Fixed issues
Splunk Enterprise 7.1.3 was released on September 7, 2018. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.
Highlighted issues
Date resolved
|
Issue number
|
Description
|
2018-07-13 |
SPL-156441, SPL-146352 |
LDAP reload can severely delay remote app deployment, need app reload metrics to improve diagnosability.
|
Authentication and authorization issues
Date resolved
|
Issue number
|
Description
|
2018-08-16 |
SPL-158573, SPL-156361 |
Splunk is crashing with DUO authentication after reload is issued
|
2018-07-03 |
SPL-155317, SPL-149332 |
SAML - Upon Login Failure all current roles being sent is displayed to user in error message
|
Data input issues
Date resolved
|
Issue number
|
Description
|
2018-08-20 |
SPL-157923, SPL-147638 |
Splunkd crashes when HEC inputs configuration contains duplicated tokens
|
2018-07-27 |
SPL-157522, SPL-156315 |
After upgrade to 7.x, HEC events greater than 512KB are dropped with parsing errors, resulting in degrade of indexing throughput
|
2018-07-16 |
SPL-152197, SPL-147327 |
Error message for corrupted FSChangeMonitor database is not actionable.
|
Search issues
Date resolved
|
Issue number
|
Description
|
2018-09-24 |
SPL-154973, SPL-155773, SPL-158832 |
timeline preview shows random events, but not the ones based on the selected timeline segment
|
2018-08-20 |
SPL-157931, SPL-157359 |
Searching a bucket with a stale .rbsentinel.lock file causes the search to hang
|
2018-08-15 |
SPL-158035, SPL-157120 |
Customer upgrade to splunk 7.1 and this broke his HUNK Archive index.
|
2018-08-15 |
SPL-158681, SPL-144312 |
Owner of Macros can not be reassigned in Web UI in version 6.6.x
|
2018-08-14 |
SPL-158581, SPL-157433 |
lookup OUTPUTNEW commands mistakenly cause optimizer to remove preceding search commands resulting in missing field values.
|
2018-08-10 |
SPL-158568, SPL-153464 |
Job Progress Status goes from 0 to 100 back to 0
|
2018-08-03 |
SPL-153836, SPL-142710 |
Splunk ignores "is_risky=false" setting for any command that is not an actual custom script like sendemail. For example the setting is ignored for outputlookup and outputcsv.
|
2018-08-01 |
SPL-158130, SPL-152245 |
Scheduled search job terminated unexpectedly
|
2018-07-27 |
SPL-154531, SPL-152434 |
xml export bloats in size due to repeated <fieldOrder> section
|
2018-07-27 |
SPL-153976, SPL-157687 |
Splunkd Crashes When Opening A Simple Dashboard
|
2018-07-25 |
SPL-157799, SPL-157619, ITSI-1332 |
When you click in a generated search to run the search in a separate tab, no results are displayed and no errors are logged because the search process has crashed.
|
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2018-08-22 |
SPL-157939, SPL-154061 |
Configuring the scheduler to be turned off on indexers results in a flood of UI warnings, needlessly alarming the Splunk administrator
|
2018-08-16 |
SPL-157792, SPL-153649 |
Search scheduler shifts earliest_time and latest_time based on the skew, when using allow_skew
|
2018-08-10 |
SPL-158566, SPL-153792 |
Datamodel works both accelerated and non-accelerated in standalone, but fails on indexer instance when accelerated in an indexer clustered environment
|
Charting, reporting, and visualization issues
Date resolved
|
Issue number
|
Description
|
2018-07-27 |
SPL-153976, SPL-157687 |
Splunkd Crashes When Opening A Simple Dashboard
|
Data model and pivot issues
Date resolved
|
Issue number
|
Description
|
2018-08-15 |
SPL-158340, SPL-152600 |
Save the pivot table as a Report or Dashboard: Pivot Table Error - Error in PivotRowCol
|
2018-08-10 |
SPL-158566, SPL-153792 |
Datamodel works both accelerated and non-accelerated in standalone, but fails on indexer instance when accelerated in an indexer clustered environment
|
Indexer and indexer clustering issues
Date resolved
|
Issue number
|
Description
|
2018-08-20 |
SPL-157931, SPL-157359 |
Searching a bucket with a stale .rbsentinel.lock file causes the search to hang
|
2018-08-10 |
SPL-158272, SPL-148413 |
Bucket fix-up stack stuck with reason "potential dup primaries" prevents cluster from advertising all data searchable
|
2018-07-04 |
SPL-155703, SPL-153569 |
Data rebalance blocked by stuck bucket discard
|
Distributed search and search head clustering issues
Date resolved
|
Issue number
|
Description
|
2018-08-10 |
SPL-156177, SPL-151900 |
Distsearch.conf: value specified in disabled_server property will get ignored, if same value exists in servers property
|
2018-08-10 |
SPL-157927, SPL-157978 |
Scheduler blocked during pruning savedsearch history due to slow LDAP server
|
2018-08-10 |
SPL-158112, SPL-154592 |
Incorrect Version Mismatch Message
|
2018-07-26 |
SPL-156425, SPL-155536 |
prolonged gaps in SHC captain metrics.log group=searchscheduler
|
2018-07-13 |
SPL-156441, SPL-146352 |
LDAP reload can severely delay remote app deployment, need app reload metrics to improve diagnosability.
|
Distributed deployment, forwarder, deployment server issues
Date resolved
|
Issue number
|
Description
|
2018-07-10 |
SPL-156355, SPL-149328 |
Deployment Clients unable to connect to Deployment Server with phoneHomeIntervalInSecs = 600
|
2018-07-04 |
SPL-156539, SPL-155035 |
Splunk Fowarders splunkd process stopping - Crashing thread: HttpClientPollingThread
|
Monitoring Console issues
Date resolved
|
Issue number
|
Description
|
2018-08-10 |
SPL-158342, SPL-156694 |
"Failed to fetch DMC settings to verify status" error in web_service.log when clicking "Settings> Data Inputs" from Splunk Web
|
Splunk Web and interface issues
Date resolved
|
Issue number
|
Description
|
2018-09-24 |
SPL-154973, SPL-155773, SPL-158832 |
timeline preview shows random events, but not the ones based on the selected timeline segment
|
2018-08-19 |
SPL-158678, SPL-153034 |
Formatting of an event is not kept when piped to table
|
2018-08-14 |
SPL-157829, SPL-157139 |
Can not display more than 30 alerts in Alert's trigger actions
|
2018-08-14 |
SPL-157127, SPL-156282 |
Wrong description in lookup definition in UI
|
2018-08-10 |
SPL-157125, SPL-154541 |
No filter by owner in views when owner contains a back slash "\"
|
2018-07-30 |
SPL-157317, SPL-157705 |
In Forwarder Management Web GUI screen, 'more server classes' pop-up has titile: Apps
|
2018-07-04 |
SPL-155339, SPL-153658 |
UI Visualizations of wide lists are not rendered correctly.
|
Admin and CLI issues
Date resolved
|
Issue number
|
Description
|
2018-08-14 |
SPL-158504, SPL-136970 |
default and local meta files getting corrupt or being alterted in such a way as to cause warnings.
|
2018-07-10 |
SPL-154478, SPL-153105 |
New splunkd_stop_timeout parameter in server.conf displays validation warning when pushed from cluster master
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2018-08-22 |
SPL-159188, SPL-146261 |
Search Assistant executes subsearches incurring subsearch side effects and increased CPU and memory usage
|
2018-08-22 |
SPL-155093, SPL-148815 |
Mistranslation of "Product Tour" > "Add Data Tour" in Japanese
|
2018-08-22 |
SPL-158074, SPL-157436 |
404 Error: quality_of_incoming_data
|
2018-08-21 |
SPL-157820, SPL-157190 |
Remote Storage: Time out attempting to localize remote bucket
|
2018-08-16 |
SPL-157342, SPL-157795 |
Prebuilt panels text in an app are not extracted for localization when using "splunk extract i18n -app <appname>" command
|
2018-08-16 |
SPL-158120, SPL-153699 |
Indexer message/slowness after splunk 7 upgrade and possibly reducing indexer capacity to half.
|
2018-08-15 |
SPL-156540, SPL-147803 |
License master rollovers stopped by a broken syslog output blocking indexing, need better logging for diagnosability.
|
2018-08-10 |
SPL-157897, SPL-155772 |
SEDCMD not working for long characters
|
2018-08-09 |
SPL-158142, SPL-157745 |
Lengthy login_content messages run off login window
|
2018-07-31 |
SPL-155385, SPL-154018 |
Splunkd looks for default openssl cert file under build path
|
2018-07-27 |
SPL-156899, SPL-153174 |
Request for better messaging for "Duplicated License situation happen on peer ..."
|
Splunk Analytics for Hadoop
Date resolved
|
Issue number
|
Description
|
2018-07-27 |
ERP-2140, ERP-2092 |
Role Inheritance Failure
|
Feedback submitted, thanks!