Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF

Splunk Enterprise version 7.0 is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 7.0.9 was released on February 27, 2019.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Search issues

Date resolved Issue number Description
2019-02-07 SPL-141395, SPL-166005, SPL-164542, SPL-166004 Search Peer Crash - Crashing thread: NonRedistExecutorThread
2019-02-04 SPL-165312, SPL-162306 Search returns 78 events, when you specify | noop search_optimization=true or false it returns 165 results
2019-01-04 SPL-164144, SPL-163825 Search process management may fail on race conditions resulting in spurious status as in SPL-152541.

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2019-01-17 SPL-157118, SPL-161721, SPL-164488, SPL-164489 invisible datamodels /data/models/._*.json files are causing the manager to fail finding the datamodel definition

Data model and pivot issues

Date resolved Issue number Description
2019-01-17 SPL-157118, SPL-161721, SPL-164488, SPL-164489 invisible datamodels /data/models/._*.json files are causing the manager to fail finding the datamodel definition

Indexer and indexer clustering issues

Date resolved Issue number Description
2019-02-12 SPL-161436, SPL-163136, SPL-166359, SPL-166360 SmartStore buckets with both earliest and latest timestamps 0 can't be replicated, bucket fix-up tasks stuck with "cannot fix up search factor as the bucket is not serviceable" status.
2019-01-17 SPL-162311, SPL-156164 Shutdown sequence does not begin after master has instructed peer to restart during rolling restart phase of a bundle push

Distributed search and search head clustering issues

Date resolved Issue number Description
2019-01-17 SPL-164011, SPL-164677, SPL-164731, SPL-164732 SHC: when captain node is in AutomaticDetention status, all alerts (scheduled searches) appear to have stopped as well.
2019-01-15 SPL-141869, SPL-156380, SPL-164476, SPL-164477 App bundle push issued from SHC app deployer extremely slow
2019-01-03 SPL-164430, SPL-164134 Search performance degrading over time
2018-12-05 SPL-162318, SPL-162906, SPL-163487, SPL-163488, SPL-163751 DispatchReaper fails to reap artifacts from fill_summary_index.py in SH Cluster

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2019-02-06 SPL-161043, SPL-141772 App deployment fails sporadically on Windows

Authentication and Authorization issues

Date resolved Issue number Description
2019-02-08 SPL-166197, SPL-156375 Capability to Schedule Saved Searches restricted after upgrade to 7.x.
2019-02-06 SPL-164997, SPL-163411 LookupAccountName No mapping between account names and security IDs was done
2018-11-29 SPL-161631, SPL-145067 Exclude user "nobody" from LDAP searches

Admin and CLI issues

Date resolved Issue number Description
2019-02-05 SPL-145827, SPL-156137, SPL-165766, SPL-165767 Capability rtsearch is enabling for power user after being remove when running CLI cmd and restarting splunk
2018-11-22 SPL-154372, SPL-162272, SPL-163099, SPL-163100 Shared embedded report is not loading when admin is logged in

Uncategorized issues

Date resolved Issue number Description
2019-03-15 SPL-163951, SPL-160833 Seeing 500 internal server error when opening many manager pages
2019-02-20 SPL-166673, SPL-165351 Mismatch between source and uploaded bucket metadata creates incorrect shell directory
2019-02-18 SPL-164979, SPL-166184, SPL-166510, SPL-166511 Search deadlock in StateStoreWorkerScheduler when executing kvstore lookup
2019-02-07 SPL-166106, SPL-165008 MaxMind GeoIP DB needs to be updated for Jan 2019
2019-01-30 SPL-164932, SPL-163072 introspection disk data appears to not be accurate
2019-01-29 SPL-159337, SPL-163271, SPL-163272, SPL-163273 Splunk UF crashing due to invalid EVENT_BREAKER
2019-01-17 SPL-163554, SPL-157146 Diag with SPLUNK_DB set to drive name and \ results in improper format on Windows
2019-01-16 SPL-159813, SPL-163056, SPL-164724, SPL-164725 Post 6.6 / 7.0 upgrade, power user role cannot edit alert.expires from UI
2019-01-14 SPL-162335, SPL-162709, SPL-164841, SPL-164842 IdataDO_Collector.cpp void collect__summaries(): Assertion `paths.size() == 2' failed.
2019-01-08 SPL-163808, SPL-165197, SPL-164105, SPL-164251, SPL-164252 CIM Setup page is showing single line because of syntax error in underlying search
2019-01-03 SPL-158199, SPL-160043, SPL-160046, SPL-164266, SPL-164267 when merging tsidx files, splunk optimize failed to open temporary manifest file due to file name collision cause by race condition
2018-12-19 SPL-162247, SPL-163448, SPL-163530, SPL-163531, SPL-163863, SPL-163865 After adding Tags Whitelist for Data Models, the newly added tags disappears when there is a change in the acceleration setting for the respective datamodel from the UI.
2018-12-14 SPL-157230, SPL-163803, SPL-163974, SPL-163975 conf-mutator.pid cleanup error during GUI initiated restart
2018-12-05 SPL-162714, SPL-163276, SPL-163298, SPL-163299 HEC: Source is not logged when invalid token is used
2018-11-30 SPL-163087, SPL-152828 Splunk does not start as specified user on boot on MacOS
Last modified on 03 June, 2020
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.0.9

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters