Splunk® Enterprise

Release Notes

Splunk Enterprise version 7.1 is no longer supported as of October 31, 2020. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 7.1.8 was released on June 17, 2019. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Data input issues

Date resolved Issue number Description
2019-03-26 SPL-162492, SPL-163676, SPL-167747 Web UI is counting "Number of (monitored) files" inconsistently

Search issues

Date resolved Issue number Description
2019-06-12 SPL-170344, SPL-169625 After upgrade to 7.2.6 unable to send test email with sendemail.py
2019-05-21 SPL-170372, SPL-160881 eventstats on an event search can create duplicate events in some scenarios
2019-05-17 SPL-170646, SPL-168750 Warning produced by Search does not indicate the Search ID causing the warning.
2019-05-13 SPL-169611, SPL-155648 New phased_execution_mode is spawning extra processes for custom search commands
2019-05-05 SPL-169613, SPL-168826 Splunk crashes when auto lookup and default search index are used
2019-04-05 SPL-168693, SPL-166401 sendemail send messages when search does not return any result resulting in empty messages
2019-03-29 SPL-167580, SPL-156535 TcpChannelThread crashed due to race condition when multiple threads updating a ExternalProcessToken object simultaneously

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2019-05-30 SPL-169214, SPL-165235 sc_admin doesn't have the capability to add data
2019-05-30 SPL-168454, SPL-169945, SPL-170956, SPL-171390 now()function in real time alert returns 0 Epoch time
2019-05-03 SPL-167727, SPL-168447, SPL-168712, SPL-169862 Scheduled searches with short dispatch TTL may be skipped forever
2019-04-14 SPL-168934, SPL-136608 Users don't have capability "accelerate_search", can not access accelerated reports
2019-03-29 SPL-168124, SPL-161055 Internal Error: datamodel - invalid or unaccelerable root object
2019-03-29 SPL-168110, SPL-164733 tstats searches do not run on datamodels that contain only a streamable BaseSearch object

Charting, reporting, and visualization issues

Date resolved Issue number Description
2019-05-28 SPL-163158, SPL-169369, SPL-169370, SPL-169371 Custom drilldown search string is not encoded causing drilldown search failure
2019-04-14 SPL-164920, SPL-166952, SPL-167850, SPL-169010, SPL-169011 Dashboard issue: Multiselect URL retains single value after Hide Filters selected

Data model and pivot issues

Date resolved Issue number Description
2019-05-30 SPL-169214, SPL-165235 sc_admin doesn't have the capability to add data
2019-05-30 SPL-168454, SPL-169945, SPL-170956, SPL-171390 now()function in real time alert returns 0 Epoch time
2019-05-03 SPL-167727, SPL-168447, SPL-168712, SPL-169862 Scheduled searches with short dispatch TTL may be skipped forever
2019-04-14 SPL-168934, SPL-136608 Users don't have capability "accelerate_search", can not access accelerated reports
2019-03-29 SPL-168124, SPL-161055 Internal Error: datamodel - invalid or unaccelerable root object
2019-03-29 SPL-168110, SPL-164733 tstats searches do not run on datamodels that contain only a streamable BaseSearch object

Indexer and indexer clustering issues

Date resolved Issue number Description
2019-04-23 SPL-167731, SPL-166936 Indexer Cluster continually tries to roll hot bucket that has already been rolled.
2019-04-03 SPL-168507, SPL-163391 Multi-Site Clustering - Splunk Indexer Discovery Failover is Failing on UFs
2019-03-25 SPL-168118, SPL-168054 Peer flaps from Up to BatchAdding when handleBucketsNotificationBatch is rejected during Master un-initialized

Windows-specific issues

Date resolved Issue number Description
2019-05-23 SPL-169287, SPL-155149 Registry changes under SYSTEM\CurrentControlSet are not being read by WinRegMon
2019-03-21 SPL-158510, SPL-165771, SPL-165772 Splunk Perfmon-Collected Events Not Coinciding with WinPerfmon Data

Uncategorized issues

Date resolved Issue number Description
2019-05-30 SPL-162658, SPL-168783, SPL-169607, SPL-170159 Editing Summary Indexing not working when Search contains a tstats
2019-05-21 SPL-168025, SPL-167635 Failed to localize because of CacheManager inconsistent bucket state after a truncate
2019-05-21 SPL-163485, SPL-170059, SPL-170799, SPL-170800 Daily License Usage panel for previous 30 days does not sum all license stacks for stack size overlay
2019-05-17 SPL-167918, SPL-169681, SPL-170615, SPL-170616 Expanding event in events viewer has lot of horizontal space in the table
2019-05-05 SPL-167436, SPL-165730 Customer is unable to install Splunk Enterprise 7.1.6 on SLES 11.X & SLES 12.X versions
2019-04-23 SPL-163357, SPL-168445, SPL-168960 After upgrade to 7.1, summarization searches with stats command having group-by fields in non-lex order and dealing with millions of high cardinality events, causes High CPU on the indexer and never complete
2019-03-21 SPL-166756, SPL-165351 Mismatch between source and uploaded bucket metadata creates incorrect shell directory
Last modified on 14 April, 2020
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020   Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.1.8


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters