Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


Splunk Enterprise version 7.0 is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 7.0.5 was released on July 27, 2018.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Highlighted issues

Date resolved Issue number Description
2018-07-13 SPL-156440, SPL-146352 LDAP reload can severely delay remote app deployment, need app reload metrics to improve diagnosability.
2018-06-20 SPL-155053, SPL-152556 fill_summary_index.py fails in SHC environment

Data input issues

Date resolved Issue number Description
2018-06-20 SPL-155069, SPL-153591 high delay on events from UF after upgrade to (6.6.x)

Search issues

Date resolved Issue number Description
2018-07-16 SPL-157126, SPL-156282 Wrong description in lookup definition in UI
2018-07-12 SPL-154532, SPL-152434 xml export bloats in size due to repeated <fieldOrder> section
2018-07-10 SPL-148858, SPL-148547 REGEX eval replace() does not work correctly (overly greedy)
2018-06-20 SPL-155338, SPL-153658 UI Visualizations of wide lists are not rendered correctly.
2018-06-20 SPL-155294, SPL-154026 gentimes command shows incorrect starthuman time with daylight savings
2018-06-19 SPL-155412, SPL-155106 splunkd process consuming large amount of memory
2018-06-01 SPL-152809, SPL-141639 6.5.2 Error in chart command: The value for option span is invalid: log10
2018-05-31 SPL-154970, SPL-153432 The bins option returns inconsistent count values in distributed environment
2018-05-28 SPL-153995, SPL-147061 debug/refresh reports errors on vanilla install
2018-05-11 SPL-152493, SPL-148796 ui_inactivity_timeout not working even after search completes

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2018-07-10 SPL-154405, SPL-147319 SHC AuthenticationManagerLDAP complains "Could not find user="system"" flooding splunkd.log
2018-05-20 SPL-154302, SPL-153349 Scheduling Alerts - Apply Time Range Of Initial Search Not Reflecting when Saving as Alert

Data model and pivot issues

Date resolved Issue number Description
2018-07-10 SPL-154405, SPL-147319 SHC AuthenticationManagerLDAP complains "Could not find user="system"" flooding splunkd.log

Indexer and indexer clustering issues

Date resolved Issue number Description
2018-07-24 SPL-154986, SPL-155130, SPL-155215, SPL-155220, SPL-157832 single-copy bucket stuck with status "no possible primaries", causes entire cluster to be tagged as "not fully searchable"
2018-07-10 SPL-156785, SPL-146688 Race condition in Indexer Cluster bundles dry run causing "Unable to create/replace target file: No such file or directory".
2018-07-04 SPL-155702, SPL-153569 Data rebalance blocked by stuck bucket discard
2018-06-22 SPL-154353, SPL-146575 RF and SF not being met on CM after adding new Indexes and rolling restart
2018-06-08 SPL-154647, SPL-152465 Clustering - when a peer is in detention, we will make excess copies
2018-05-23 SPL-153520, SPL-153121 CMSlave Should output errors when failing to enqueue the bundle validate job

Distributed search and search head clustering issues

Date resolved Issue number Description
2018-07-14 SPL-154829, SPL-141363 Indexers report "Unknown search command" for external search commands even though the indexers contain the search bundle with the external command
2018-07-13 SPL-155355, SPL-154419 SHC captain does not clean up local bundles after failed replication attempts
2018-07-13 SPL-156440, SPL-146352 LDAP reload can severely delay remote app deployment, need app reload metrics to improve diagnosability.
2018-07-13 SPL-156424, SPL-155536 prolonged gaps in SHC captain metrics.log group=searchscheduler
2018-07-09 SPL-154617, SPL-152935 KVStore Replication Error: replSetReconfig got BadValue _id field value of 256 is out of range
2018-07-04 SPL-156178, SPL-151900 Distsearch.conf: value specified in disabled_server property will get ignored, if same value exists in servers property
2018-07-04 SPL-155641, SPL-154870 BundleDeltaHandler failing on indexing_tokens directory
2018-07-03 SPL-154032, SPL-154067, SPL-154926, SPL-156192 SHC bundle rejected at push-time because of built-in apps warning is still created and picked up by SHC members
2018-06-22 SPL-155634, SPL-154654 SHC captain stops delegating DMA searches after a delegated DMA search job fails (status=delegated_remote_completion, success=0).
2018-06-22 SPL-155808, SPL-154402 SHC: alert suppression may fail during restart due to timing issues
2018-06-20 SPL-155203, SPL-146262 HTTP server thread blocked for ever without logging during shutdown
2018-05-09 SPL-153832, SPL-148106 Crashing thread: TcpChannelThread, Assertion `_slave != __null ClusteringMgr::_slave_writeBucketsToSearch.

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2018-07-10 SPL-156354, SPL-149328 Deployment Clients unable to connect to Deployment Server with phoneHomeIntervalInSecs = 600
2018-06-03 SPL-155010, SPL-153261 Slow Performance in the Deployment Server UI and sometime crash the browser
2018-05-09 SPL-154007, SPL-148851 Application bundle cache (by default under $SPLUNK_HOME/var/run/tmp/) *never* gets cleaned up on Deployment server even server class no longer exists

Monitoring Console issues

Date resolved Issue number Description
2018-05-15 SPL-153767, SPL-138918 Mount points are not listed correctly in "Average I/O Usage and Performance" panel of Monitoring Console

Splunk Web and interface issues

Date resolved Issue number Description
2018-07-16 SPL-157126, SPL-156282 Wrong description in lookup definition in UI
2018-07-12 SPL-154532, SPL-152434 xml export bloats in size due to repeated <fieldOrder> section
2018-07-10 SPL-148858, SPL-148547 REGEX eval replace() does not work correctly (overly greedy)
2018-06-20 SPL-155338, SPL-153658 UI Visualizations of wide lists are not rendered correctly.
2018-06-20 SPL-155294, SPL-154026 gentimes command shows incorrect starthuman time with daylight savings
2018-06-19 SPL-155412, SPL-155106 splunkd process consuming large amount of memory
2018-06-01 SPL-152809, SPL-141639 6.5.2 Error in chart command: The value for option span is invalid: log10
2018-05-31 SPL-154970, SPL-153432 The bins option returns inconsistent count values in distributed environment
2018-05-28 SPL-153995, SPL-147061 debug/refresh reports errors on vanilla install
2018-05-11 SPL-152493, SPL-148796 ui_inactivity_timeout not working even after search completes

REST, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2018-06-25 SPL-154837, SPL-153655 /services/search/jobs/*/results is responding with duplicate JSON field 'init_offset' when output_mode is 'json_cols' and search has no result
2018-06-20 SPL-155053, SPL-152556 fill_summary_index.py fails in SHC environment

Authentication and authorization issues

Date resolved Issue number Description
2019-09-18 SPL-149313, SPL-148551 srchFilter term not included in search when calculated field of same name exists
2018-06-29 SPL-155318, SPL-149332 SAML - Upon Login Failure all current roles being sent is displayed to user in error message

PDF issues

Date resolved Issue number Description
2018-06-27 SPL-154368, SPL-153668 When exporting to PDF one particular IP Address generates an error while others work

Admin and CLI issues

Date resolved Issue number Description
2018-06-20 SPL-155191, SPL-154589 Enabling splunk boot-start won't work with ubuntu-like distro
2018-06-17 SPL-155554, SPL-146439 Saving roles manager page when no indexes are listed remove previous indexes
2018-06-15 SPL-153624, SPL-154857, SPL-155429 savedsearches.conf configuration is_visible needs clarification
2018-06-12 SPL-153625, SPL-154021, SPL-154022 leading and trailing comma validation should be robust for http proxy configuration

Uncategorized issues

Date resolved Issue number Description
2019-01-28 SPL-155427, SPL-155716, SPL-155719 CIM Setup page is showing single line because of Indexes.js collection not executing callbacks
2018-07-20 SPL-156315, SPL-157319, SPL-157522, SPL-157595 After upgrade to 7.x, HEC events greater than 512KB are dropped with parsing errors, resulting in degrade of indexing throughput
2018-07-16 SPL-156541, SPL-147803 License master rollovers stopped by a broken syslog output blocking indexing, need better logging for diagnosability.
2018-07-15 SPL-153174, SPL-156193, SPL-156899 Request for better messaging for "Duplicated License situation happen on peer ..."
2018-07-03 SPL-155035, SPL-156539, SPL-155351 Splunk Fowarders splunkd process stopping - Crashing thread: HttpClientPollingThread
2018-06-14 SPL-155224, SPL-153036 CMBucketId has lock contention from std::map log(n) lookup time
2018-06-14 SPL-152888, SPL-154243, SPL-155000, SPL-155019, SPL-155451 Chunks of summary index data are routed to the wrong index when queues are blocked
2018-06-11 SPL-154062, SPL-154018 Splunkd looks for default openssl cert file under build path
2018-05-28 SPL-154366, SPL-152887 Color Range Feature coupled with real-time search causes the colors to flicker when updating
2018-05-25 SPL-154014, SPL-145371 Bulletin board message timestamp incorrect on SHC members
2018-05-09 SPL-153935, SPL-151228 Add suppression state file listing to splunk diag.
2018-05-04 SPL-154129, SPL-153011 HTML entity name appears in Tour dialog if username contains &,<,>,",'
Last modified on 09 December, 2020
PREVIOUS
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.0.5


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters