Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Fixed issues

Splunk Enterprise 7.1.0 was released on April 24, 2018. This release includes fixes for the following issues.

For more information about security fixes, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Search issues

Date resolved Issue number Description
2018-03-14 SPL-148633, SPL-144670 Log required field back-propagation
2018-03-02 SPL-149361, SPL-146354 Adding more detail to no_proxy option under server.conf
2018-02-23 SPL-147664, SPL-142442 The rex command, when used on a field that doesn't exist (i.e. null) or on an event that fails to match, causes the optimizer to mistakenly optimize out preceding search commands
2018-02-22 SPL-148402, SPL-145724 streamstats and eventstats fail to clear the multivalue component for any generated fields
2018-01-26 SPL-145965, SPL-141829 CIDR Search not returning expected behavior after upgrade to 6.6.0
2018-01-16 SPL-148042, SPL-148047, SPL-148048, SPL-148049 datamodel command flat search does not work properly

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2018-02-09 SPL-148154, SPL-147646 "Email when complete" only sends to first email address in list
2018-01-30 SPL-145702, SPL-142783 stack overflow when expanding pivot with circular dependency
2017-11-08 SPL-146093, SPL-142612 Some default license alerts are not returning any results for splunk cloud

Charting, reporting, and visualization issues

Date resolved Issue number Description
2018-01-18 SPL-147210, SPL-145825 Rendering issues for stacked area graph with Null Values = Gaps

Data model and pivot issues

Date resolved Issue number Description
2018-02-09 SPL-148154, SPL-147646 "Email when complete" only sends to first email address in list
2018-01-30 SPL-145702, SPL-142783 stack overflow when expanding pivot with circular dependency
2017-11-08 SPL-146093, SPL-142612 Some default license alerts are not returning any results for splunk cloud

Indexer and indexer clustering issues

Date resolved Issue number Description
2018-02-18 SPL-148621, SPL-147640 "DatabaseDirectoryManager - Getting size on disk" errors persist on version 6.5.6
2018-02-09 SPL-148862, SPL-148830 Indexer Discovery not working with no indexer_discovery stanza in 7.0.x
2018-02-08 SPL-146202, SPL-142643 Cluster peer crashed due to "Crashing thread: TcpListener" "Assertion `pProcessor != __null' failed."
2018-02-08 SPL-146001, SPL-142193 too many hot bucket rolls causing replication failures
2018-02-01 SPL-146292, SPL-143401 REGEX in transforms is hitting PCRE recursion limit
2018-01-26 SPL-145276, SPL-143967 event=commitGenerationFailure for non-existent bucket
2018-01-26 SPL-144482, SPL-143402 Fsck processes are stuck leading to fixup tasks not completing .
2017-11-01 SPL-146088, SPL-151973, SPL-151110, SPL-151111 Clustering creates extra copies of buckets erroneously.

Distributed search and search head clustering issues

Date resolved Issue number Description
2018-02-02 SPL-146110, SPL-141347 Improve error message when peers closing or resetting the connection while searching
2018-01-30 SPL-146722, SPL-145290 dispatch folder filling up with artifact RemoteStorageRetrieveIndexes_1506518206.19514 on the cluster-master
2018-01-26 SPL-146674, SPL-143060 Rename/Untar errors - over 100,000 errors across all peers
2018-01-25 SPL-145197, SPL-142756 Large number of bundles in var/run/searchpeers when the latest common bundle in distributed search doesn't progress.
2018-01-11 SPL-147265, SPL-146356 SHC captain stops delegating searches to itself after a while when using scheduler_load_based

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2018-01-24 SPL-145274, SPL-143764 Deployment server doesn't always update client attributes without a reload, resulting in stale data on the Forwarder Management UI.

Splunk Web and interface issues

Date resolved Issue number Description
2018-03-02 SPL-149361, SPL-146354 Adding more detail to no_proxy option under server.conf
2018-02-27 SPL-148610, SPL-139017 The messages.po file contains French translations of css object when it shouldn't
2018-01-24 SPL-147406, SPL-144340 Lookup Definition Case Sensitivity in Web GUI should reflect default settings

Windows-specific issues

Date resolved Issue number Description
2017-10-17 SPL-144222, SPL-142071 splunk-winevtlog crashes on unregistering wait handle

Rest, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2018-03-02 SPL-148831 Upgrade to Python 2.7.14 or later

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2018-04-09 SPL-146269, SPL-142994 SAML User session logout results in infinite loop when SLO is configured to point to SP(Splunk Logout) with ADFS
2018-03-02 SPL-148831 Upgrade to Python 2.7.14 or later
2018-02-14 SPL-146113, SPL-144798 uiStatusPage doesn't respect root_endpoint in SAML deployments.
2018-02-09 SPL-144309, SPL-141681 Custom web.conf:root_endpoint may cause SAML authentication to fail.

PDF issues

Date resolved Issue number Description
2017-12-12 SPL-144174, SPL-132666 Exported pdf shows token string for the dashboard element's title property instead of its value

Unsorted issues

Date resolved Issue number Description
2018-03-02 SPL-148831 Upgrade to Python 2.7.14 or later
2018-02-08 SPL-147089, SPL-143398 Slow license master response times after upgrade to 6.5 due to __tz_convert() bottleneck and extensive debug logging calls for lots of warnings
2018-01-31 SPL-148577, SPL-144346 The metadata command datatype argument value should be same as index creation CLI
2018-01-22 SPL-146940, SPL-154028, SPL-148483, SPL-147898, SPL-147899, SPL-154029 TcpOutputProc randomly drops indexers from the server list
2017-10-23 SPL-144346, SPL-148577, SPL-145047 The metadata command does not work with metrics indexes
2017-10-05 SPL-145141, SPL-145487 mstats and mcatalog search all indexes rather than a default index
2017-10-02 SPL-144856 The mstats command does not work when using parentheses around a single metric_name argument

Uncategorized issues

Date resolved Issue number Description
2018-02-20 SPL-145963, SPL-143331 default_match is not honoured when lookup matches is 0 (using a kvstore collection)
2018-02-16 SPL-146288, SPL-130415 Deadlock during shutdown
2018-02-09 SPL-146514 MessagesManager functionality needs to be available before and during UserManager initialization.
2018-02-09 SPL-145250, SPL-143141 SSL error for validation of self-signed certificates is not actionable.
2018-01-24 SPL-145243, SPL-145097 MessagesManager may deadlock during splunk startup when SAML is enabled.
2018-01-24 SPL-145964, SPL-143204 CIDR searches providing different results than a wildcard search (host=172.29.100.0/24 vs host=172.29.100.*)
2017-11-29 SPL-144661 Upload datamodel dialog has duplicate and inaccurate error messages
2017-09-21 SPL-124026, SPL-122942 Relative paths should not be allowed under volume's path=file:// on remote storages


Splunk Analytics for Hadoop

Date resolved Issue number Description
2018-01-29 ERP-2111, ERP-2079 Large splunk_archiver.log causes space problems.
PREVIOUS
Linux kernel memory overcommitting and Splunk crashes
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.1.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters