Fixed issues
Splunk Enterprise 7.1.9 was released on October 7, 2019. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.
Data input issues
Date resolved
|
Issue number
|
Description
|
2019-06-18 |
SPL-169707, SPL-169706 |
Splunk Enterprise for Windows missing python six (possibly others)
|
Search issues
Date resolved
|
Issue number
|
Description
|
2019-09-13 |
SPL-173458, SPL-173777, SPL-174871, SPL-174872 |
Crash from multisearch command causing splunkd to crash.
|
2019-07-05 |
SPL-164164, SPL-165401, SPL-172754 |
Missing Lookup does not cause Failure in Scheduled Searches
|
2019-07-05 |
SPL-172453, SPL-165608 |
column order is misaligned in alert email compared to the results showing in Splunk.
|
2019-06-04 |
SPL-130503, SPL-168864, SPL-170977, SPL-170978 |
CEXC: Field order not preserved in generating reporting custom commands
|
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2019-09-06 |
SPL-170981, SPL-172822, SPL-175483, SPL-175484 |
Running jobs should not be marked as expired
|
2019-08-25 |
SPL-173807, SPL-171073 |
SHC Stop Executing DMA Searches
|
2019-08-25 |
SPL-174884, SPL-173647 |
Search dispatched without all peers participating without having a message that not all peers were participating
|
2019-07-05 |
SPL-164164, SPL-165401, SPL-172754 |
Missing Lookup does not cause Failure in Scheduled Searches
|
Data model and pivot issues
Date resolved
|
Issue number
|
Description
|
2019-08-25 |
SPL-173807, SPL-171073 |
SHC Stop Executing DMA Searches
|
Indexer and indexer clustering issues
Date resolved
|
Issue number
|
Description
|
2019-09-10 |
SPL-170943, SPL-167708 |
Apply cluster bundle does not apply bundle to any indexers which are in progress of adding to cluster
|
2019-08-25 |
SPL-174884, SPL-173647 |
Search dispatched without all peers participating without having a message that not all peers were participating
|
Distributed search and search head clustering issues
Date resolved
|
Issue number
|
Description
|
2019-09-10 |
SPL-173618, SPL-175396, SPL-175397, SPL-174681 |
Servers with Custom groups in DMC are not saved to distsearch.conf
|
2019-08-25 |
SPL-173807, SPL-171073 |
SHC Stop Executing DMA Searches
|
2019-08-25 |
SPL-171401, SPL-175305, SPL-173077, SPL-175304 |
KVstore out of Sync In Two Out Of Nine SHs
|
2019-06-28 |
SPL-171367, SPL-169046 |
in SHC, several copies of the same scheduled index-time realtime search are running on distinct SHC instances - impacting ITSI itsi_event_grouping
|
Monitoring Console/DMC issues
Date resolved
|
Issue number
|
Description
|
2019-09-10 |
SPL-173618, SPL-175396, SPL-175397, SPL-174681 |
Servers with Custom groups in DMC are not saved to distsearch.conf
|
2019-07-05 |
SPL-166121, SPL-168248, SPL-170453, SPL-170454 |
DMC App, Filter in Apps search is case sensitive
|
Splunk Web and interface issues
Date resolved
|
Issue number
|
Description
|
2019-07-05 |
SPL-172453, SPL-165608 |
column order is misaligned in alert email compared to the results showing in Splunk.
|
Windows-specific issues
Date resolved
|
Issue number
|
Description
|
2019-08-01 |
SPL-171658, SPL-166645 |
Splunk is filling the "C:/Windows/Temp" folder with .tmp files
|
Authentication and Authorization issues
For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.
Date resolved
|
Issue number
|
Description
|
2019-09-12 |
SPL-175247, SPL-168795 |
Unable to clear non-actionable messages requesting a splunkd restart from WebUI with sc_admin role
|
Unsorted issues
Date resolved
|
Issue number
|
Description
|
2019-09-12 |
SPL-175126, SPL-168112 |
Search Head on Search Head Cluster on Windows platform crash in thread: TcpChannelThread.
|
2019-08-25 |
SPL-171401, SPL-175305, SPL-173077, SPL-175304 |
KVstore out of Sync In Two Out Of Nine SHs
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2019-09-13 |
SPL-172641, SPL-174492, SPL-174494, SPL-174491 |
regex_cpu_profiling not generating events on WIndows instance
|
2019-09-06 |
SPL-171220, SPL-174138, SPL-175767, SPL-175768 |
Frequent restarting of real-time searches and bundle replication can cause memory growth in splunkd mothership
|
2019-09-02 |
SPL-162758, SPL-167453 |
Replicated bucket in indexer cluster is timestamped with earliest time 0 (January 1970) if its last slice is empty.
|
2019-08-26 |
SPL-174634, SPL-175272, SPL-175273, SPL-175167 |
$message$ token is not working for <fail> search event handler
|
2019-07-08 |
SPL-167490, SPL-162985 |
When using Time Picker set to Date&Latest, $timepicker.latest$ fails to populate when set to now
|
2019-07-05 |
SPL-171699, SPL-169847 |
Configure Splunk to refuse to send 0 size attachments when an alert or report contains no results
|
Feedback submitted, thanks!