Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.6.9

Splunk Enterprise 6.6.9 was released on August 15, 2018.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Highlighted issues

Date resolved Issue number Description
2018-07-26 SPL-156439, SPL-146352 LDAP reload can severely delay remote app deployment, need app reload metrics to improve diagnosability.

Data input issues

Date resolved Issue number Description
2018-07-26 SPL-152200, SPL-147327 Error message for corrupted FSChangeMonitor database is not actionable.

Search issues

Date resolved Issue number Description
2018-08-13 SPL-147123, SPL-157579, SPL-157682, SPL-158323, SPL-158415, SPL-158930, SPL-158977, SPL-159169, SPL-159201 Timechart search only return columns for OTHER and/or NULL when the index data sets is large and when the split-by field has large distinct values
2018-08-09 SPL-156713, SPL-148606 Inconsistent Search Results Against _audit Index
2018-08-03 SPL-158186, SPL-152598 The "srtemp" directory can grow to hundreds of GB in size and fill up the disk due to orphaned temporary files left behind by abnormally terminated searches and never reaped
2018-08-01 SPL-144312, SPL-154875, SPL-158680, SPL-158681 Owner of Macros can not be reassigned in Web UI in version 6.6.x
2018-08-01 SPL-158131, SPL-152245 Scheduled search job terminated unexpectedly
2018-07-26 SPL-154533, SPL-152434 xml export bloats in size due to repeated <fieldOrder> section

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2018-07-26 SPL-153649, SPL-156991, SPL-157792, SPL-157793 Search scheduler shifts earliest_time and latest_time based on the skew, when using allow_skew

Charting, reporting, and visualization issues

Date resolved Issue number Description
2018-08-13 SPL-147123, SPL-157579, SPL-157682, SPL-158323, SPL-158415, SPL-158930, SPL-158977, SPL-159169, SPL-159201 Timechart search only return columns for OTHER and/or NULL when the index data sets is large and when the split-by field has large distinct values
2018-08-09 SPL-156713, SPL-148606 Inconsistent Search Results Against _audit Index
2018-08-03 SPL-158186, SPL-152598 The "srtemp" directory can grow to hundreds of GB in size and fill up the disk due to orphaned temporary files left behind by abnormally terminated searches and never reaped
2018-08-01 SPL-144312, SPL-154875, SPL-158680, SPL-158681 Owner of Macros can not be reassigned in Web UI in version 6.6.x
2018-08-01 SPL-158131, SPL-152245 Scheduled search job terminated unexpectedly
2018-07-26 SPL-154533, SPL-152434 xml export bloats in size due to repeated <fieldOrder> section

Indexer and indexer clustering issues

Date resolved Issue number Description
2018-07-11 SPL-146688, SPL-154580, SPL-156341, SPL-156725, SPL-156785 Race condition in Indexer Cluster bundles dry run causing "Unable to create/replace target file: No such file or directory".
2018-06-29 SPL-153597, SPL-152465 Clustering - when a peer is in detention, we will make excess copies
2018-06-27 SPL-153569, SPL-154997, SPL-155702, SPL-155703 Data rebalance blocked by stuck bucket discard

Distributed search and search head clustering issues

Date resolved Issue number Description
2018-07-26 SPL-156439, SPL-146352 LDAP reload can severely delay remote app deployment, need app reload metrics to improve diagnosability.
2018-07-26 SPL-154419, SPL-154747, SPL-155355, SPL-155520 SHC captain does not clean up local bundles after failed replication attempts
2018-07-26 SPL-155536, SPL-155778, SPL-156424, SPL-156425 prolonged gaps in SHC captain metrics.log group=searchscheduler
2018-07-10 SPL-155204, SPL-146262 HTTP server thread blocked for ever without logging during shutdown
2018-07-09 SPL-154870, SPL-154934, SPL-155641, SPL-155642 BundleDeltaHandler failing on indexing_tokens directory
2018-07-04 SPL-156179, SPL-151900 Distsearch.conf: value specified in disabled_server property will get ignored, if same value exists in servers property
2018-07-04 SPL-154654, SPL-154841, SPL-155634, SPL-155639, SPL-156876 SHC captain stops delegating DMA searches after a delegated DMA search job fails (status=delegated_remote_completion, success=0).
2018-07-03 SPL-156192, SPL-154032 SHC bundle rejected at push-time because of built-in apps warning is still created and picked up by SHC members

Splunk Web and interface issues

Date resolved Issue number Description
2018-07-12 SPL-156282, SPL-157126, SPL-157127, SPL-157204 Wrong description in lookup definition in UI
2018-07-12 SPL-153034, SPL-153408, SPL-158677, SPL-158678 Formatting of an event is not kept when piped to table
2018-07-10 SPL-154541, SPL-155723, SPL-157124, SPL-157125 No filter by owner in views when owner contains a back slash "\"
2018-06-25 SPL-153658, SPL-154823, SPL-155338, SPL-155339 UI Visualizations of wide lists are not rendered correctly.

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2018-06-12 SPL-149332, SPL-155316, SPL-155317, SPL-155318 SAML - Upon Login Failure all current roles being sent is displayed to user in error message

Admin and CLI issues

Date resolved Issue number Description
2018-06-17 SPL-146439, SPL-155132, SPL-155554, SPL-155555 Saving roles manager page when no indexes are listed remove previous indexes
2018-06-05 SPL-155190, SPL-154589 Enabling splunk boot-start won't work with ubuntu-like distro

Unsorted issues

Date resolved Issue number Description
2018-07-27 SPL-147803, SPL-154752, SPL-156540, SPL-156541 License master rollovers stopped by a broken syslog output blocking indexing, need better logging for diagnosability.

Uncategorized issues

Date resolved Issue number Description
2018-07-31 SPL-157142, SPL-154018 Splunkd looks for default openssl cert file under build path


Splunk Analytics for Hadoop

Date resolved Issue number Description
2018-08-02 ERP-2092, ERP-2139, ERP-2140, ERP-2141 Role Inheritance Failure
PREVIOUS
6.6.10
  NEXT
6.6.8

This documentation applies to the following versions of Splunk® Enterprise: 6.6.9, 6.6.10, 6.6.11, 6.6.12


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters