Fixed issues
Splunk Enterprise 9.0.4.1
Splunk Enterprise 9.0.4.1 was released on March 17, 2023. This release fixes the following issue:
Date filed
|
Issue number
|
Description
|
2023-02-24 |
SPL-236548, SPL-237216, SPL-236740 |
SXML dashboards without the "version=" stanza in the search app may have <set>..</set> tags changed to <set /> when upgrading to 9.0.3 or 9.0.4
|
Splunk Enterprise 9.0.4
Splunk Enterprise 9.0.4 was released on February 14, 2023. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once.
Search issues
Date resolved
|
Issue number
|
Description
|
2023-01-17 |
SPL-233842, SPL-231946 |
|metadata command ignores splunk_server parameter
|
2022-12-08 |
SPL-233762, SPL-198314 |
Exporting _time field applies user timezone offset but contains the server's timezone (usually +0000)
|
2022-12-06 |
SPL-230581, SPL-227411 |
After upgrade one set of clustered indexers has increase in thread crashes during search
|
2022-11-18 |
SPL-231852, SPL-230091 |
Search utilize huge memory on only one indexer.
|
2022-10-18 |
SPL-231441, SPL-223053 |
eventstats will generate less results when time range is large
|
2022-09-30 |
SPL-230091, SPL-231852 |
Search can use large amount of memory on large/malformed events that (look like) XML
|
Charting, reporting, and visualization issues
Date resolved
|
Issue number
|
Description
|
2023-01-19 |
SPL-234344, SPL-234102 |
Simple XML dashboards outside the search app and without a specified version attribute did not automatically update to version=1.1. This attribute specification does not apply to default dashboards.
|
2023-01-03 |
SPL-234148 |
"Invalid value" for earliest/latest in time token in Studio Dashboards with Chained Searches and Global Time Picker
|
2022-12-08 |
SPL-230541, SPL-233115 |
After upgrade several panels from dashboards do not load and show an error message stating "e.map is not a function"
|
2022-12-08 |
SPL-233667, SPL-231930 |
Refresh not working as expected when chunking is used
|
2022-12-06 |
SPL-233115, SPL-230541 |
After upgrade several panels from dashboards do not load and show an error message stating "e.map is not a function"
|
2022-12-06 |
SPL-233110, SPL-230519 |
Search - Scheduler Dashboard studio views not working as expected after the upgrade when using root_endpoint with more than one directory level (web.conf)
|
2022-12-06 |
SPL-233133, SPL-223193 |
"Open in Search" function doesn't work with chained searches in Dashboard Studio when the time range depends on an input/token, showing error "Invalid earliest_time"
|
Distributed search and search head clustering issues
Date resolved
|
Issue number
|
Description
|
2023-01-04 |
SPL-224258, SPL-220963 |
SH Deployer ignores per app setting etc/shcluster/apps "deployer_lookups_push_mode" if this setting is present in apps located in ./etc/apps folder
|
Universal forwarder issues
Date resolved
|
Issue number
|
Description
|
2023-01-18 |
SPL-217024, SPL-252644 |
Constant Memory growth with Universal Forwarder UDP / TCP inputs and third party forwarding enabled.
|
2022-12-05 |
SPL-231514, SPL-228406 |
UF crash on EventLoop::run assert rv > 0
|
2022-12-01 |
SPL-233535, SPL-231086 |
UF 9.x Unnecessary user creation during silent installation
|
Monitoring Console issues
Date resolved
|
Issue number
|
Description
|
2023-01-05 |
SPL-234321, SPL-231388 |
Backport for splunkd crashed in HealthDistIngestionLatency::calculateAndUpdateHealthColor()
|
2022-12-20 |
SPL-231388, SPL-233684, SPL-234321 |
Splunkd crashed in HealthDistIngestionLatency::calculateAndUpdateHealthColor()
|
Windows-specific issues
Date resolved
|
Issue number
|
Description
|
2023-01-05 |
SPL-233007, SPL-234066 |
KV Store fails to find the private key for a given certificate on Windows. It searches for -sslCertificateSelector subject=US
|
2022-12-05 |
SPL-233454, SPL-224633 |
Windows Event Logs Message Showing "Splunk could not get the description for this event"
|
2022-12-01 |
SPL-233535, SPL-231086 |
UF 9.x Unnecessary user creation during silent installation
|
2022-11-18 |
SPL-232362, SPL-231084 |
Window Splunk crashes when running INGEST_EVAL lookup
|
REST, Simple XML, and Advanced XML issues
Date resolved
|
Issue number
|
Description
|
2023-01-17 |
SPL-233622, SPL-219208 |
REST endpoint not reporting accurate index size after upgrade to Splunk Enterprise
|
Admin and CLI issues
Date resolved
|
Issue number
|
Description
|
2023-05-09 |
SPL-235372 |
The partitionBy setting described under the rfs and rfs:<name> stanzas in outputs.conf.spec is not functional and has no effect.
|
2022-12-02 |
SPL-233492, SPL-229404 |
Invalid key in stanza instrumentation.usage.tlsBestPractices
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2022-12-07 |
SPL-233539, SPL-232879 |
error message: "Host header contains invalid characters" for host headers containing "_" and for literal IPv6 adresses in square brackets :8000") ]
|
2022-11-28 |
SPL-233026, SPL-230560 |
Splunk crashes with error Crashing thread: IndexInitExecutorWorker-0
|
2022-11-15 |
SPL-232357, SPL-219356 |
Splunk heavy forwarder crashes on TcpOutEloop
|
Feedback submitted, thanks!