgrade issue: searches failed to run (UI appeared to be getting stuck at either "Loading...", "Parsing job...", or "Finalizing job..."); requiring clearing the browser cache.
2017-01-16 SPL-134802, SPL-135226, SPL-135227 POST to parser endpoint fails on loading search app

Windows-specific issues

Date resolved Issue number Description
2017-03-06 SPL-131265, SPL-126708 splunk-perfmon.exe locked a file unexpectedly

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2017-03-06 SPL-132949, SPL-137123 indexer complains "Failed to get LDAP user" for search head local user on 6.5.x
2017-02-16 SPL-130771, SPL-137016, SPL-137017, SPL-137018 Improvement for "Rejecting expired token" Warning Message
2017-01-06 SPL-134444, SPL-119588 Credential Manager /services/storage/passwords stops working when decrypted password is not utf8

PDF issues

Date resolved Issue number Description
2017-03-06 SPL-136052, SPL-134977 sendemail.py does not respect action.email.include.view_link for views (scheduled PDF delivery)
2017-02-23 SPL-137296 PDF export ignores the empty data points on the chart

Admin and CLI issues

Date resolved Issue number Description
2017-01-24 SPL-134343, SPL-135504, SPL-135505 Admin user sharing a search via the 'Share' button to a non-admin user may result in 'Permission Denied' for user when clicking the link.
2016-12-29 SPL-133442, SPL-138163 If app name is over 30 characters, there will be no space between fields of "display app" cli command

Unsorted issues

Date resolved Issue number Description
2017-03-13 SPL-136281, SPL-138051, SPL-136658 Fix "one time client" stickiness on forwarders
2017-03-06 SPL-136939, SPL-138139, SPL-138140 Splunk HF 6.5.1 crashes when trying to resolve hostname
2017-02-07 SPL-134506, SPL-136387, SPL-136388, SPL-136389 nested mount points are not shown in the "/services/server/status/partitions-space" endpoint
2017-01-31 SPL-135275 Custom django app fails to load results for even a simple search
2017-01-04 SPL-133720, SPL-134618, SPL-134617 splunkd instrument-resource-usage process uses one full CPU core after upgrade to 6.5.1 on Centos 5

Uncategorized issues

Date resolved Issue number Description
2017-03-03 SPL-135024, SPL-134501 Add validation to transforms.conf DELIMS as it does not support non-ASCII delimiters.
2017-02-16 SPL-135106, SPL-134608 The indexing_volume dashboard is not showing accurate information, and should be deprecated
2017-02-16 SPL-135384, SPL-130614 Eventypes w/macros does not work
2017-01-24 SPL-134422, SPL-134443 Timechart does not render properly or display if function field is "constructor"
2017-01-20 SPL-132888, SPL-135327, SPL-135329 Unable to select a radio button with one click when the value of it contains a rex command with quotes
Last modified on 25 March, 2019
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020

This documentation applies to the following versions of Splunk® Enterprise: 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters