Fixed issues
Splunk Enterprise 7.0.8 was released on November 26, 2018.
Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.
Authentication and authorization issues
Date resolved
|
Issue number
|
Description
|
2018-11-12 |
SPL-160382, SPL-147611 |
Socket error message in splunkd after login to SplunkWeb with self-signed cert
|
2018-11-08 |
SPL-159552, SPL-163568, SPL-161659, SPL-161660, SPL-161688, SPL-162483, SPL-162484 |
SAML - "role" not parsing comma separated list
|
2018-11-06 |
SPL-160537, SPL-160761, SPL-161367, SPL-161369, SPL-162604 |
saml - "Did not find a saml session index for this session, maybe a local user" should be WARN
|
Search issues
Date resolved
|
Issue number
|
Description
|
2018-11-09 |
SPL-154678, SPL-159962, SPL-162439, SPL-162440, SPL-162447, SPL-162448 |
|metadata search error - Failed to apply deletes to some metadata
|
2018-11-08 |
SPL-159400, SPL-160293, SPL-160294, SPL-160295 |
Assertion in PortableIovecCursor::bytesLeftToWrite() during search job export
|
2018-11-08 |
SPL-162669, SPL-159002 |
Search process crashing - thread: phase_1 - Segmentation fault in LookupTable::applyLookup
|
2018-11-07 |
SPL-158401, SPL-160505, SPL-160506, SPL-160507 |
Search with a FullFilePath containing \\ produce less events than with * and less over a longer period
|
2018-11-06 |
SPL-159006, SPL-160172, SPL-162158, SPL-162183 |
Memmapping Errors when using geospatial lookups
|
2018-11-01 |
SPL-161351 |
Turn down frequency of "Disabling automatic lookup of table='" to debug
|
2018-10-26 |
SPL-144752, SPL-161069, SPL-162298, SPL-162495 |
Token values are not extracted all the time with sendemail command
|
2018-10-23 |
SPL-161871, SPL-153621 |
Search shows "No results found" intermittently due to difference in minutes part between timezones of splunk instance and user preference
|
2018-09-28 |
SPL-149404, SPL-153486, SPL-157068, SPL-160449 |
Search.log error message asks user to consider increasing match limit for a Regex without a reason
|
2018-09-19 |
SPL-158486, SPL-159930, SPL-160098, SPL-160106 |
tstats return less/no events if there is a cycle lookup field with NOT filter
|
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2018-10-25 |
SPL-161715, SPL-144102 |
Custom Alert Action Parameters fails when Search has | (pipe) in its name
|
Charting, reporting, and visualization issues
Date resolved
|
Issue number
|
Description
|
2018-10-23 |
SPL-161708, SPL-158788 |
Scheduling PDF from Exporting Dashboard UI Issue
|
Indexer and indexer clustering issues
Date resolved
|
Issue number
|
Description
|
2018-11-12 |
SPL-162800, SPL-161301 |
For a multisite cluster, splunk is not reaping prior search-buckets manifests after new generation
|
2018-11-06 |
SPL-162302 |
Crashing thread: CMMasterServiceThread
|
2018-10-29 |
SPL-162290, SPL-155681 |
Splunk on a search head, hits OOM killer by storing a vast, untold, quantity of messages
|
Universal forwarder issues
Date resolved
|
Issue number
|
Description
|
2018-11-20 |
SPL-161891, SPL-163080, SPL-163081 |
RPM dependencies (/bin/mv, uname, which, hostname)
|
Monitoring Console issues
Date resolved
|
Issue number
|
Description
|
2018-09-24 |
SPL-160348, SPL-158166 |
Monitoring Console does not allow user to select 'All Queues' in Queues to Measure dropdown
|
Splunk Web and interface issues
Date resolved
|
Issue number
|
Description
|
2018-11-09 |
SPL-154871, SPL-145546 |
When assigning indexes to roles, indexes defined on the indexer tier are not displayed
|
Windows-specific issues
Date resolved
|
Issue number
|
Description
|
2018-11-09 |
SPL-162352, SPL-158197 |
splunk-regmon - failed to start the driver due to permission issue
|
2018-11-05 |
SPL-162146, SPL-145841 |
MonitorNoHandle do not respect _TCP_ROUTING in inputs.conf
|
Admin and CLI issues
Date resolved
|
Issue number
|
Description
|
2018-11-08 |
SPL-162465, SPL-142345 |
SHOULD_LINEMERGE always shows true on UI when there is a LINE_BREAKER setting in sourcetype
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2018-11-14 |
SPL-160031, SPL-158931 |
Suppress introspection errors from bulletin board on Cloud instances
|
2018-11-13 |
SPL-162723, SPL-159413 |
"Failed to localize" due to "ERROR CacheManagerHandler"..."not an owner"..."and the bucket is draining"
|
2018-11-09 |
SPL-158550, SPL-157891 |
Unable to open bucket as bucket is stuck in stale state
|
2018-11-08 |
SPL-161252, SPL-159966 |
ADP: "Failed to localize" after startup because bucket is not registered with the CacheManager until repair finishes
|
2018-10-31 |
SPL-154451, SPL-159988, SPL-161122, SPL-161123, SPL-161124, SPL-161125 |
Only 100 indexes are listed when creating or modifying a HEC on SH
|
2018-10-30 |
SPL-162299, SPL-161462 |
Splunk is crashing with CacheManager FATAL error
|
2018-10-22 |
SPL-160871, SPL-142546 |
System message emanating from a search peer prompts to restart the search-head instead of the search peer it originates from
|
2018-10-05 |
SPL-160347, SPL-159547 |
Automatic Timestamp recognition fails for formats that use single-digit zero for hour
|
Feedback submitted, thanks!