Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 8.1.2 was released on February 1, 2021. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Highlighted issues

Date filed Issue number Description
2021-01-29 SPL-198149, SPL-199358 KVStore lookup indexing leads to slow search performance and intermittent errors in searches.

In Splunk Enterprise version 8.1.2, if you encounter this problem change the enable_splunkd_kv_lookup_indexing parameter to true in the [lookup] stanza of limits.conf in your $SPLUNK_HOME/etc/system/local directory on your search peers.

Authentication and authorization issues

Date resolved Issue number Description
2020-12-21 SPL-198824 SAML configuration causes splunkd crash with assert "Assertion `rootPath.isDir()' failed."

Upgrade issues

Date resolved Issue number Description
2020-12-11 SPL-198236, SPL-196933 Settings removed from savedsearches.conf after upgrading from 7.3.3 to 7.3.7.1

Data input issues

Date resolved Issue number Description
2020-11-26 SPL-198010, SPL-197548 Splunk Web > Add Data > Set Source Type; the extracted timestamp (_time) should be in Splunk User's timezone

Search issues

Date resolved Issue number Description
2020-12-21 SPL-198275, SPL-196346 The use of "usetime" and "earlier" arguements are causing a left join to behave as a inner join
2020-12-10 SPL-198365, SPL-198156 On Splunkweb - Splunk Answers link in Help section redirects to a page which is not working
2020-11-25 SPL-198006, SPL-196788 Matching terms on search bear display field names lowercase

Indexer and indexer clustering issues

Date resolved Issue number Description
2020-12-08 SPL-197830, SPL-197071 CMMaster and Fixup warnings repeatedly on new 8.1 index cluster install

Distributed search and search head clustering issues

Date resolved Issue number Description
2021-01-14 SPL-199416, SPL-198851 Unexplained benign SHCMasterHTTPProxy Low Level HTTP Request failure (for artifact) Response Code 500 post upgrade
2020-12-21 SPL-198824 SAML configuration causes splunkd crash with assert "Assertion `rootPath.isDir()' failed."

Splunk Web and interface issues

Date resolved Issue number Description
2020-12-10 SPL-198407, SPL-198097 disabling ui tour in local/ui-conf breaks search in 8.1.0.1 when upgrading from 8.0.5
2020-12-10 SPL-198365, SPL-198156 On Splunkweb - Splunk Answers link in Help section redirects to a page which is not working
2020-11-26 SPL-198010, SPL-197548 Splunk Web > Add Data > Set Source Type; the extracted timestamp (_time) should be in Splunk User's timezone

Admin and CLI issues

Date resolved Issue number Description
2020-12-11 SPL-198236, SPL-196933 Settings removed from savedsearches.conf after upgrading from 7.3.3 to 7.3.7.1

Uncategorized issues

Date resolved Issue number Description
2021-01-14 SPL-193996, SPL-186425 SmartStore: Rebuilding an evicted DMA summary causes us to re-upload the old tsidx file with the newly rebuilt one
2020-12-21 SPL-196941, SPL-198281 diag fails on windows server 2016 running splunk 8.1.0 with french locale/language set
2020-12-17 SPL-198536, SPL-197299 Splunk will crash after startup when enableDataIntegrityControl=true is set for _metrics index
2020-12-16 SPL-198468, SPL-196929 in outputs.conf, configure syslog forward to third party, when the third party syslog server hang, the whole HF stop sending data to indexer tier
2020-12-15 SPL-198537, SPL-195587 Bundles filled up + common bundle issues on SH after disk problems on idx peer
2020-12-10 SPL-198411, SPL-196313 Dashboard panel font size changes with browser zoom on v8.0.2
Last modified on 31 March, 2021
PREVIOUS
Timestamp recognition of dates with two-digit years fails beginning January 1, 2020
  NEXT
Deprecated and removed in version 8.1

This documentation applies to the following versions of Splunk® Enterprise: 8.1.2


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters