Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.6.5

Splunk Enterprise 6.6.5 was released on December 19, 2017.

For information about other security fixes, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Data input issues

Date resolved Issue number Description
2017-12-05 SPL-143741, SPL-146920, SPL-146921 HF Crashing thread: ExecProcessorSchedulerThread

Search issues

Date resolved Issue number Description
2017-12-06 SPL-144706, SPL-142263 TAB character in Search string causes splunk to throw error - ERROR bucket - Error in 'bucket' command: Invalid argument: ' '
2017-11-21 SPL-144990, SPL-146537, SPL-146592 Searches with $info_min_time$<1,000,000,000 not returning data.
2017-11-07 SPL-145252, SPL-146174, SPL-146175 Column sorting does not work on search and report page if the field contains a whitespace
2017-10-19 SPL-145620, SPL-145801, SPL-145802 Tabs within a dashboard search query cause the open in search to return no results

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2017-11-19 SPL-145700, SPL-142783 stack overflow when expanding pivot with circular dependency
2017-11-13 SPL-145462, SPL-146448, SPL-146449 Event line break lost in Alert email

Charting, reporting, and visualization issues

Date resolved Issue number Description
2017-12-06 SPL-144706, SPL-142263 TAB character in Search string causes splunk to throw error - ERROR bucket - Error in 'bucket' command: Invalid argument: ' '
2017-11-21 SPL-144990, SPL-146537, SPL-146592 Searches with $info_min_time$<1,000,000,000 not returning data.
2017-11-07 SPL-145252, SPL-146174, SPL-146175 Column sorting does not work on search and report page if the field contains a whitespace
2017-10-19 SPL-145620, SPL-145801, SPL-145802 Tabs within a dashboard search query cause the open in search to return no results

Data model and pivot issues

Date resolved Issue number Description
2017-11-19 SPL-145700, SPL-142783 stack overflow when expanding pivot with circular dependency
2017-11-13 SPL-145462, SPL-146448, SPL-146449 Event line break lost in Alert email

Indexer and indexer clustering issues

Date resolved Issue number Description
2017-12-14 SPL-145736, SPL-146499, SPL-146849 Index Cluster not recovering from index peer failure - "cannot replicate as bucket hasn't rolled"
2017-12-04 SPL-146010, SPL-144365 Indexer queue gets blocked by a forwarded event larger than its persistent queue.
2017-12-04 SPL-145960, SPL-144862 Make cluster stop attempting to replicate thawed buckets but keep them searchable
2017-12-04 SPL-146214, SPL-146405, SPL-146685, SPL-146828, SPL-146925, SPL-148108, SPL-148109 Search returns the following error "Could not read event: cd=(n/a). Results may be incomplete ! (logging only the first such error; enable DEBUG to see the rest)"
2017-11-30 SPL-146217, SPL-142643 cluster peer crashed due to "Crashing thread: TcpListener" "Assertion `pProcessor != __null' failed."
2017-11-15 SPL-144652, SPL-146479, SPL-146480 forwarder_site_failover not working with SSL

Distributed search and search head clustering issues

Date resolved Issue number Description
2017-12-05 SPL-145939, SPL-141225 SHC shows last_conf_replication : Pending after upgrade due to missing mgmt_uri conf in server.conf
2017-12-04 SPL-146672, SPL-143060 Rename/Untar errors - over 100,000 errors across all peers
2017-12-01 SPL-145290, SPL-146721, SPL-146722 dispatch folder filling up with artifact RemoteStorageRetrieveIndexes_1506518206.19514 on the cluster-master
2017-11-19 SPL-144273, SPL-132295 Excessive "Inconsistent bundles" Logging
2017-10-23 SPL-145195, SPL-142756 Large number of bundles in var/run/searchpeers when the latest common bundle in distributed search doesn't progress.
2017-10-23 SPL-144479, SPL-140260 $SPLUNK_HOME/var/run/searchpeers growing due to latest common bundle in peers being stuck to an old version.

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2017-12-06 SPL-146471, SPL-141430 continueMatching=false in serverclass.conf does not work as expected
2017-11-30 SPL-146230, SPL-147407, SPL-147408 Getting 500 error in DS when apps contain Japanese character in conf file

Monitoring Console/DMC issues

Date resolved Issue number Description
2017-11-10 SPL-144658, SPL-146338, SPL-146339 Monitoring console app's health check page shows results only for the 100 instances
2017-11-08 SPL-146244, SPL-146097 Typo in split by dropdown of Monitoring Console's License usage dashboard

Splunk Web and interface issues

Date resolved Issue number Description
2017-11-14 SPL-144500, SPL-146432, SPL-146433 Misconfigured view warnings in web_service.log due to the case sensitive comparison of boolean values
2017-11-07 SPL-145252, SPL-146174, SPL-146175 Column sorting does not work on search and report page if the field contains a whitespace
2017-10-23 SPL-144340, SPL-147405, SPL-147406 Lookup Definition Case Sensitivity in Web GUI should reflect default settings

Windows-specific issues

Date resolved Issue number Description
2017-12-11 SPL-142531, SPL-147470, SPL-147471 splunk-winprintmon crash in jobMon_w::add

Rest, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2017-11-01 SPL-144793, SPL-146125, SPL-146129 | rest /services/apps/local/ display for the column/attribute author always nobody

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2017-12-04 SPL-146111, SPL-144798 uiStatusPage doesn't respect root_endpoint in SAML deployments.

Admin and CLI issues

Date resolved Issue number Description
2017-11-01 SPL-143462, SPL-145528, SPL-145529 Summary index menu not displaying indexes from search peer

Uncategorized issues

Date resolved Issue number Description
2017-12-11 SPL-147148, SPL-143398 Slow license master response times after upgrade to 6.5 due to __tz_convert() bottleneck and extensive debug logging calls for lots of warnings
2017-11-07 SPL-146155, SPL-144250 | inputlookup "where" command returning inaccurate results for compare operations (< , >) on strings or fields with quotes
2017-10-25 SPL-144991, SPL-145959, SPL-145946, SPL-145947, SPL-145948, SPL-145958 Issues with RPM Upgrades - empty search_mrspakle/modules directory
2017-10-23 SPL-144807, SPL-141762 Modifications to kvstore collections are not being distributed to Indexer
PREVIOUS
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
  NEXT
6.6.4

This documentation applies to the following versions of Splunk® Enterprise: 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters