Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Fixed issues

Splunk Enterprise 7.3.2 was released on October 2, 2019. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Highlighted issues

Splunk Enterprise 7.3.2 fixes the defect in version 7.3.1 (SPL-175599) that affected data durability under certain conditions for customers using SmartStore. Version 7.3.1.1 fixed this issue, and the issue is also fixed in version 7.3.2.

Search issues

Date resolved Issue number Description
2019-08-21 SPL-175234, SPL-170402 Sparkline in 7.2 in fast/smart mode does not work with table command in the search
2019-08-07 SPL-173986, SPL-166826 Stats search may return empty string for the aggregated fields when there is high number of events and cardinalities.
2019-08-07 SPL-172821, SPL-169594 The results of mstats command vary depending on spans
2019-08-06 SPL-172237, SPL-168112 Crashing thread: dispatch- __assert_perror_fail and phase_1-StatsDatum8setValue
2019-07-25 SPL-170469, SPL-169649 User role with search filter that limits searched indexers in "Restrict Search Terms" would still distribute to non-matching splunk_servers
2019-07-22 SPL-172836, SPL-171270 dedup's sortby not working as expected when using head/transaction
2019-07-22 SPL-172676, SPL-169114 LookupDataProvider warning correction in splunkd.log (with ES installed)
2019-07-19 SPL-172639, SPL-172773 trim command throws error and truncates return when concatenating empty field to a number
2019-07-15 SPL-168691, SPL-166401 sendemail send messages when search does not return any result resulting in empty messages
2019-07-15 SPL-171188, SPL-168859 Any transformational commands will not include the base fields when performing search in SMART mode resulting in required field not been included
2019-07-05 SPL-172449, SPL-165608 column order is misaligned in alert email compared to the results showing in Splunk.

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2019-08-22 SPL-174886, SPL-173647 Search dispatched without all peers participating without having a message that not all peers were participating
2019-08-21 SPL-173809, SPL-171073 SHC Stop Executing DMA Searches
2019-08-19 SPL-146181, SPL-136608 Roles without the "accelerate_search" capability can not access accelerated reports.

Charting, reporting, and visualization issues

Date resolved Issue number Description
2019-07-15 SPL-172927, SPL-171800 Color palette expression type is not updating when using token value
2019-07-15 SPL-169371, SPL-163158 Custom drilldown search string is not encoded causing drilldown search failure

Data model and pivot issues

Date resolved Issue number Description
2019-08-21 SPL-173809, SPL-171073 SHC Stop Executing DMA Searches

Indexer and indexer clustering issues

Date resolved Issue number Description
2019-08-22 SPL-174886, SPL-173647 Search dispatched without all peers participating without having a message that not all peers were participating
2019-08-22 SPL-172576, SPL-168132 Clustered indexes aren't fully searchable during an indexer cluster rolling upgrade
2019-08-22 SPL-170937, SPL-167708 Apply cluster bundle does not apply bundle to any indexers which are in progress of adding to cluster
2019-07-31 SPL-172815, SPL-168577 Indexer Discovery breaks when one Indexer stops listening.

Distributed search and search head clustering issues

Date resolved Issue number Description
2019-08-23 SPL-175304, SPL-171401 KVstore out of Sync In Two Out Of Nine SHs
2019-08-21 SPL-173809, SPL-171073 SHC Stop Executing DMA Searches
2019-08-18 SPL-169951, SPL-167421 the scheduled search "Bucket Copy Trigger" (aka Hadoop Data Roll) has stopped working properly.
2019-08-15 SPL-174889, SPL-145260 UI: Jobs Manager page still displaying supposedly deleted job
2019-07-19 SPL-172712, SPL-172804 deployer can not deploy when conf_deploy_repository is set non default value in 7.3.0. "Cannot find preservation mode for non-existent app"
2019-07-08 SPL-170647, SPL-164088 DistributedBundleReplicationManager log still says "Asynchronous bundle replication to peer(s) succeeded" while a bundle replication failed

Universal forwarder issues

Date resolved Issue number Description
2019-07-31 SPL-172815, SPL-168577 Indexer Discovery breaks when one Indexer stops listening.

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2019-08-22 SPL-174532, SPL-170151 Deployment Server does not clean up previous bundles where app and bundle names do not match

Monitoring Console/DMC issues

Date resolved Issue number Description
2019-08-20 SPL-175193, SPL-161159 DMC/MC (UI) - KV Store-> Instance -> 'Average Replication Lag' is removed. The user no longer will be able to see "Average Replication Lag' for each instance.
2019-07-25 SPL-170454, SPL-166121 DMC App, Filter in Apps search is case sensitive
2019-07-15 SPL-167351, SPL-166014 Cloud Admin App will not update HEC tokens once they're created

Splunk Web and interface issues

Date resolved Issue number Description
2019-07-19 SPL-172639, SPL-172773 trim command throws error and truncates return when concatenating empty field to a number
2019-07-05 SPL-172449, SPL-165608 column order is misaligned in alert email compared to the results showing in Splunk.

Windows-specific issues

Date resolved Issue number Description
2019-08-08 SPL-171660, SPL-166645 Splunk is filling the "C:/Windows/Temp" folder with .tmp files

Rest, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2019-08-22 SPL-174913, SPL-173500 REST API /cluster/config endpoint returns default values
2019-08-07 SPL-172691, SPL-169155 Splunkd runs out of file descriptors when post processing with services/search/jobs/{search_id}/results endpoint

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2019-08-21 SPL-175249, SPL-168795 Unable to clear non-actionable messages requesting a splunkd restart from WebUI with sc_admin role
2019-08-20 SPL-175202, SPL-164557 Add capability of skewing time validation for SAML assertions
2019-07-25 SPL-170469, SPL-169649 User role with search filter that limits searched indexers in "Restrict Search Terms" would still distribute to non-matching splunk_servers

Admin and CLI issues

Date resolved Issue number Description
2019-09-12 SPL-173041, SPL-174738 Error when enabling Getting Started app on Windows: Invalid template path.
2019-08-22 SPL-175046, SPL-166620 btool dumps : CountAccounter::CountAccounter(bool): Assertion `main_thread_created' failed (LDAP)
2019-08-15 SPL-174889, SPL-145260 UI: Jobs Manager page still displaying supposedly deleted job
2019-07-24 SPL-172946, SPL-167536 Some blank lines are created when exporting report to csv file by cli command on windows

Unsorted issues

Date resolved Issue number Description
2019-08-23 SPL-175304, SPL-171401 KVstore out of Sync In Two Out Of Nine SHs
2019-08-20 SPL-175193, SPL-161159 DMC/MC (UI) - KV Store-> Instance -> 'Average Replication Lag' is removed. The user no longer will be able to see "Average Replication Lag' for each instance.
2019-08-18 SPL-174529, SPL-167631 ERROR HttpInputDataHandler - Parsing error : Incorrect index
2019-08-13 SPL-172559, SPL-169489 DDAA fails with the error "Failed to download and update receipt file"
2019-07-22 SPL-172676, SPL-169114 LookupDataProvider warning correction in splunkd.log (with ES installed)
2019-07-15 SPL-167351, SPL-166014 Cloud Admin App will not update HEC tokens once they're created

Uncategorized issues

Date resolved Issue number Description
2019-08-22 SPL-173371, SPL-171488 Very Frequent Error "Monotonic time source didn't increase; is it stuck?"
2019-08-21 SPL-172722, SPL-169562 EXTRACT with REGEX capture groups are not extracting fields without specifying FORMAT.
2019-08-08 SPL-170998, SPL-169775 "parsing" thread crashing on bad data when it is in a tar.gz2 format
2019-08-01 SPL-171701, SPL-169847 Configure Splunk to refuse to send 0 size attachments when an alert or report contains no results
2019-07-24 SPL-170856, SPL-170282 S3Client shows statusCode=403 with a wrong access_key when multiple on-prem remote storages are configured
2019-07-22 SPL-172397, SPL-169589 Carriage Returns are added to csv files when users export Windows Eventlog
2019-07-17 SPL-171418, SPL-146805 PDF x-axis labels overlapping on line&column chart
2019-07-15 SPL-170484, SPL-168989 Multiple stale Splunk processes with Systemd managed Splunk service
2019-07-02 SPL-170159, SPL-162658 Editing Summary Indexing not working when Search contains a tstats
PREVIOUS
Field alias behavior change
  NEXT
Deprecated and removed in version 7.3

This documentation applies to the following versions of Splunk® Enterprise: 7.3.2


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters