Splunk® Enterprise

Release Notes

Splunk Enterprise version 9.0 will no longer be supported as of June 14, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.0.4.1

Splunk Enterprise 9.0.4.1 was released on March 17, 2023. This release fixes the following issue:

Date filed Issue number Description
2023-02-24 SPL-236548, SPL-237216, SPL-236740 SXML dashboards without the "version=" stanza in the search app may have <set>..</set> tags changed to <set /> when upgrading to 9.0.3 or 9.0.4

Splunk Enterprise 9.0.4

Splunk Enterprise 9.0.4 was released on February 14, 2023. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Search issues

Date resolved Issue number Description
2023-01-17 SPL-233842, SPL-231946 |metadata command ignores splunk_server parameter
2022-12-08 SPL-233762, SPL-198314 Exporting _time field applies user timezone offset but contains the server's timezone (usually +0000)
2022-12-06 SPL-230581, SPL-227411 After upgrade one set of clustered indexers has increase in thread crashes during search
2022-11-18 SPL-231852, SPL-230091 Search utilize huge memory on only one indexer.
2022-10-18 SPL-231441, SPL-223053 eventstats will generate less results when time range is large
2022-09-30 SPL-230091, SPL-231852 Search can use large amount of memory on large/malformed events that (look like) XML

Charting, reporting, and visualization issues

Date resolved Issue number Description
2023-01-19 SPL-234344, SPL-234102 Simple XML dashboards outside the search app and without a specified version attribute did not automatically update to version=1.1. This attribute specification does not apply to default dashboards.
2023-01-03 SPL-234148 "Invalid value" for earliest/latest in time token in Studio Dashboards with Chained Searches and Global Time Picker
2022-12-08 SPL-230541, SPL-233115 After upgrade several panels from dashboards do not load and show an error message stating "e.map is not a function"
2022-12-08 SPL-233667, SPL-231930 Refresh not working as expected when chunking is used
2022-12-06 SPL-233115, SPL-230541 After upgrade several panels from dashboards do not load and show an error message stating "e.map is not a function"
2022-12-06 SPL-233110, SPL-230519 Search - Scheduler Dashboard studio views not working as expected after the upgrade when using root_endpoint with more than one directory level (web.conf)
2022-12-06 SPL-233133, SPL-223193 "Open in Search" function doesn't work with chained searches in Dashboard Studio when the time range depends on an input/token, showing error "Invalid earliest_time"

Distributed search and search head clustering issues

Date resolved Issue number Description
2023-01-04 SPL-224258, SPL-220963 SH Deployer ignores per app setting etc/shcluster/apps "deployer_lookups_push_mode" if this setting is present in apps located in ./etc/apps folder

Universal forwarder issues

Date resolved Issue number Description
2023-01-18 SPL-217024, SPL-252644 Constant Memory growth with Universal Forwarder UDP / TCP inputs and third party forwarding enabled.
2022-12-05 SPL-231514, SPL-228406 UF crash on EventLoop::run assert rv > 0
2022-12-01 SPL-233535, SPL-231086 UF 9.x Unnecessary user creation during silent installation

Monitoring Console issues

Date resolved Issue number Description
2023-01-05 SPL-234321, SPL-231388 Backport for splunkd crashed in HealthDistIngestionLatency::calculateAndUpdateHealthColor()
2022-12-20 SPL-231388, SPL-233684, SPL-234321 Splunkd crashed in HealthDistIngestionLatency::calculateAndUpdateHealthColor()

Windows-specific issues

Date resolved Issue number Description
2023-01-05 SPL-233007, SPL-234066 KV Store fails to find the private key for a given certificate on Windows. It searches for -sslCertificateSelector subject=US
2022-12-05 SPL-233454, SPL-224633 Windows Event Logs Message Showing "Splunk could not get the description for this event"
2022-12-01 SPL-233535, SPL-231086 UF 9.x Unnecessary user creation during silent installation
2022-11-18 SPL-232362, SPL-231084 Window Splunk crashes when running INGEST_EVAL lookup

REST, Simple XML, and Advanced XML issues

Date resolved Issue number Description
2023-01-17 SPL-233622, SPL-219208 REST endpoint not reporting accurate index size after upgrade to Splunk Enterprise

Admin and CLI issues

Date resolved Issue number Description
2023-05-09 SPL-235372 The partitionBy setting described under the rfs and rfs:<name> stanzas in outputs.conf.spec is not functional and has no effect.
2022-12-02 SPL-233492, SPL-229404 Invalid key in stanza instrumentation.usage.tlsBestPractices

Uncategorized issues

Date resolved Issue number Description
2022-12-07 SPL-233539, SPL-232879 error message: "Host header contains invalid characters" for host headers containing "_" and for literal IPv6 adresses in square brackets :8000") ]
2022-11-28 SPL-233026, SPL-230560 Splunk crashes with error Crashing thread: IndexInitExecutorWorker-0
2022-11-15 SPL-232357, SPL-219356 Splunk heavy forwarder crashes on TcpOutEloop
Last modified on 22 April, 2024
Field alias behavior change   Deprecated and removed in version 9.0

This documentation applies to the following versions of Splunk® Enterprise: 9.0.4


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters