Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Fixed issues

Splunk Enterprise 7.1.3 was released on September 7, 2018. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Highlighted issues

Date resolved Issue number Description
2018-07-13 SPL-156441, SPL-146352 LDAP reload can severely delay remote app deployment, need app reload metrics to improve diagnosability.

Data input issues

Date resolved Issue number Description
2018-07-16 SPL-152197, SPL-147327 Error message for corrupted FSChangeMonitor database is not actionable.

Search issues

Date resolved Issue number Description
2018-09-24 SPL-154973, SPL-155773, SPL-158832 timeline preview shows random events, but not the ones based on the selected timeline segment
2018-08-20 SPL-157931, SPL-157359 Searching a bucket with a stale .rbsentinel.lock file causes the search to hang
2018-08-15 SPL-158035, SPL-157120 Customer upgrade to splunk 7.1 and this broke his HUNK Archive index.
2018-08-15 SPL-158681, SPL-144312 Owner of Macros can not be reassigned in Web UI in version 6.6.x
2018-08-14 SPL-158581, SPL-157433 lookup OUTPUTNEW commands mistakenly cause optimizer to remove preceding search commands resulting in missing field values.
2018-08-10 SPL-158568, SPL-153464 Job Progress Status goes from 0 to 100 back to 0
2018-08-03 SPL-153836, SPL-142710 Splunk ignores "is_risky=false" setting for any command that is not an actual custom script like sendemail. For example the setting is ignored for outputlookup and outputcsv.
2018-08-01 SPL-158130, SPL-152245 Scheduled search job terminated unexpectedly
2018-07-27 SPL-154531, SPL-152434 xml export bloats in size due to repeated <fieldOrder> section
2018-07-27 SPL-153976, SPL-157687 Splunkd Crashes When Opening A Simple Dashboard
2018-07-25 SPL-157799, SPL-157619, ITSI-1332 When you click in a generated search to run the search in a separate tab, no results are displayed and no errors are logged because the search process has crashed.

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2018-08-22 SPL-157939, SPL-154061 Configuring the scheduler to be turned off on indexers results in a flood of UI warnings, needlessly alarming the Splunk administrator
2018-08-16 SPL-157792, SPL-153649 Search scheduler shifts earliest_time and latest_time based on the skew, when using allow_skew
2018-08-10 SPL-158566, SPL-153792 Datamodel works both accelerated and non-accelerated in standalone, but fails on indexer instance when accelerated in an indexer clustered environment

Charting, reporting, and visualization issues

Date resolved Issue number Description
2018-07-27 SPL-153976, SPL-157687 Splunkd Crashes When Opening A Simple Dashboard

Data model and pivot issues

Date resolved Issue number Description
2018-08-15 SPL-158340, SPL-152600 Save the pivot table as a Report or Dashboard: Pivot Table Error - Error in PivotRowCol
2018-08-10 SPL-158566, SPL-153792 Datamodel works both accelerated and non-accelerated in standalone, but fails on indexer instance when accelerated in an indexer clustered environment

Indexer and indexer clustering issues

Date resolved Issue number Description
2018-08-20 SPL-157931, SPL-157359 Searching a bucket with a stale .rbsentinel.lock file causes the search to hang
2018-08-10 SPL-158272, SPL-148413 Bucket fix-up stack stuck with reason "potential dup primaries" prevents cluster from advertising all data searchable
2018-07-04 SPL-155703, SPL-153569 Data rebalance blocked by stuck bucket discard

Distributed search and search head clustering issues

Date resolved Issue number Description
2018-08-10 SPL-156177, SPL-151900 Distsearch.conf: value specified in disabled_server property will get ignored, if same value exists in servers property
2018-08-10 SPL-157927, SPL-157978 Scheduler blocked during pruning savedsearch history due to slow LDAP server
2018-08-10 SPL-158112, SPL-154592 Incorrect Version Mismatch Message
2018-07-26 SPL-156425, SPL-155536 prolonged gaps in SHC captain metrics.log group=searchscheduler
2018-07-13 SPL-156441, SPL-146352 LDAP reload can severely delay remote app deployment, need app reload metrics to improve diagnosability.

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2018-07-10 SPL-156355, SPL-149328 Deployment Clients unable to connect to Deployment Server with phoneHomeIntervalInSecs = 600
2018-07-04 SPL-156539, SPL-155035 Splunk Fowarders splunkd process stopping - Crashing thread: HttpClientPollingThread

Monitoring Console/DMC issues

Date resolved Issue number Description
2018-08-10 SPL-158342, SPL-156694 "Failed to fetch DMC settings to verify status" error in web_service.log when clicking "Settings> Data Inputs" from Splunk Web

Splunk Web and interface issues

Date resolved Issue number Description
2018-09-24 SPL-154973, SPL-155773, SPL-158832 timeline preview shows random events, but not the ones based on the selected timeline segment
2018-08-19 SPL-158678, SPL-153034 Formatting of an event is not kept when piped to table
2018-08-14 SPL-157829, SPL-157139 Can not display more than 30 alerts in Alert's trigger actions
2018-08-14 SPL-157127, SPL-156282 Wrong description in lookup definition in UI
2018-08-10 SPL-157125, SPL-154541 No filter by owner in views when owner contains a back slash "\"
2018-07-30 SPL-157317, SPL-157705 In Forwarder Management Web GUI screen, 'more server classes' pop-up has titile: Apps
2018-07-04 SPL-155339, SPL-153658 UI Visualizations of wide lists are not rendered correctly.

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2018-08-16 SPL-158573, SPL-156361 Splunk is crashing with DUO authentication after reload is issued
2018-07-03 SPL-155317, SPL-149332 SAML - Upon Login Failure all current roles being sent is displayed to user in error message

Admin and CLI issues

Date resolved Issue number Description
2018-08-14 SPL-158504, SPL-136970 default and local meta files getting corrupt or being alterted in such a way as to cause warnings.
2018-07-10 SPL-154478, SPL-153105 New splunkd_stop_timeout parameter in server.conf displays validation warning when pushed from cluster master

Unsorted issues

Date resolved Issue number Description
2018-08-20 SPL-157923, SPL-147638 Splunkd crashes when HEC inputs configuration contains duplicated tokens
2018-08-15 SPL-156540, SPL-147803 License master rollovers stopped by a broken syslog output blocking indexing, need better logging for diagnosability.
2018-07-27 SPL-156899, SPL-153174 Request for better messaging for "Duplicated License situation happen on peer ..."
2018-07-27 SPL-157522, SPL-156315 After upgrade to 7.x, HEC events greater than 512KB are dropped with parsing errors, resulting in degrade of indexing throughput

Uncategorized issues

Date resolved Issue number Description
2018-08-22 SPL-159188, SPL-146261 Search Assistant executes subsearches incurring subsearch side effects and increased CPU and memory usage
2018-08-22 SPL-155093, SPL-148815 Mistranslation of "Product Tour" > "Add Data Tour" in Japanese
2018-08-22 SPL-158074, SPL-157436 404 Error: quality_of_incoming_data
2018-08-21 SPL-157820, SPL-157190 Remote Storage: Time out attempting to localize remote bucket
2018-08-16 SPL-157342, SPL-157795 Prebuilt panels text in an app are not extracted for localization when using "splunk extract i18n -app <appname>" command
2018-08-16 SPL-158120, SPL-153699 Indexer message/slowness after splunk 7 upgrade and possibly reducing indexer capacity to half.
2018-08-10 SPL-157897, SPL-155772 SEDCMD not working for long characters
2018-08-09 SPL-158142, SPL-157745 Lengthy login_content messages run off login window
2018-07-31 SPL-155385, SPL-154018 Splunkd looks for default openssl cert file under build path


Splunk Analytics for Hadoop

Date resolved Issue number Description
2018-07-27 ERP-2140, ERP-2092 Role Inheritance Failure
PREVIOUS
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.1.3


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters