Splunk® Enterprise

Release Notes

Splunk Enterprise version 7.3 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Welcome to Splunk Enterprise 7.3

If you are new to Splunk Enterprise, read the Splunk Enterprise Overview. If you are familiar with Splunk Enterprise and want to explore the new features interactively, download the Splunk Essentials for Cloud and Enterprise app from Splunkbase.

For system requirements information, see the Installation Manual.

Before proceeding, review Known Issues for this release and Fixed issues.

Splunk Enterprise 7.3 was first released on June 4, 2019.

Planning to upgrade from an earlier version?

If you plan to upgrade to this version from an earlier version of Splunk Enterprise, read How to upgrade Splunk Enterprise in the Installation Manual for information you need to know before you upgrade.

See About upgrading: READ THIS FIRST for specific migration tips and information that might affect you when you upgrade.

The Deprecated features topic lists computing platforms, browsers, and features for which Splunk has deprecated or removed support in this release.

What's New in 7.3.0

New Feature or Enhancement Description
SmartStore enhancements Support for Splunk Enterprise Security workloads.


Support for report acceleration and data model acceleration summaries. See About SmartStore in Managing Indexers and Clusters of Indexers.

Data retention based on raw uncompressed data size per index, supplementing existing controls based on time and compressed data size. See Configure data retention for SmartStore indexes in Managing Indexers and Clusters of Indexers.

Improved SmartStore resiliency.

Improved scalability of SmartStore and indexer clustering.

Support for SmartStore on non-clustered standalone indexers. See About SmartStore in Managing Indexers and Clusters of Indexers.

Indexing pipeline improvements Balanced index load distribution: Efficient resource utilization by automatically distributing indexing load within an indexer across multiple pipeline sets, achieving higher indexing throughput, improved resource utilization, and reduced cost. See Manage pipeline sets for index parallelization in Managing Indexers and Clusters of Indexers.
Searchable data rebalance Minimal disruption to searching during indexer cluster data rebalance. See Rebalance the indexer cluster in Managing Indexers and Clusters of Indexers.
Workload management Shared memory resources between search workload pools.


New workload categories provide isolation of resources allocated to search and ingest processes. See How workload management works in the Workload Management manual.

Explicit resource caps on modular inputs and scripted inputs, to limit excessive resource usage.

Enhanced workload rules to control resource usage based on indexes and users, in addition to apps and roles. See Configure workload management in the Workload Management manual.

Improved monitoring of resource consumption on a per pool basis. See Monitor workload management in the Workload Management manual.

Ability to set distinct workload pools for data model acceleration and report acceleration searches. See Assign searches to workload pools in the Workload Management manual.

Splunk Metrics Workspace Splunk Metrics Workspace is now part of Splunk Enterprise inside the Search & Reporting app. See Visualize metrics in the Splunk Metrics Workspace.
Metrics rollups Keep aggregated metrics data over longer periods of time in metrics rollup summaries for storage savings and better search performance. See Roll up metrics data for faster search performance and increased storage capacity in Metrics.
Chart multiple series Co-analyze multiple related metrics easily in the same view and create sophisticated visualizations for monitoring.
Metrics index storage optimization Reduced storage footprint and increased search performance.
Token-based authentication Ability to authenticate in REST API calls using a token instead of username and password for LDAP and local login users. See Set up authentication with tokens in Securing Splunk Enterprise.
Improved roles management New user interface for selecting Searchable Indexes, Default indexes, Capabilities, and Inheritance on the Roles configuration page. See Add and edit roles with Splunk Web in Securing Splunk Enterprise.
Deployer enhancements Flexible deployer options for search head clustering to assist with application and configuration upgrades as well as single search head to SHC migration. See Use the deployer to distribute apps and configuration updates in the Distributed Search manual.
SearchEvaluator performance and memory usage improvements Reduced memory footprint of searches and increased performance.
Search performance enhancements Faster search execution with lower memory usage, especially for complex queries spanning large numbers of indexers.
Enhancement in sub-second event data retention Ability to retain sub-second event data without indexing additional fields. See the ADD_EXTRA_TIME_FIELDS setting in props.conf in the Admin Manual.

What's New in 7.3.1

Splunk Enterprise 7.3.1 was released on July 31, 2019. It introduces the following enhancements and resolves the issues described in Fixed issues.

Enhancement Description
Enhancement to Metric Store Logs to Metrics functionality Support blacklist and whitelist for Metric dimensions when configuring Logs to Metrics. Support for wildcard ( * ) to specify patterns. Ability to automatically treat numeric fields as measures. See Set up ingest-time log-to-metrics conversion with configuration files in Metrics.
Enhancement to Metric Store rollups functionality Ability to roll up only a subset of metrics, rather than every metric in the source metric index. Ability to specify multiple aggregate function rather than a single aggregate function. See Manage metric rollup policies with configuration files in Metrics.
Python future and 2to3 packages Splunk Enterprise 7.3.1 includes the Python libraries "future" and "2to3", which help to make Python 2 syntax compatible with both Python 2 and Python 3. The Splunk Python SDK is dual-compatible via the "Six" library as of v1.6.5, so "future" and "2to3" are most useful for customers who do not use the SDK or who need further modification. See Python 3 Migration for more information.

What's New in 7.3.2

Splunk Enterprise 7.3.2 was released on October 2, 2019. It introduces the following enhancements and resolves the issues described in Fixed issues.

Enhancement Description
Histogram metric datatype support Splunk Enterprise now supports the histogram metric datatype, which enables you to bucket your metric data into a time series of histograms. You can use the new histperc macro to estimate percentile (a.k.a. quantile) values for specific time periods based on your histogram time series. See Use histogram metrics in the Metrics Manual.
Python future and 2to3 packages Splunk Enterprise 7.3.2 includes the Python libraries "future" and "2to3", which help to make Python 2 syntax compatible with both Python 2 and Python 3. The Splunk Python SDK is dual-compatible via the "Six" library as of v1.6.5, so "future" and "2to3" are most useful for customers who do not use the SDK or who need further modification. See Python 3 Migration for more information.

What's New in 7.3.3

Splunk Enterprise 7.3.3 was released on November 18, 2019. It introduces the following enhancement and resolves the issues described in Fixed issues.

Enhancement Description
Dynamic configuration of clustering configurations The following clustering configurations are now dynamically configurable and do not require a restart of the cluster master or indexer.
  • max_replication_errors
  • rep_max_send_timeout
  • rep_max_rcv_timeout
  • target_wait_time
  • use_batch_remote_rep_changes

What's New in 7.3.4

Splunk Enterprise 7.3.4 was released on January 14, 2020. It introduces the following enhancement and resolves the issues described in Fixed issues.

Enhancement Description
Dynamic configuration of clustering configurations The following clustering configurations are now dynamically configurable and do not require a restart of the cluster master or indexer.
  • remote_storage_upload_timeout
  • remote_storage_retention_period

What's New in 7.3.5

Splunk Enterprise 7.3.5 was released on March 25, 2020. It resolves the issues described in Fixed issues.

What's New in 7.3.5.2

Splunk Enterprise 7.3.5.2 was released on May 26, 2020. It resolves the issue described in Fixed issues.

What's New in 7.3.6

Splunk Enterprise 7.3.6 was released on June 4, 2020. It introduces the following enhancement and resolves the issues described in Fixed issues.

Enhancement Description
CPU/vCPU usage dashboards New CPU/vCPU usage dashboards in the Monitoring Console provide a central location for tracking physical CPU and virtual CPU (vCPU) resource consumption of distributed deployments and individual instances.


See Resource Usage: CPU Usage in Monitoring Splunk Enterprise.

What's New in 7.3.7

Splunk Enterprise 7.3.7 was released on August 17, 2020. It introduces the following enhancement and resolves the issues described in Fixed issues.

Enhancement Description
Auto-tuning max_inactive setting in limits.conf Improved ingestion scalability and throughput in a deployment with a high cardinality of host/source/sourcetype combinations by auto-tuning input channel cache. See Troubleshoot the input process in the Getting Data In Manual and limits.conf.spec in the Admin Manual.

What's New in 7.3.7.1

Splunk Enterprise 7.3.7.1 was released on September 2, 2020. It resolves the issue described in Fixed issues.

What's New in 7.3.8

Splunk Enterprise 7.3.8 was released on November 12, 2020. It introduces the following enhancements and resolves the issues described in Fixed issues.

Enhancement Description
SAML assertion encryption SAML assertion encryption provides admins the option to enable encryption of SAML assertions to provide a higher level of security for authentication services. See Configure automatic decryption of SAML assertions from an IdP in the Securing the Splunk Platform Manual.
Read access to license information Users with the new license_read capability can access license information with read-only permissions.

What's New in 7.3.9

Splunk Enterprise 7.3.9 was released on February 24, 2021. It resolves the issues described in Fixed issues.

Documentation updates

Splunk Enterprise 7.3.0 introduces additional guided data onboarding manuals that provide end-to-end guidance for getting specific data sources into specific Splunk platform deployments. You can find all the guided data onboarding manuals by clicking the Add data tab on the Splunk Enterprise documentation page.

REST API updates

This release includes these new and updated REST API endpoints.

New endpoints:

Updated endpoints:

The REST API Reference Manual describes the endpoints.

Last modified on 24 February, 2021
  Known issues

This documentation applies to the following versions of Splunk® Enterprise: 7.3.9


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters