Welcome to Splunk Enterprise 7.3
If you are new to Splunk Enterprise, read the Splunk Enterprise Overview. If you are familiar with Splunk Enterprise and want to explore the new features interactively, download the Splunk Enterprise Overview app from Splunkbase.
For system requirements information, see the Installation Manual.
Before proceeding, review the Known Issues for this release.
Splunk Enterprise 7.3 was first released on June 4, 2019.
Planning to upgrade from an earlier version?
If you plan to upgrade to this version from an earlier version of Splunk Enterprise, read How to upgrade Splunk Enterprise in the Installation Manual for information you need to know before you upgrade.
See About upgrading: READ THIS FIRST for specific migration tips and information that might affect you when you upgrade.
The Deprecated features topic lists computing platforms, browsers, and features for which Splunk has deprecated or removed support in this release.
What's New in 7.3
|New Feature or Enhancement||Description|
|SmartStore enhancements|| Support for Splunk Enterprise Security workloads.
Data retention based on raw uncompressed data size per index, supplementing existing controls based on time and compressed data size. See Configure data retention for SmartStore indexes in Managing Indexers and Clusters of Indexers.
Improved SmartStore resiliency.
Improved scalability of SmartStore and indexer clustering.
Support for SmartStore on non-clustered standalone indexers. See About SmartStore in Managing Indexers and Clusters of Indexers.
|Indexing pipeline improvements||Balanced index load distribution: Efficient resource utilization by automatically distributing indexing load within an indexer across multiple pipeline sets, achieving higher indexing throughput, improved resource utilization, and reduced cost. See Manage pipeline sets for index parallelization in Managing Indexers and Clusters of Indexers.|
|Searchable data rebalance||Minimal disruption to searching during indexer cluster data rebalance. See Rebalance the indexer cluster in Managing Indexers and Clusters of Indexers.|
|Workload management|| Shared memory resources between search workload pools.
Explicit resource caps on modular inputs and scripted inputs, to limit excessive resource usage.
Enhanced workload rules to control resource usage based on indexes and users, in addition to apps and roles. See Configure workload management in the Workload Management manual.
Improved monitoring of resource consumption on a per pool basis. See Monitor workload management in the Workload Management manual.
Ability to set distinct workload pools for data model acceleration and report acceleration searches. See Assign searches to workload pools in the Workload Management manual.
|Splunk Metrics Workspace||Splunk Metrics Workspace is now part of Splunk Enterprise inside the Search & Reporting app. See Visualize metrics in the Splunk Metrics Workspace.|
|Metrics rollups||Keep aggregated metrics data over longer periods of time in metrics rollup summaries for storage savings and better search performance. See Roll up metrics data for faster search performance and increased storage capacity in Metrics.|
|Chart multiple series||Co-analyze multiple related metrics easily in the same view and create sophisticated visualizations for monitoring.|
|Metrics index storage optimization||Reduced storage footprint and increased search performance.|
|Token-based authentication||Ability to authenticate in REST API calls using a token instead of username and password for LDAP and local login users. See Set up authentication with tokens in Securing Splunk Enterprise.|
|Improved roles management||New user interface for selecting Searchable Indexes, Default indexes, Capabilities, and Inheritance on the Roles configuration page. See Add and edit roles with Splunk Web in Securing Splunk Enterprise.|
|Deployer enhancements||Flexible deployer options for search head clustering to assist with application and configuration upgrades as well as single search head to SHC migration. See Use the deployer to distribute apps and configuration updates in the Distributed Search manual.|
|SearchEvaluator performance and memory usage improvements||Reduced memory footprint of searches and increased performance.|
|Search performance enhancements||Faster search execution with lower memory usage, especially for complex queries spanning large numbers of indexers.|
|Enhancement in sub-second event data retention|| Ability to retain sub-second event data without indexing additional fields. See the |
Splunk Enterprise 7.3.0 introduces additional guided data onboarding manuals that provide end-to-end guidance for getting specific data sources into specific Splunk platform deployments. You can find all the guided data onboarding manuals by clicking the Add data tab on the Splunk Enterprise documentation page.
REST API updates
This release includes these new and updated REST API endpoints.
The REST API Reference Manual describes the endpoints.
This documentation applies to the following versions of Splunk® Enterprise: 7.3.0