Splunk® Enterprise

Release Notes

Splunk Enterprise version 7.3 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 7.3.5.2

Splunk Enterprise 7.3.5.2 was released on May 26, 2020. This release fixes the following issue that affects only 64-bit Windows versions of Splunk Enterprise:

Date resolved Issue number Description
2020-05-20 SPL-189124 KV store does not start after upgrade to Splunk Enterprise 7.3.5 on Windows 64-bit.

Splunk Enterprise 7.3.5

Splunk Enterprise 7.3.5 was released on March 25, 2020. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Authentication and authorization issues

Date resolved Issue number Description
2020-02-19 SPL-183231, SPL-178521 idpCert.pem certificate gets malformed using Metadata XML File
2020-02-13 SPL-178515, SPL-179823, SPL-182060, SPL-182067, SPL-183204, SPL-183205 Unable to view SAML settings when idpCerts is deleted

Data input issues

Date resolved Issue number Description
2020-02-13 SPL-182046, SPL-170497 Updating HEC turns on useACK (breaks input)

Search issues

Date resolved Issue number Description
2020-03-03 SPL-183532, SPL-183945, SPL-184234, SPL-184236, SPL-184237 Search head performance degraded after upgrade from 8.0.2- to 8.0.2 and 7.3.4- to 7.3.4
2020-03-02 SPL-177695 Eventtyper not matching when field is MV
2020-02-14 SPL-182843, SPL-181525 Issue with maps viz, geostats in combination with |append or |inputlookup append=t, some pie chart not showing on map
2020-02-13 SPL-180066, SPL-169835 ad-hoc search artifact uses up 22GB of disk space with thousands of "tmpevents_*.csv.gz" and "mmsort_pass1_*.csv.gz" temporary files
2020-02-13 SPL-181367, SPL-180038 Search performance decreases (long running searches) with high index deployments (2K indexes)
2020-02-13 SPL-181499, SPL-181551 Suppress warning message when update=true used in real-time search
2020-02-13 SPL-181700, SPL-180256 fields extracted with modular regex show incomplete required fields list in smartmode for transforming or non-streaming commands , producing no results found
2020-02-13 SPL-181331, SPL-181303 Rex mode sed - 7.1.0+ - Sed with caret (^) is giving an incorrect result/not functioning as expected
2020-02-13 SPL-181153, SPL-177255 Searching for lookup default_match value includes default_match value in lispy

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2020-02-19 SPL-183262, SPL-162249 The filter function of <splunk-search-dropdown> UI component is not working on on Splunk Enterprise 7.3
2020-01-31 SPL-180352, SPL-169912 SHC - Alert Scheduler - Next Scheduled Time does not update if cron-scheduler is updated from Deployer

Charting, reporting, and visualization issues

Date resolved Issue number Description
2020-02-20 SPL-175517, SPL-176861, SPL-178455 fieldformat value in dashboard shows as epoch time until it sorted
2020-02-18 SPL-183078, SPL-181033 _time is shown as GMT on Visualization when Time zone is set to default on Windows
2020-02-14 SPL-182843, SPL-181525 Issue with maps viz, geostats in combination with |append or |inputlookup append=t, some pie chart not showing on map
2020-02-13 SPL-181932, SPL-181372 Bootstrap modal is not working in dashboard
2020-02-06 SPL-182114, SPL-179348 autoLB not switching IDX when reaching frequency limit

Indexer and indexer clustering issues

Date resolved Issue number Description
2020-02-27 SPL-182286, SPL-182635, SPL-183851, SPL-184461 Intermittent crashes due to corrupted buckets slowing down fixup tasks - Follow up of SPL-182014
2020-02-19 SPL-182131, SPL-182014 60 Indexers in a cluster are crashing sporadically -Crashing thread: cachemanagerDownloadExecutorWorker-10
2020-02-13 SPL-180283, SPL-178632 Fixup stuck after reprovisioning an indexer in SmartStore enabled cluster.
2020-02-13 SPL-182234, SPL-180406 Cluster Master UI states search and replication factors SF/RF are not met, but there are no fixup tasks listed
2020-02-06 SPL-182086, SPL-182016 Cluster Peer rolling restart can cause unnecessary extra re-adds
2020-02-03 SPL-181618, SPL-180200 Some cluster peers did not try to restart when new bundle was applied

Distributed search and search head clustering issues

Date resolved Issue number Description
2020-03-04 SPL-178007, SPL-175784 Application does not exist error for bundle application with full mode when deploy app contains an empty default folder
2020-03-03 SPL-183476, SPL-181508 Negative values returned by one SH in Average KVstore Latency graph in MC
2020-03-03 SPL-178005, SPL-175964 README folders for some apps get deleted on captain during push from deployer to SHC
2020-03-02 SPL-178009, SPL-174856 Out-of-sync issues can occur when using full or local_only push modes to push configurations from the deployer to the search head cluster
2020-02-14 SPL-179683, SPL-177024 SearchOrchestation framework should not run subsearches multiple times.
2020-02-13 SPL-181031, SPL-181151, SPL-181498 | metasearch + BatchMode order of magnitude slower than 7.2
2020-02-10 SPL-181703, SPL-181953, SPL-181954 Alert suppression removal during captaincy changes may cause SHC instability.

Universal forwarder issues

Date resolved Issue number Description
2020-02-26 SPL-157269, SPL-160984, SPL-184043 High CPU usage originating from Splunk UF on macOS devices

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2020-03-03 SPL-178005, SPL-175964 README folders for some apps get deleted on captain during push from deployer to SHC

Splunk Web and interface issues

Date resolved Issue number Description
2020-02-19 SPL-183231, SPL-178521 idpCert.pem certificate gets malformed using Metadata XML File
2020-02-19 SPL-183262, SPL-162249 The filter function of <splunk-search-dropdown> UI component is not working on on Splunk Enterprise 7.3
2020-02-18 SPL-183078, SPL-181033 _time is shown as GMT on Visualization when Time zone is set to default on Windows
2020-02-13 SPL-181424, SPL-166093 Dom Purify error observed in UCC 3 based addons.
2020-02-13 SPL-178515, SPL-179823, SPL-182060, SPL-182067, SPL-183204, SPL-183205 Unable to view SAML settings when idpCerts is deleted
2020-02-07 SPL-182139, SPL-182472, SPL-182773, SPL-182774 Degradation in Web UI performance with large number of Knowledge Objects and Users
2020-02-06 SPL-182641, SPL-181165 Splunkweb does not start as per repro but we fail to report it failed to start.

REST, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2020-02-07 SPL-182139, SPL-182472, SPL-182773, SPL-182774 Degradation in Web UI performance with large number of Knowledge Objects and Users

Uncategorized issues

Date resolved Issue number Description
2020-02-20 SPL-183179, SPL-179817 scheduled view object not deleted when source dashboard deleted in cloud v7.2.6
2020-02-18 SPL-183088, SPL-132957 Report created by user name with space in can not be accelerated
2020-02-18 SPL-178172, SPL-180649, SPL-181717 Disabling replication of kvstore collection for automatic lookup causes "Could not load lookup=..." errors to appear
2020-02-14 SPL-180575, SPL-181506, SPL-183342 Splunk streaming cli RealTime searches consume high memory and don't stream results until Job finalizes
2020-02-13 SPL-179441, SPL-172622 Cluster map visualization is not accurate after upgrade to 7.2.x
2020-02-13 SPL-180810, SPL-143274 search optimizer incorrectly removes _time projections which precede transaction commands
2020-02-13 SPL-179444, SPL-165762 Invalid latest_time: latest_time must be after earliest_time when DST is reached
2020-02-07 SPL-172272, SPL-182872, SPL-182939, SPL-182940 Language localization needs to apply for placeholder 'Username' and 'Password' text on login page
Last modified on 05 December, 2022
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020   Deprecated and removed in version 7.3

This documentation applies to the following versions of Splunk® Enterprise: 7.3.5


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters