Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


Splunk Enterprise version 7.3 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 7.3.6 was released on June 4, 2020. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Data input issues

Date resolved Issue number Description
2020-04-06 SPL-185133, SPL-143408 CHARSET=AUTO does not convert

Search issues

Date resolved Issue number Description
2021-01-11 SPL-185211, SPL-185783, SPL-186424 False positive indexed_kv_limit related warning messages can be shown: "The search you ran returned a number of fields that exceeded the current indexed field extraction limit. "
2020-05-08 SPL-182532, SPL-186259, SPL-188691, SPL-188692 Splunk Analytics for Hadoop does not return any search result when using "earliest and latest" clause in 7.3.3 version
2020-05-06 SPL-181381, SPL-168867 Deleted fields such as _confstr (source::|host::|sourcetype) occasionally resurface with a different field name
2020-05-06 SPL-185417, SPL-186114, SPL-186537 Specific Search Crashes After Returning Few Results
2020-05-06 SPL-188632, SPL-184072 Alert PDF Email has timezone mismatch
2020-04-23 SPL-186668, SPL-180741 Clarification of expected behavior with subsearch
2020-04-14 SPL-185916, SPL-184106 User with neither READ nor WRITE permission can still use `outputlookup` to overwrite existing on-disk CSV lookup file
2020-04-13 SPL-183749, SPL-181801 | delete command may generate unnecessary errors when SmartStore cache is under pressure
2020-04-13 SPL-185795, SPL-185555 Realtime search breaks when customizing server.conf
2020-04-03 SPL-185691, SPL-185078 update MaxMind GeoLite2-City DB to latest version 20200317
2020-03-30 SPL-185393, SPL-184348 Splunk returns no results after adding field extractions without capturing group in REGEX when using FORMAT field::value.
2020-03-09 SPL-180864, SPL-162429, SPL-182397 Reporting Custom command with version 2 failed to stream/fetch results.
2020-03-05 SPL-184225, SPL-181448 mstats - The same search query with mstats produces different results each time it is run

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2020-05-06 SPL-188632, SPL-184072 Alert PDF Email has timezone mismatch
2020-04-17 SPL-185856, SPL-184327 Accelerated Report summaries not being used
2020-04-14 SPL-181035, SPL-185883, SPL-186235 alert.expires can't be used to set default alert expiry for new alerts
2020-04-07 SPL-185213, SPL-178252 DMA consuming much more RAM after upgrade to 7.X

Charting, reporting, and visualization issues

Date resolved Issue number Description
2020-04-23 SPL-186015, SPL-185606 Custom VIZ data chunking, one chunk of previous search is sent when previous search is interupted
2020-04-14 SPL-186302, SPL-182027 Drilldown token filters are not working
2020-04-02 SPL-185580, SPL-185142 Can Not Open In Search From Dashboard Panel
2020-03-26 SPL-177890, SPL-179769, SPL-179770 Pagination Issue in dashboard
2020-03-13 SPL-181931, SPL-182611, SPL-183301 Drilldown is not working if search string contains & or ?

Data model and pivot issues

Date resolved Issue number Description
2020-04-07 SPL-185213, SPL-178252 DMA consuming much more RAM after upgrade to 7.X

Indexer and indexer clustering issues

Date resolved Issue number Description
2020-04-28 SPL-184899, SPL-185653, SPL-186340 Data rebalance performance issues in a large indexer cluster
2020-04-16 SPL-185516, SPL-185189 SmartStore: Indexer peers marked "Down" when connection to remote objectstore is unstable
2020-04-03 SPL-184958, SPL-183290 Using REST or CLI to validate and apply bundle causes peers to restart twice
2020-03-13 SPL-183952, SPL-181945 Rebalancing isn't completing due to missing cold buckets

Distributed search and search head clustering issues

Date resolved Issue number Description
2020-08-29 SPL-174495, SPL-174883, SPL-180980 One of SHC members has been stuck at 'Restarting' during rolling restart for bundle push from deployer.
2020-05-13 SPL-188938, SPL-185709 Getting incorrect no.of instances in the Kvstore Average latency graph in ES SHC
2020-05-13 SPL-182150, SPL-186503, SPL-188709 Authentication.conf replicating empty stanza header multiple times per minute
2020-04-24 SPL-184281, SPL-185103, SPL-185654 Explanation for user-prefs replication and option to disable these.
2020-04-22 SPL-186585, SPL-175689 Enhancing error message for SH heartbeat lost
2020-04-13 SPL-181067, SPL-177889 Events found but not displayed, eventstats some events been ignored occasionally
2020-03-06 SPL-184165, SPL-173029 KV store backup/restore - large collection hangs at "Busy" status when trying to restore from a backup

Universal forwarder issues

Date resolved Issue number Description
2020-05-07 SPL-188620, SPL-184263 UFs stop forwarding after some time due to deadlock between HealthReporter threads
2020-03-30 SPL-183953, SPL-184897, SPL-185540, SPL-185541 Batch Stanza deleting file upon restart/read completion

Splunk Web and interface issues

Date resolved Issue number Description
2020-04-14 SPL-181035, SPL-185883, SPL-186235 alert.expires can't be used to set default alert expiry for new alerts
2020-03-13 SPL-179445, SPL-183710, SPL-184707 custom.xml in default/data/ui/nav breaks navigation bar in other apps

REST, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2020-04-03 SPL-184958, SPL-183290 Using REST or CLI to validate and apply bundle causes peers to restart twice

Authentication and authorization issues

Date resolved Issue number Description
2020-04-10 SPL-185715, SPL-183142 Session token generated in JWT/Bearer token-based call cannot be used to auth rest calls

PDF issues

Date resolved Issue number Description
2020-03-31 SPL-184181, SPL-182193 PDF - timecharts are being cut when sent as PDF

Admin and CLI issues

Date resolved Issue number Description
2020-03-17 SPL-179501, SPL-184329, SPL-181871, SPL-184331 Some page at "Settings > All Configurations" throws 404 ERROR
2020-03-02 SPL-181290, SPL-181951, SPL-181574, SPL-181948, SPL-181950 Splunk does not set realtime_schedule to 0 after enabling summary indexing for a scheduled report

Uncategorized issues

Date resolved Issue number Description
2020-04-20 SPL-186349, SPL-186282 DMA rebuild is causing random indexer crashes
2020-04-08 SPL-185418, SPL-181222 SummaryDirector for Authentication DMA has incorrect search
2020-04-02 SPL-170326, SPL-185140, SPL-184111, SPL-185141 HTTP Event Collector sporadically fails to index JSON extractions when "Tried to set INDEXED_EXTRACTIONS but it already had a value!" error occurs.
2020-04-01 SPL-183002, SPL-183000 diag cannot get index listings for UNC paths
2020-04-01 SPL-183329, SPL-181223 When enabling CORS support HTTP headers are rejected
2020-03-18 SPL-183477, SPL-184039, SPL-184962 MC: Health Check page stuck in "Loading..." when Forwarder license is used
Last modified on 12 January, 2021
PREVIOUS
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
  NEXT
Deprecated and removed in version 7.3

This documentation applies to the following versions of Splunk® Enterprise: 7.3.6


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters