Fixed issues
Splunk Enterprise 7.1.8 was released on June 17, 2019. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.
Data input issues
Date resolved
|
Issue number
|
Description
|
2019-03-26 |
SPL-162492, SPL-163676, SPL-167747 |
Web UI is counting "Number of (monitored) files" inconsistently
|
Search issues
Date resolved
|
Issue number
|
Description
|
2019-06-12 |
SPL-170344, SPL-169625 |
After upgrade to 7.2.6 unable to send test email with sendemail.py
|
2019-05-21 |
SPL-170372, SPL-160881 |
eventstats on an event search can create duplicate events in some scenarios
|
2019-05-17 |
SPL-170646, SPL-168750 |
Warning produced by Search does not indicate the Search ID causing the warning.
|
2019-05-13 |
SPL-169611, SPL-155648 |
New phased_execution_mode is spawning extra processes for custom search commands
|
2019-05-05 |
SPL-169613, SPL-168826 |
Splunk crashes when auto lookup and default search index are used
|
2019-04-05 |
SPL-168693, SPL-166401 |
sendemail send messages when search does not return any result resulting in empty messages
|
2019-03-29 |
SPL-167580, SPL-156535 |
TcpChannelThread crashed due to race condition when multiple threads updating a ExternalProcessToken object simultaneously
|
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2019-05-30 |
SPL-169214, SPL-165235 |
sc_admin doesn't have the capability to add data
|
2019-05-30 |
SPL-168454, SPL-169945, SPL-170956, SPL-171390 |
now()function in real time alert returns 0 Epoch time
|
2019-05-03 |
SPL-167727, SPL-168447, SPL-168712, SPL-169862 |
Scheduled searches with short dispatch TTL may be skipped forever
|
2019-04-14 |
SPL-168934, SPL-136608 |
Users don't have capability "accelerate_search", can not access accelerated reports
|
2019-03-29 |
SPL-168124, SPL-161055 |
Internal Error: datamodel - invalid or unaccelerable root object
|
2019-03-29 |
SPL-168110, SPL-164733 |
tstats searches do not run on datamodels that contain only a streamable BaseSearch object
|
Charting, reporting, and visualization issues
Date resolved
|
Issue number
|
Description
|
2019-05-28 |
SPL-163158, SPL-169369, SPL-169370, SPL-169371 |
Custom drilldown search string is not encoded causing drilldown search failure
|
2019-04-14 |
SPL-164920, SPL-166952, SPL-167850, SPL-169010, SPL-169011 |
Dashboard issue: Multiselect URL retains single value after Hide Filters selected
|
Data model and pivot issues
Date resolved
|
Issue number
|
Description
|
2019-05-30 |
SPL-169214, SPL-165235 |
sc_admin doesn't have the capability to add data
|
2019-05-30 |
SPL-168454, SPL-169945, SPL-170956, SPL-171390 |
now()function in real time alert returns 0 Epoch time
|
2019-05-03 |
SPL-167727, SPL-168447, SPL-168712, SPL-169862 |
Scheduled searches with short dispatch TTL may be skipped forever
|
2019-04-14 |
SPL-168934, SPL-136608 |
Users don't have capability "accelerate_search", can not access accelerated reports
|
2019-03-29 |
SPL-168124, SPL-161055 |
Internal Error: datamodel - invalid or unaccelerable root object
|
2019-03-29 |
SPL-168110, SPL-164733 |
tstats searches do not run on datamodels that contain only a streamable BaseSearch object
|
Indexer and indexer clustering issues
Date resolved
|
Issue number
|
Description
|
2019-04-23 |
SPL-167731, SPL-166936 |
Indexer Cluster continually tries to roll hot bucket that has already been rolled.
|
2019-04-03 |
SPL-168507, SPL-163391 |
Multi-Site Clustering - Splunk Indexer Discovery Failover is Failing on UFs
|
2019-03-25 |
SPL-168118, SPL-168054 |
Peer flaps from Up to BatchAdding when handleBucketsNotificationBatch is rejected during Master un-initialized
|
Windows-specific issues
Date resolved
|
Issue number
|
Description
|
2019-05-23 |
SPL-169287, SPL-155149 |
Registry changes under SYSTEM\CurrentControlSet are not being read by WinRegMon
|
2019-03-21 |
SPL-158510, SPL-165771, SPL-165772 |
Splunk Perfmon-Collected Events Not Coinciding with WinPerfmon Data
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2019-05-30 |
SPL-162658, SPL-168783, SPL-169607, SPL-170159 |
Editing Summary Indexing not working when Search contains a tstats
|
2019-05-21 |
SPL-168025, SPL-167635 |
Failed to localize because of CacheManager inconsistent bucket state after a truncate
|
2019-05-21 |
SPL-163485, SPL-170059, SPL-170799, SPL-170800 |
Daily License Usage panel for previous 30 days does not sum all license stacks for stack size overlay
|
2019-05-17 |
SPL-167918, SPL-169681, SPL-170615, SPL-170616 |
Expanding event in events viewer has lot of horizontal space in the table
|
2019-05-05 |
SPL-167436, SPL-165730 |
Customer is unable to install Splunk Enterprise 7.1.6 on SLES 11.X & SLES 12.X versions
|
2019-04-23 |
SPL-163357, SPL-168445, SPL-168960 |
After upgrade to 7.1, summarization searches with stats command having group-by fields in non-lex order and dealing with millions of high cardinality events, causes High CPU on the indexer and never complete
|
2019-03-21 |
SPL-166756, SPL-165351 |
Mismatch between source and uploaded bucket metadata creates incorrect shell directory
|
Feedback submitted, thanks!