Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


Splunk Enterprise version 7.1 is no longer supported as of October 31, 2020. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 7.1.4 was released on October 22, 2018. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Highlighted issues

Date filed Issue number Description
2018-08-29 SPL-159442, SPL-156444 Searches may take considerably more memory than with 7.0.x or earlier. This applies particularly to searches that search and/or return a large result set. Due to search speed performance improvements some memory usage increase is expected with 7.1.x even after this issue is fixed.

Search issues

Date resolved Issue number Description
2018-10-05 SPL-157727, SPL-144000 Can't search for indexed fields included in summary index since fields.conf "INDEXED = true" since 6.6
2018-10-02 SPL-159442, SPL-160079, SPL-160171, SPL-160019 High Memory usage from a | dedup search after updating to 7.1.2
2018-09-30 SPL-158259, SPL-160421, SPL-160574 result_queue_max_size is not working with 7.1.2
2018-09-28 SPL-159182, SPL-159414, SPL-160318, SPL-161161 Unbounded memory growth with transactions and keeporphans
2018-09-27 SPL-160449, SPL-149404 Search.log error message asks user to consider increasing match limit for a Regex without a reason
2018-09-25 SPL-159318, SPL-159666, SPL-160523 search process crash in AST due to subsearch in a saved search
2018-09-19 SPL-160169, SPL-158283 Splunk crashing with selfjoin
2018-09-19 SPL-155679, SPL-160875 After upgrade splunk to 7.1.1, splunkd is crashing very often on SHPHeartbeatThread
2018-09-19 SPL-160098, SPL-158486 tstats return less/no events if there is a cycle lookup field with NOT filter
2018-09-12 SPL-158934, SPL-159726, SPL-159751 Post 7.1.1 upgrade issue: stats aggregating in additional empty records with mix of prestats and event data
2018-09-12 SPL-156444, SPL-160015 High Memory usage on process after updating to 7.1.1
2018-08-28 SPL-154920, SPL-156245, SPL-159249 Search Removal With Case Insensitive Capability

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2018-09-17 SPL-159602, SPL-159053 Trigger Time format in alert emails without AM/PM designators and no Timezone information.

Charting, reporting, and visualization issues

Date resolved Issue number Description
2018-09-18 SPL-157992, SPL-158984, SPL-158911, SPL-159564 Geom used in dashboard causing crash
2018-09-10 SPL-159637, SPL-158897 Selected time picker on dashboard is not translated

Indexer and indexer clustering issues

Date resolved Issue number Description
2018-10-05 SPL-159407, SPL-157189 splunk is not reaping prior search-buckets manifests after new generation

Distributed search and search head clustering issues

Date resolved Issue number Description
2018-09-17 SPL-159860, SPL-158218 Custom search commands do not work on indexers when search's app context does not exist

Universal forwarder issues

Date resolved Issue number Description
2018-10-08 SPL-160530, SPL-156698 splunk-netmon consumes additional 2GB memory every day on Universal Forwarder

Monitoring Console/DMC issues

Date resolved Issue number Description
2018-09-21 SPL-160349, SPL-158166 Monitoring Console does not allow user to select 'All Queues' in Queues to Measure dropdown

Splunk Web and interface issues

Date resolved Issue number Description
2018-09-13 SPL-159197, SPL-158196 Users page doesn't show default pagination correctly
2018-08-28 SPL-154920, SPL-156245, SPL-159249 Search Removal With Case Insensitive Capability

Windows-specific issues

Date resolved Issue number Description
2018-10-08 SPL-160530, SPL-156698 splunk-netmon consumes additional 2GB memory every day on Universal Forwarder
2018-10-08 SPL-159549, SPL-153030 PowerShell inputs fail after several runs

Authentication and Authorization issues

Date resolved Issue number Description
2018-09-04 SPL-157717, SPL-159084, SPL-159085 Splunk local authentication: User REST call causes splunk to crash, once the user password expiration days becomes less than 'Expiration alert in days'

Admin and CLI issues

Date resolved Issue number Description
2018-10-12 SPL-161286, SPL-154594 system/default/props.conf for python.log just plain WRONG
2018-09-21 SPL-158762, SPL-158949, SPL-159931 Sorting on "type" column in lookup definitions does not work

Uncategorized issues

Date resolved Issue number Description
2018-12-03 SPL-158771, SPL-159016, SPL-159703 Splunk Enterprise Login page is not localized
2018-10-17 SPL-158349 Splunk Search head initial kv sync is failing
2018-10-10 SPL-158708, SPL-159416, SPL-161121 Localization of dashboard content broken for tokenized strings
2018-10-10 SPL-158938, SPL-158931 Suppress introspection errors from bulletin board on Cloud instances
2018-10-05 SPL-160350, SPL-159547 Automatic Timestamp recognition fails for formats that use single-digit zero for hours
2018-10-05 SPL-160869, SPL-142546 System message emanating from a search peer prompts to restart the search-head instead of the search peer it originates from
2018-10-03 SPL-156206, SPL-154378 Splunk Introspection mem_used misreporting very high values "17592186044029.098"
2018-09-21 SPL-159614, SPL-158875 splunk shipped python in *nix doesn't work with iso2022_jp
2018-09-13 SPL-155513, SPL-159646, SPL-159848 Mstats not honoring time picker range for windowed real time search
2018-09-11 SPL-159622, SPL-159061 local values for browser tab header text not being respected
2018-08-29 SPL-158939, SPL-154144 CPU Cores Not Calculated Properly or Correctly
Last modified on 17 August, 2020
PREVIOUS
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.1.4


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters