Splunk® Enterprise

Release Notes

Splunk Enterprise version 7.1 is no longer supported as of October 31, 2020. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 7.1.7 was released on April 1, 2019. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Authentication and authorization issues

Date resolved Issue number Description
2019-03-18 SPL-167534, SPL-166078 HTTP 404 when ToS not accepted and URL has query strings. (daf)
2019-02-28 SPL-167035, SPL-154382 Role Capability To See Indexes for Summary Indexing Gives Role Index Edit Ability
2019-02-08 SPL-166196, SPL-156375 Capability to Schedule Saved Searches restricted after upgrade to 7.x.
2019-02-04 SPL-164998, SPL-163411 LookupAccountName No mapping between account names and security IDs was done
2019-01-17 SPL-164796, SPL-161438 Splunk Enterprise Windows 64 bit installer for 7.1.2 contains data in \etc\system\local\authentication.conf

Search issues

Date resolved Issue number Description
2019-03-27 SPL-158113, SPL-166657, SPL-166967, SPL-166969 Explicit empty strings in lookups being returned as null since 7.1.0, don't show as part of a multivalue field on repeated matches.
2019-03-18 SPL-165500, SPL-163422 srchMaxTime is set to 0 when a role is created through Web
2019-03-18 SPL-158669, SPL-166022, SPL-167324, SPL-167327 scanCount matches eventCount w/transforming command
2019-02-25 SPL-163471, SPL-166636 Search job fails with "Error in 'SearchParser': Missing a search command before '|'. Error at position '140' of search query"
2019-02-14 SPL-166005, SPL-141395 Search Peer Crash - Crashing thread: NonRedistExecutorThread
2019-02-11 SPL-164793 DMA - tstats failing silently on unsupported syntax of nested evals
2019-01-31 SPL-165176 searchOrchestrator crash due to | noop log_debug=*
2019-01-28 SPL-160683, SPL-164645, SPL-164880 Error message on ES App's IR Dashboard when editing notable events due to inconsistent availableCount caused by Timeliner failure to write the events to disk
2019-01-28 SPL-163361, SPL-164567, SPL-164879 mvexpand consumes more memory than expected, error: command.mvexpand: output will be truncated at <low number> results due to excessive memory usage.

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2019-01-28 SPL-164488, SPL-157118 invisible datamodels /data/models/._*.json files are causing the manager to fail finding the datamodel definition

Charting, reporting, and visualization issues

Date resolved Issue number Description
2019-01-15 SPL-154054, SPL-163446, SPL-164721 Dashboard Editor in de-DE locale CSS error in Format visualization modal for Stats Table/Line/Bar Charts

Distributed search and search head clustering issues

Date resolved Issue number Description
2019-02-26 SPL-166329, SPL-159052 SH is not making use of the latest bundle info from the indexer, during the bundle replication.
2019-02-12 SPL-163151, SPL-164425, SPL-164426 2 out of 9 SHC member cannot get bundle push from deployer
2019-01-17 SPL-164731, SPL-164011 SHC: when captain node is in AutomaticDetention status, all alerts (scheduled searches) appear to have stopped as well.

Data model and pivot issues

Date resolved Issue number Description
2019-01-28 SPL-164488, SPL-157118 invisible datamodels /data/models/._*.json files are causing the manager to fail finding the datamodel definition

Indexer and indexer clustering issues

Date resolved Issue number Description
2019-02-12 SPL-166359, SPL-161436 SmartStore buckets with both earliest and latest timestamps 0 can't be replicated, bucket fix-up tasks stuck with "cannot fix up search factor as the bucket is not serviceable" status.

Monitoring Console issues

Date resolved Issue number Description
2019-02-18 SPL-166325, SPL-159030 Error log when performing 'splunk offline' on a peer
2019-01-28 SPL-165338, SPL-160335 No custom checklist item examples in checklist.conf.spec

Splunk Web and interface issues

Date resolved Issue number Description
2019-03-11 SPL-166295, SPL-146810 tools.proxy.on forces SSO
2019-03-03 SPL-166777, SPL-165253 Using "%" in dashboard XML can cause infinite 'Loading...' loop for dashboards with no error reported.

Windows-specific issues

Date resolved Issue number Description
2019-02-14 SPL-166104, SPL-152109 (7.1.x) - Windows security event is getting truncated with multiple blacklists

Admin and CLI issues

Date resolved Issue number Description
2019-02-04 SPL-165767, SPL-145827 Capability rtsearch is enabling for power user after being remove when running CLI cmd and restarting splunk

Uncategorized issues

Date resolved Issue number Description
2019-03-25 SPL-166228, SPL-166798, SPL-167655 Splunk crashes in _mongoc_openssl_ctx_new on shutdown
2019-03-22 SPL-166511, SPL-164979 Search deadlock in StateStoreWorkerScheduler when executing kvstore lookup
2019-03-18 SPL-167014, SPL-143275 Bucket rebuild fails with reason: Failed to process delete journals
2019-03-11 SPL-157867, SPL-160837, SPL-165956 MSI Installation - installer unable to handle complex service password
2019-02-07 SPL-166107, SPL-165008 MaxMind GeoIP DB needs to be updated for Jan 2019
2019-02-04 SPL-160841, SPL-164523, SPL-164531 Received fatal signal 11 (SEGV) on TailWatcher on Heavy Forwarders RegexExtractionProcessor race condition
2019-02-04 SPL-165614, SPL-162969 Splunk upgrade failures due to kv store migration issues
2019-01-30 SPL-164933, SPL-163072 introspection data appears to not be accurate
2019-01-14 SPL-164724, SPL-159813 Post 6.6 / 7.0 upgrade, power user role cannot edit alert.expires from UI
2019-01-14 SPL-164841, SPL-162335 IdataDO_Collector.cpp void collect__summaries(): Assertion `paths.size() == 2' failed.
2019-01-09 SPL-163224, SPL-163907, SPL-164524 Duplicated license error (72 hour grace period) shutting down search before 72 hours has passed.
Last modified on 12 August, 2024
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020   Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.1.7


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters