Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Fixed issues

Splunk Enterprise 7.1.2 was released on July 11, 2018. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Date resolved Issue number Description
2018-06-19 SPL-155560, SPL-155219 DMA accelerating too much data when acceleration.backfill_time unset, resulting in heavy indexer load
2018-06-15 SPL-155291, SPL-152556 fill_summary_index.py fails in SHC environment

Search issues

Date resolved Issue number Description
2018-07-04 SPL-153745, SPL-153724 The mcollect and meventcollect commands erroneously count against licensing.
2018-06-18 SPL-154876, SPL-152598 The "srtemp" directory can grow to hundreds of GB in size and fill up the disk due to orphaned temporary files left behind by abnormally terminated searches and never reaped
2018-06-15 SPL-155413, SPL-155106 splunkd process consuming large amount of memory in 7.0
2018-06-14 SPL-148349, SPL-145602 REGEX flag (?J) "duplicate group names" causes splunk to crash
2018-06-14 SPL-152492, SPL-148796 ui_inactivity_timeout not working even after search completes
2018-06-13 SPL-154420, SPL-153686 invalid regex range causing splunk to crash
2018-06-12 SPL-154463, SPL-154931 When eventstats is the last command in a reporting search in Splunk 7.1.0 the stats tab truncates all results past a certain number of results.
2018-06-11 SPL-154969, SPL-153432 The bins option returns inconsistent count values in distributed environment
2018-06-04 SPL-155091, SPL-145560 Splunkd DispatchManager logging is inconsistent
2018-06-01 SPL-152808, SPL-141639 6.5.2 Error in chart command: The value for option span is invalid: log10
2018-05-23 SPL-152236, SPL-151719 Windows Events Logs: Hidden Character Added To Field Name Breaks Search
2018-05-15 SPL-152728, SPL-135296 SearchResults complains in splunkd.log about a corrupt CSV file header without naming the problematic file or lookup table

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2018-06-19 SPL-155560, SPL-155219 DMA accelerating too much data when acceleration.backfill_time unset, resulting in heavy indexer load
2018-06-14 SPL-154403, SPL-147319 SHC AuthenticationManagerLDAP complains "Could not find user="system"" flooding splunkd.log
2018-06-08 SPL-154836, SPL-154136 Duplicate alerts are triggered for real time alert type on Splunk Enterprise 7.1.0
2018-06-01 SPL-153150, SPL-148958 tstats will not return any results from an Accelerated Datamodel/Namespace/tscollect job if the raw event has 2-byte characters

Data model and pivot issues

Date resolved Issue number Description
2018-06-19 SPL-155560, SPL-155219 DMA accelerating too much data when acceleration.backfill_time unset, resulting in heavy indexer load
2018-06-14 SPL-154403, SPL-147319 SHC AuthenticationManagerLDAP complains "Could not find user="system"" flooding splunkd.log
2018-06-01 SPL-153150, SPL-148958 tstats will not return any results from an Accelerated Datamodel/Namespace/tscollect job if the raw event has 2-byte characters

Indexer and indexer clustering issues

Date resolved Issue number Description
2018-06-25 SPL-155130, SPL-154986 single-copy bucket stuck with status "no possible primaries", causes entire cluster to be tagged as "not fully searchable"
2018-06-12 SPL-155226, SPL-153036 CMBucketId has lock contention from std::map log(n) lookup time
2018-06-08 SPL-154354, SPL-146575 RF and SF not being met on CM after adding new Indexes and rolling restart
2018-06-08 SPL-154648, SPL-152465 Clustering - when a peer is in detention, we will make excess copies
2018-05-15 SPL-151811, SPL-146335 DispatchReaper not cleaning up remote-bundle files on CM

Distributed search and search head clustering issues

Date resolved Issue number Description
2018-06-27 SPL-155642, SPL-154870 BundleDeltaHandler failing on indexing_tokens directory
2018-06-26 SPL-155520, SPL-154419 SHC captain does not clean up local bundles after failed replication attempts
2018-06-24 SPL-154067, SPL-154032 SHC bundle rejected at push-time because of built-in apps warning is still created and picked up by SHC members, completely defeating the purpose of that safeguard
2018-06-21 SPL-154830, SPL-141363 Indexers report "Unknown search command" for external search commands even though the indexers contain the search bundle with the external command
2018-06-20 SPL-152625, SPL-130444 SHC: alert suppression may fail during restart if suppression information does not exist locally on member
2018-06-20 SPL-155639, SPL-154654 SHC captain stops delegating DMA searches after a delegated DMA search job fails (status=delegated_remote_completion, success=0).
2018-06-18 SPL-152420, SPL-145554 The savedsearch key/value field is not quoted in SHCMaster log message breaking extraction
2018-06-11 SPL-153314, SPL-152280 Deployer app staging area may miss bundles if preparation takes more than 10 minutes.
2018-06-06 SPL-154089, SPL-154739 Search heads may fail with "Skip search X during searchable rolling process" in invalid configurations where they communicate with cluster masters in an older version.
2018-05-23 SPL-152139, SPL-132295 Excessive "Inconsistent bundles" Logging
2018-05-15 SPL-153833, SPL-148106 Crashing thread: TcpChannelThread, Assertion `_slave != __null ClusteringMgr::_slave_writeBucketsToSearch.

Universal forwarder issues

Date resolved Issue number Description
2018-05-23 SPL-153631, SPL-151229 AIX 7.1 Deployment Server Restarting UF give splunkd; SRC did not 'chssys splunkd' on our behalf: exit code=-1

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2018-06-07 SPL-155009, SPL-153261 Slow Performance in the Deployment Server UI and sometime crash the browser
2018-05-23 SPL-154008, SPL-148851 Application bundle cache (by default under $SPLUNK_HOME/var/run/tmp/) *never* gets cleaned up on Deployment server even server class no longer exists

Monitoring Console/DMC issues

Date resolved Issue number Description
2018-06-14 SPL-155092, SPL-149486 "HTTP Event Collector: Deployment" dashboard is not rendering at all and incorrectly reports "You currently have no tokens configured"
2018-05-15 SPL-153766, SPL-138918 Mount points are not listed correctly in "Average I/O Usage and Performance" panel of Monitoring Console

Splunk Web and interface issues

Date resolved Issue number Description
2018-06-29 SPL-156316, SPL-145546 When assigning indexes to roles, indexes defined on the indexer tier are not displayed
2018-06-14 SPL-152492, SPL-148796 ui_inactivity_timeout not working even after search completes
2018-05-23 SPL-153996, SPL-147061 debug/refresh reports errors on vanilla install

Windows-specific issues

Date resolved Issue number Description
2018-05-23 SPL-153193, SPL-151800 Windows Registry Monitoring Input is ignoring the _TCP_ROUTING setting

Rest, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2018-06-15 SPL-155291, SPL-152556 fill_summary_index.py fails in SHC environment
2018-06-14 SPL-154840, SPL-153655 /services/search/jobs/*/results is responding with duplicate JSON field 'init_offset' when output_mode is 'json_cols' and search has no result

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2018-06-01 SPL-153125, SPL-151937 Scripted authentication fails to parse getSearchFilter output, hitting PCRE_ERROR_MATCHLIMIT.

Admin and CLI issues

Date resolved Issue number Description
2018-06-15 SPL-155555, SPL-146439 Saving roles manager page when no indexes are listed remove previous indexes
2018-06-15 SPL-155429, SPL-153624 savedsearches.conf configuration is_visible needs clarification
2018-06-08 SPL-154021, SPL-153625 leading and trailing comma validation should be robust for http proxy configuration
2018-06-05 SPL-154589, SPL-154772, SPL-155190, SPL-155191, SPL-155194 Enabling splunk boot-start won't work with ubuntu-like distro
2018-05-28 SPL-152846, SPL-147286 Setting DATETIME_CONFIG as filename does not update props.conf

Unsorted issues

Date resolved Issue number Description
2018-07-04 SPL-153745, SPL-153724 The mcollect and meventcollect commands erroneously count against licensing.
2018-06-06 SPL-154616, SPL-152935 KVStore Replication Error: replSetReconfig got BadValue _id field value of 256 is out of range
2018-05-23 SPL-153081, SPL-147956 mstats not returning results
2018-05-15 SPL-153082, SPL-145094 introspection: IOStats read incorrect if more than one partition created on one physical drive

Uncategorized issues

Date resolved Issue number Description
2018-06-19 SPL-155451, SPL-152888 Chunks of summary index data are routed to the wrong index when queues are blocked
2018-06-15 SPL-149190, SPL-141808 (Windows Only) Support sslRootCAPath on Windows
2018-06-06 SPL-154369, SPL-153668 When exporting to PDF one particular IP Address generates an error while others work
2018-06-03 SPL-154567, SPL-154139 embedded report uses oldest search artifact from the history endpoint
2018-05-25 SPL-154015, SPL-145371 Bulletin board message timestamp incorrect on SHC members
2018-05-23 SPL-154130, SPL-153011 HTML entity name appears in Tour dialog if username contains &,<,>,",'
2018-05-23 SPL-152244, SPL-135274 search assistant incorrectly wrapping kv pairs in quotes
2018-05-22 SPL-154367, SPL-152887 Color Range Feature coupled with real-time search causes the colors to flicker when updating
2018-05-18 SPL-152438, SPL-151132 PDF export broken with SimpleXML <init> TAG
2018-05-15 SPL-153420, SPL-145043 Too long of a dashboard title throws nondescript error message
2018-05-15 SPL-153758, SPL-153687 Dashboard time range picker selected state does not correctly display certain ranges
PREVIOUS
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.1.2


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters