Splunk® Enterprise

Release Notes

Splunk Enterprise version 7.2 is no longer supported as of April 30, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 7.2.7

Splunk Enterprise 7.2.7 was released on June 19, 2019. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Search issues

Date resolved Issue number Description
2019-05-16 SPL-170371, SPL-160881 eventstats on an event search can create duplicate events in some scenarios
2019-05-14 SPL-169625, SPL-170344, SPL-169918, SPL-170338, SPL-170343 After upgrade to 7.2.6 unable to send test email with sendemail.py
2019-05-09 SPL-169612, SPL-155648 New phased_execution_mode is spawning extra processes for custom search commands
2019-05-05 SPL-168826, SPL-169613, SPL-169614, SPL-169071, SPL-169615 Splunk crashes when auto lookup and default search index are used

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2019-05-08 SPL-169215, SPL-165235 sc_admin doesn't have the capability to add data
2019-05-02 SPL-168712, SPL-167727 Scheduled searches with short dispatch TTL may be skipped forever

Charting, reporting, and visualization issues

Date resolved Issue number Description
2019-05-15 SPL-165825, SPL-166949, SPL-169238 table(spl) column orders not honoured/incorrect in custom dashboard when totalsRow set to True
2019-04-18 SPL-166770, SPL-168636, SPL-168637 URI malformed error in dashboard if search string contains %
2019-04-14 SPL-169010, SPL-164920 Dashboard issue: Multiselect URL retains single value after Hide Filters selected

Monitoring Console/DMC issues

Date resolved Issue number Description
2019-05-15 SPL-169126, SPL-166014 DMC App will not update HEC tokens once they're created
2019-04-23 SPL-167313, SPL-167530 A few drill-downs in monitoring console need fixing (due to incorrect regex)

Windows-specific issues

Date resolved Issue number Description
2019-05-14 SPL-169288, SPL-155149 Registry changes under SYSTEM\CurrentControlSet are not being read by WinRegMon

Uncategorized issues

Date resolved Issue number Description
2019-05-14 SPL-168989, SPL-169901, SPL-170484 Multiple stale Splunk processes with Systemd managed Splunk service
2019-05-05 SPL-167437, SPL-165730 Customer is unable to install Splunk Enterprise 7.2.4 on SLES 11.X & SLES 12.X versions
2019-05-01 SPL-167976, SPL-168686, SPL-169471 splunk validate files improve the Error handling for the open call "reason="unknown cause for open() failing"
2019-04-23 SPL-168649, SPL-167902 KV Store migration during Splunk rolling upgrade from version 7.0.X or older to 7.2.X may fail in some cases
2019-04-14 SPL-168960, SPL-163357 After upgrade to 7.1, summarization searches with stats command having group-by fields in non-lex order and dealing with millions of high cardinality events, causes High CPU on the indexer and never complete
Last modified on 14 April, 2020
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020   Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.2.7


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters