Splunk® Enterprise

Release Notes

Splunk Enterprise version 7.0 is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 7.0.4 was released on May 9, 2018.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Authentication and authorization issues

Date resolved Issue number Description
2018-04-16 SPL-153124, SPL-151937 Scripted authentication fails to parse getSearchFilter output, hitting PCRE_ERROR_MATCHLIMIT.

Data input issues

Date resolved Issue number Description
2018-04-22 SPL-153180, SPL-148346 UF ignores files that are currently being written to

Search issues

Date resolved Issue number Description
2018-05-01 SPL-145602, SPL-148349, SPL-153732 REGEX flag (?J) "duplicate group names" causes splunk to crash
2018-04-23 SPL-148632, SPL-144670 Log required field back-propagation
2018-04-23 SPL-153646, SPL-145560 Splunkd DispatchManager logging is inconsistent
2018-04-19 SPL-152749, SPL-141223 Documentation to confirm action.populate_lookup.dest in savedsearches.conf does not work with kvstore lookups
2018-04-18 SPL-148873, SPL-146082 Edit Summary Indexing Dialog not working with searches containing subsearches
2018-04-03 SPL-152729, SPL-135296 SearchResults complains in splunkd.log about a corrupt CSV file header without naming the problematic file or lookup table
2018-03-20 SPL-152232, SPL-151719 Windows Events Logs: Hidden Character Added To Field Name Breaks Search

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2018-04-18 SPL-153149, SPL-148958 tstats will not return any results from an Accelerated Datamodel/Namespace/tscollect job if the raw event has 2-byte characters

Distributed search and search head clustering issues

Date resolved Issue number Description
2018-04-22 SPL-152421, SPL-145554 The savedsearch key/value field is not quoted in SHCMaster log message breaking extraction
2018-04-17 SPL-148541, SPL-147793 During shutdown disable captaincy election
2018-04-17 SPL-153218, SPL-152280 Deployer app staging area may miss bundles if preparation takes more than 10 minutes.
2018-04-13 SPL-152011, SPL-146295 Rolling restarts/UI restarts should spawn an external process to initiate shutdown.
2018-04-09 SPL-152626, SPL-130444 SHC: alert suppression may fail during restart if suppression information does not exist locally on member

Data model and pivot issues

Date resolved Issue number Description
2018-04-18 SPL-153149, SPL-148958 tstats will not return any results from an Accelerated Datamodel/Namespace/tscollect job if the raw event has 2-byte characters

Indexer and indexer clustering issues

Date resolved Issue number Description
2018-04-12 SPL-153051, SPL-152821 Contention on DatabaseManager::_mux and CMIndexId mutex impacting search performance and indexer cluster stability.
2018-03-20 SPL-151813, SPL-146335 DispatchReaper not cleaning up remote-bundle files on CM

Universal forwarder issues

Date resolved Issue number Description
2018-04-22 SPL-153632, SPL-151229 AIX 7.1 Deployment Server Restarting UF give splunkd; SRC did not 'chssys splunkd' on our behalf: exit code=-1
2018-04-18 SPL-153453, SPL-149198 Some of the rolled log files read twice by Splunk Universal Forwarder
2018-04-16 SPL-152201, SPL-144080 Splunk Forwarder crashes if EVENT_BREAKER_ENABLE is specified for a WMI input

Monitoring Console issues

Date resolved Issue number Description
2018-04-27 SPL-149486, SPL-153396, SPL-155092 "HTTP Event Collector: Deployment" dashboard is not rendering at all and incorrectly reports "You currently have no tokens configured"

Splunk Web and interface issues

Date resolved Issue number Description
2018-05-01 SPL-145602, SPL-148349, SPL-153732 REGEX flag (?J) "duplicate group names" causes splunk to crash
2018-04-23 SPL-148632, SPL-144670 Log required field back-propagation
2018-04-23 SPL-153646, SPL-145560 Splunkd DispatchManager logging is inconsistent
2018-04-19 SPL-152749, SPL-141223 Documentation to confirm action.populate_lookup.dest in savedsearches.conf does not work with kvstore lookups
2018-04-18 SPL-148873, SPL-146082 Edit Summary Indexing Dialog not working with searches containing subsearches
2018-04-03 SPL-152729, SPL-135296 SearchResults complains in splunkd.log about a corrupt CSV file header without naming the problematic file or lookup table
2018-03-20 SPL-152232, SPL-151719 Windows Events Logs: Hidden Character Added To Field Name Breaks Search

Windows-specific issues

Date resolved Issue number Description
2018-04-19 SPL-153192, SPL-151800 Windows Registry Monitoring Input is ignoring the _TCP_ROUTING setting

PDF issues

Date resolved Issue number Description
2018-04-25 SPL-153256, SPL-148648 Long (em) Dash inside Tokens in PDF Reports causes Removal of Formatting
2018-03-27 SPL-152437, SPL-151132 PDF export broken with SimpleXML <init> TAG

Admin and CLI issues

Date resolved Issue number Description
2018-04-18 SPL-152206, SPL-145579 chkconfig directive missing for AWS with enable boot-start
2018-04-16 SPL-146927, SPL-141771 Starting Splunk via the CLI may fail or cause problems if service runs as a domain user and some storage is on a remote share
2018-04-05 SPL-152848, SPL-147286 Setting DATETIME_CONFIG as filename does not update props.conf

Uncategorized issues

Date resolved Issue number Description
2018-05-02 SPL-148947, SPL-146340 Log scale chart not able to handle Y-Axis having incremental / decremental values of 1/10
2018-04-19 SPL-153049, SPL-145043 Too long of a dashboard title throws nondescript error message
2018-04-16 SPL-153078, SPL-145094 introspection: IOStats read incorrect if more than one partition created on one physical drive
2018-04-09 SPL-152763, SPL-151501 Enabling/Disabling acceleration for a data model creates an unnecessary copy of the data model JSON in <appname>/local/data/models/<model>.json
2018-04-06 SPL-152814, SPL-147956 mstats not returning results if tmp folder does not exist
2018-03-30 SPL-151738, SPL-148014 S2 Bucket is Staled Until Timeout
2018-03-19 SPL-151304, SPL-135274 search assistant incorrectly wrapping kv pairs in quotes
2018-03-13 SPL-151755, SPL-148815 Mistranslation of "Product Tour" > "Add Data Tour" in Japanese
Last modified on 12 August, 2024
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020   Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.0.4


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters