Splunk® Enterprise

Release Notes

Splunk Enterprise version 7.2 is no longer supported as of April 30, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 7.2.5.1

Splunk Enterprise 7.2.5.1 was released on March 28, 2019. Version 7.2.5 introduced a defect (SPL-167959) that causes crashes in deployments that have invalid FIELDALIAS definitions in props.conf. Version 7.2.5.1 prevents these crashes from occurring.

Splunk Enterprise 7.2.5

Splunk Enterprise 7.2.5 was released on March 18, 2019. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Search issues

Date resolved Issue number Description
2019-02-27 SPL-164894, SPL-163932 disabling case_sensitive_match in transforms.conf not working as documented for lookups
2019-02-27 SPL-165046, SPL-165326 Search crashes due to missing name in EVAL- in props.conf
2019-02-27 SPL-166967, SPL-158113, SPL-166657 Explicit empty strings in lookups being returned as null since 7.1.0, don't show as part of a multivalue field on repeated matches.
2019-02-11 SPL-163422, SPL-164424, SPL-165500 srchMaxTime is set to 0 when a role is created through Web
2019-02-08 SPL-166004, SPL-141395 Search Peer Crash - Crashing thread: NonRedistExecutorThread
2019-01-28 SPL-164879, SPL-163361 mvexpand on 7.1+ consumes more memory than expected
2019-01-28 SPL-164880, SPL-160683 Error message on ES App's IR Dashboard when editing notable events due to inconsistent availableCount caused by Timeliner failure to write the events to disk

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2019-04-02 SPL-166658, SPL-161055 Accelerated Datamodel: "Invalid or unaccelerable root object for datamodel", even though that's expected for DMs that have both BaseEvent and BaseSearch objects.

Charting, reporting, and visualization issues

Date resolved Issue number Description
2019-03-05 SPL-161165, SPL-167176 Customer can't double or triple-click XML since 7.2.0

Data model and pivot issues

Date resolved Issue number Description
2019-04-02 SPL-166658, SPL-161055 Accelerated Datamodel: "Invalid or unaccelerable root object for datamodel", even though that's expected for DMs that have both BaseEvent and BaseSearch objects.

Indexer and indexer clustering issues

Date resolved Issue number Description
2019-02-12 SPL-166360, SPL-161436 SmartStore buckets with both earliest and latest timestamps 0 can't be replicated, bucket fix-up tasks stuck with "cannot fix up search factor as the bucket is not serviceable" status.

Distributed search and search head clustering issues

Date resolved Issue number Description
2019-02-14 SPL-164426, SPL-163151 2 out of 9 SHC member cannot get bundle push from deployer

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2019-02-19 SPL-165827, SPL-166188 Setting DC phoneHomeIntervalInSecs under stanza is ineffective

Monitoring Console/DMC issues

Date resolved Issue number Description
2019-01-25 SPL-165397, SPL-160335 No custom checklist item examples in checklist.conf.spec

Splunk Web and interface issues

Date resolved Issue number Description
2019-03-04 SPL-166292, SPL-146810 tools.proxy.on forces SSO
2019-02-26 SPL-166776, SPL-165253 Using "%" in dashboard XML can cause infinite 'Loading...' loop for dashboards with no error reported.

Windows-specific issues

Date resolved Issue number Description
2019-02-22 SPL-166108, SPL-152109 (7.2.x) Windows Events getting truncated or missing.

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2019-02-28 SPL-167036, SPL-154382 Role Capability To See Indexes for Summary Indexing Gives Role Index Edit Ability
2019-02-08 SPL-156375, SPL-164872, SPL-166196, SPL-166197 Capability to Schedule Saved Searches restricted after upgrade to 7.x.

Admin and CLI issues

Date resolved Issue number Description
2019-03-01 SPL-164505, SPL-162655 In Splunk 7.2.x, Field Aliasing removes the alias field if the original field does not exist
2019-02-04 SPL-165766, SPL-145827 Capability rtsearch is enabling for power user after being remove when running CLI cmd and restarting splunk

Unsorted issues

Date resolved Issue number Description
2019-03-07 SPL-167347, SPL-165968 Frequent searches with outputlookup may trigger highly increased KV Store storage usage or in some cases crash of the mongod process
2019-02-28 SPL-165956, SPL-157867 MSI Installation - installer unable to handle complex service password
2019-02-27 SPL-166510, SPL-164979 Search deadlock in StateStoreWorkerScheduler when executing kvstore lookup
2019-01-30 SPL-164931, SPL-163072 Introspection data appears to not be accurate

Uncategorized issues

Date resolved Issue number Description
2019-02-27 SPL-166757, SPL-165351 Mismatch between source and uploaded bucket metadata creates incorrect shell directory
2019-01-28 SPL-165244, SPL-158821 Indexes showing events from 2000-2039 - impacting multiple customers
2019-01-28 SPL-162250, SPL-162849, SPL-165234 Error Configuring Indexed Extracions: Invalid value='/s' for parameter='FIELD_DELIMITER'
Last modified on 14 April, 2020
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020   Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.2.5


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters