Splunk® Enterprise

Release Notes

Splunk Enterprise version 8.2 is no longer supported as of September 30, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 8.2.7 was released on June 30, 2022. This release includes the fix included in patch version 8.2.6.1 and also fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Search issues

Date resolved Issue number Description
2022-04-26 SPL-221374 streamstats reset_on_change=t breaks the window parameter in 8.2.x
2022-04-22 SPL-222705, SPL-218865 en_GB locale has MM/DD/YY (US) format in timerange picker (used to be DD/MM/YY )
2022-04-11 SPL-221578, SPL-222407 crashing thread: StatusEnforcerThread after upgrading Splunk to version 8.2.5
2022-04-06 SPL-221670, SPL-207048 Tstats search fails when a regular bucket has "psrsvd_v" terms (most common for index=_internal on environments with Enterprise Security)
2022-04-06 SPL-221483, SPL-216071 WLM admission rules preventing use of index=* not honoured when user has restricted index access
2022-04-05 SPL-213464, SPL-221621, SPL-218049 High CPU usage after upgrade from 8.0.5 to 8.2.2
2022-03-27 SPL-218854 Splunkd appears to have a memory leak resulting in an OOM error over time, Splunkd using 288GB memory
2022-03-16 SPL-219874 Automatic Lookups calls to the same file no longer work after upgrading Splunk from 8.0.8 to 8.2.3
2022-03-16 SPL-215906 Following upgrade from 7.3.4 to 8.2.2 customer seeing searches for index=1 OR index=2 OR index=3 missing LOOKUP results
2022-03-08 SPL-217478, SPL-219257 geo_countries lookup creates warning "Possible file corruption of geo lookup binary index file: /Applications/splunk8221/etc/apps/search/lookups/geo_countries/seg.key"

Charting, reporting, and visualization issues

Date resolved Issue number Description
2022-08-04 SPL-218939 classic new dashboard is not showing data/search results from default token, but the first one on the list
2022-06-06 SPL-224947, SPL-223215 Clone- Drilldown in dashboards works only once for dashboard token update
2022-04-27 SPL-222825, SPL-221489 Find search bar in Splunk toolbar only returns Classic dashboards
2022-04-26 SPL-223136, SPL-220713 Resize handle disappearing and refresh button not updating the VIZ
2022-04-19 SPL-221489, SPL-222825, SPL-222826 Find search bar in Splunk toolbar only returns Classic dashboards

Distributed search and search head clustering issues

Date resolved Issue number Description
2022-04-20 SPL-221606 Segmentation fault crash on SHC captains (Crashing thread: TcpChannelThread) - fatal signal 11
2022-04-11 SPL-221578, SPL-222407 crashing thread: StatusEnforcerThread after upgrading Splunk to version 8.2.5
2022-04-01 SPL-219207, SPL-220495 shc_member is getting removed from server_roles for SEARCH HEAD Captain when we switch from dynamic captain to static captain

Indexer and indexer clustering issues

Date resolved Issue number Description
2022-04-20 SPL-216614, SPL-221431 Searchable Rolling Restart stuck reassigning primacy when indexers take more than streaming_replication_wait_secs to roll their buckets when being decommissioned.
2022-03-08 SPL-220090, SPL-216960 Poor diagnosability in the choice of the number of peers to restart at once in site-by-site searchable rolling restarts.

Universal forwarder issues

Date resolved Issue number Description
2022-11-10 SPL-212687, SPL-220769, SPL-221322 'MS Defender' Windows Event Logs stop sending several times a day. System logs still send

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2022-02-24 SPL-218113, SPL-219625, SPL-218941 RestAPI output only ONE UF when TWO UF has same hostname but different GUID

Monitoring Console issues

Date resolved Issue number Description
2022-04-25 SPL-222648, SPL-217286 Monitoring Console : Runtime Statistics mvexpand command runs into excessive memory usage
2022-04-18 SPL-217286, SPL-222648, SPL-226248 Monitoring Console : Runtime Statistics mvexpand command runs into excessive memory usage

Windows-specific issues

Date resolved Issue number Description
2022-11-10 SPL-212687, SPL-220769, SPL-221322 'MS Defender' Windows Event Logs stop sending several times a day. System logs still send

Uncategorized issues

Date resolved Issue number Description
2022-05-30 SPL-224654, SPL-223165 'splunk clean eventdata -index --remote=true' command fails when 'remote.s3.endpoint' not set
2022-05-10 SPL-220216, SPL-217671 Unstable distributed search environment with 100+ search peers when indexers have thousands of indexes. Need a new setting, "searchableIndexMapping", to disable index-mapping feature.
2022-03-17 SPL-220809, SPL-218876 Cloudian Smartstore - changing to signature_version=v4 causes Splunk SmartStore to break
Last modified on 01 August, 2024
Field alias behavior change   Deprecated and removed in version 8.2

This documentation applies to the following versions of Splunk® Enterprise: 8.2.7


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters