Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


Splunk Enterprise version 8.1 will no longer be supported as of April 19, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 8.1.5 was released on July 15, 2021. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Authentication and authorization issues

Date resolved Issue number Description
2021-06-10 SPL-205482, SPL-206086, SPL-206095 Post 8.1.3 upgrade: existing SAML configuration ceased to function. Configuration UI displays "Method not allowed" message
2021-06-08 SPL-206758, SPL-206123 The authorize.conf setting srchIndexesDisallowed is ignored if search heads or peers are running version 8.0.x or lower in a mixed version environment
2021-06-03 SPL-205249, SPL-203901 Settings in Authentication Extension cause SH to crash
2021-06-03 SPL-205247, SPL-204519 SAML Scripted Auth Extensions login() function uses wrong assertion attribute
2021-05-18 SPL-204166 OEM customer can't elevate user privileges to configure SAML

Upgrade issues

Date resolved Issue number Description
2021-05-26 SPL-198052, SPL-206073, SPL-206074, SPL-206076 Upgrading From 8.0.6 to 8.1.0.1 Using a DEB package results in a No such file or directory message.

Search issues

Date resolved Issue number Description
2021-06-17 SPL-205620, SPL-197309 asset_by_cidr running before asset_by_str intermittently causing incorrect src_category to be applied to some events
2021-06-07 SPL-206450, SPL-205362 No events are returned when data with preceding wildcards(*) is ingested
2021-05-25 SPL-205542, SPL-205545, SPL-205978, SPL-205975, SPL-205976 SPL command "iplocation" info is out of date

Charting, reporting, and visualization issues

Date resolved Issue number Description
2021-05-07 SPL-204977, SPL-201506 strptime function in drilldown does not convert 3 digit millisecond values and shows NAN

Indexer and indexer clustering issues

Date resolved Issue number Description
2021-11-09 SPL-214324, SPL-205462 Indexers running out of space - Splunk not honoring the 'maxVolumeDataSizeMB' setting - 8.2.2
2021-07-15 SPL-205462, SPL-210602, SPL-211950, SPL-214324 Indexers running out of space - Splunk not honoring the 'maxVolumeDataSizeMB' setting

Distributed search and search head clustering issues

Date resolved Issue number Description
2021-06-09 SPL-206700, SPL-206055 Unable to see the scheduled type in sourcetype search_telemetry on SHC.

Universal forwarder issues

Date resolved Issue number Description
2021-05-26 SPL-198052, SPL-206073, SPL-206074, SPL-206076 Upgrading From 8.0.6 to 8.1.0.1 Using a DEB package results in a No such file or directory message.

Admin and CLI issues

Date resolved Issue number Description
2021-05-07 SPL-200416, SPL-203387 splunk clone-prep-clear-config command not removing host attribute as of 8.1.x

Uncategorized issues

Date resolved Issue number Description
2021-06-10 SPL-204962, SPL-205729, SPL-207105 Scheduled Jobs sendemail csv file Generated Extra Blank Rows
2021-06-10 SPL-206856, SPL-205891 8.1 Export button is a half visible in report
2021-06-03 SPL-198154, SPL-206108, SPL-206107 Cannot edit lmpool if a member host has been resolved to 'None' in slaves list
2021-06-03 SPL-206283, SPL-204489 Many events from internal logs are directed to malformedEventIndex
2021-05-23 SPL-194082, SPL-197944, SPL-205549, SPL-205885 idle_s3_http_client thread crashes splunkd on indexers due to remotestore connectivity issues.
Last modified on 16 September, 2022
PREVIOUS
Field alias behavior change
  NEXT
Deprecated and removed in version 8.1

This documentation applies to the following versions of Splunk® Enterprise: 8.1.5


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters