Splunk® Enterprise

Release Notes

Splunk Enterprise version 8.0 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 8.0.7 was released on October 28, 2020. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Upgrade issues

Date resolved Issue number Description
2020-12-02 SPL-192191, SPL-193821, SPL-194814, SPL-194816 Splunk Enterprise upgrade from version 7.x to 8.0.3 fails due to authentication.conf being encoded as Unicode/UTF-16LE

Authentication and authorization issues

Date resolved Issue number Description
2020-09-02 SPL-191964, SPL-192421, SPL-194541 Scripted authentication times out for pages that resolve permissions for many users.

Search issues

Date resolved Issue number Description
2020-10-07 SPL-194790, SPL-194960, SPL-194961 Reached limit max_mem_usage_mb error not appearing in UI
2020-09-30 SPL-195126, SPL-193949 search process throws exception with "ERROR SearchEvaluatorBasedExpander - Caught exception during filter to index expansion - unbalanced parentheses"
2020-09-11 SPL-194285, SPL-191472 Getting Security ID value equal to NONE_MAPPED for Member for the EventCode = 4732
2020-09-10 SPL-194413, SPL-188395, SPL-194801, SPL-194819 WebUI is not Returning Proper Bundle Validation-Restart check when there is a "Not Critical" error
2020-09-10 SPL-191854, SPL-183986 webhooks failing on Python3
2020-09-03 SPL-194536, SPL-193073, SPL-193598 reverse lookup shows inconsistent behaviors
2020-08-26 SPL-192593, SPL-192874 Searches crash with segmentation fault, backtrace contains _ZN14UnpackedResult8addMatchEP15SearchResultMemPK22LookupProcessorOptionsP19ILookupMatchFunctorPK16LookupDefinition

Charting, reporting, and visualization issues

Date resolved Issue number Description
2020-10-02 SPL-195274, SPL-193747 Console errors while loading Area chart - "TypeError: this.hcSeries.graph is undefined" or "TypeError: Cannot read property 'attr' of undefined" console error
2020-08-26 SPL-191256, SPL-191802 Dashboard search using geostats breaks when using basesearch
2020-08-20 SPL-193477, SPL-192954 Post 7.3.4 upgrade regression: SimpleXML: <selectFirstChoice> causes browser hang, cpu spike, when value is set to 'true'

Distributed search and search head clustering issues

Date resolved Issue number Description
2020-10-07 SPL-193571, SPL-194010, SPL-194964 SHC Captain number of threads kept increasing to over 8000; searches stopped;due to deadlock in CascadingBundleReplicationProvider code
2020-09-09 SPL-194186, SPL-194479, SPL-194627 Some search jobs run and then pause for a period of time before the search finishes.
2020-09-03 SPL-190110, SPL-90688 Platform alert "DMC Alert - Search Peer Not Responding" will never trigger for cluster peers who are down because clustering doesn't track peers in this state

Indexer and indexer clustering issues

Date resolved Issue number Description
2020-09-11 SPL-194091, SPL-193066 Deserialization failed. val for key=indexing_disk_space is not a valid unsigned long long number.
2020-09-03 SPL-190110, SPL-90688 Platform alert "DMC Alert - Search Peer Not Responding" will never trigger for cluster peers who are down because clustering doesn't track peers in this state

Monitoring Console issues

Date resolved Issue number Description
2020-09-03 SPL-190110, SPL-90688 Platform alert "DMC Alert - Search Peer Not Responding" will never trigger for cluster peers who are down because clustering doesn't track peers in this state
2020-08-27 SPL-191479, SPL-194327, SPL-192966 DiskMon messages throwing wrongly for volumes beyond normal hot/warm and cold

Splunk Web and interface issues

Date resolved Issue number Description
2020-10-07 SPL-194790, SPL-194960, SPL-194961 Reached limit max_mem_usage_mb error not appearing in UI
2020-09-30 SPL-195126, SPL-193949 search process throws exception with "ERROR SearchEvaluatorBasedExpander - Caught exception during filter to index expansion - unbalanced parentheses"
2020-09-11 SPL-194285, SPL-191472 Getting Security ID value equal to NONE_MAPPED for Member for the EventCode = 4732
2020-09-10 SPL-194413, SPL-188395, SPL-194801, SPL-194819 WebUI is not Returning Proper Bundle Validation-Restart check when there is a "Not Critical" error
2020-09-10 SPL-191854, SPL-183986 webhooks failing on Python3
2020-09-03 SPL-194536, SPL-193073, SPL-193598 reverse lookup shows inconsistent behaviors
2020-08-26 SPL-192593, SPL-192874 Searches crash with segmentation fault, backtrace contains _ZN14UnpackedResult8addMatchEP15SearchResultMemPK22LookupProcessorOptionsP19ILookupMatchFunctorPK16LookupDefinition

Admin and CLI issues

Date resolved Issue number Description
2020-08-28 SPL-191464, SPL-192551 Sharing permission of tags created under one view is not modifiable within other views

Uncategorized issues

Date resolved Issue number Description
2020-10-22 SPL-193425, SPL-191436 Diag needs updating so it obfuscates or removes values for remote.s3.kms.key_id values
2020-09-16 SPL-191298, SPL-193299, SPL-194575 Excess bucket removal process getting stuck when unstable buckets are not deleted due to being missing in CacheManager
Last modified on 10 December, 2024
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020   Deprecated and removed in version 8.0

This documentation applies to the following versions of Splunk® Enterprise: 8.0.7


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters