Splunk® Enterprise

Release Notes

This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise

Splunk Enterprise was released on February 8, 2024. This release fixes the following issues:

Date filed Issue number Description
2024-02-05 SPL-250501 Config validation check mistakenly blocks config push on Splunk Enterprise. This issue affects Splunk Enterprise 9.2.0 and is fixed in Splunk Enterprise
2024-02-05 SPL-250529 Occasional indexer crashes during data ingest. This issue affects Splunk Enterprise 9.2.0 and is fixed in Splunk Enterprise

Splunk Enterprise 9.2.0

Splunk Enterprise 9.2.0 was released on January 31, 2024. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Data input issues

Date resolved Issue number Description
2023-11-09 SPL-246770, SPL-243845 HTTP Input HEC input ignores _meta in inputs.conf

Search issues

Date resolved Issue number Description
2023-11-07 SPL-246383, SPL-246534, SPL-246535, SPL-246536, SPL-246537, SPL-246538, SPL-246539 Excessive logging in AuditLogger of "action=admin_all_objects, info=denied" after upgrade from 9.0.4 to 9.1.1
2023-10-31 SPL-245633, SPL-242255 Caret operator is not being identified in regex after upgrading from 8.1.3
2023-10-20 SPL-246065, SPL-190401 Crash in NewTransamProcessor
2023-10-12 SPL-245471, SPL-239942 Splunk fails to finalize a search on smart store enabled cluster when phased_execution_mode is set to multithreaded
2023-10-09 SPL-245287, SPL-245166 UTF-8 characters should not be hex-encoded in Splunk logs.

Federated search issues

Date resolved Issue number Description
2023-08-18 SPL-241502, SPL-243208, SPL-243209 Transparent federated search with service account making api calls takes excessive time
2023-07-26 SPL-238767, SPL-244936, SPL-244937 Standard mode federated search with longer than a minute From command searches, encounters socket ReadWrite error when the federated provider points to a cloud Load balancer, due to idle timeout on the LoadBalancer config
2023-06-20 SPL-240242 Federated Search: When exporting results, the remote search head (RSH) returns exceptions when it sees federated search head (FSH) socket errors. The RSH should ignore FSH socket errors.

Charting, reporting, and visualization issues

Date resolved Issue number Description
2023-07-26 SPL-240964 Visualization action buttons are not working as expected in Dashboard Studio home dashboards.
2023-06-29 SPL-241274 Dashboard Studio fails to load dashboards and displays the error "Cannot convert undefined or null to object" when search results return "null" values.

Distributed search and search head clustering issues

Date resolved Issue number Description
2023-10-20 SPL-246065, SPL-190401 Crash in NewTransamProcessor

Universal forwarder issues

Date resolved Issue number Description
2023-11-03 SPL-245807, SPL-246456, SPL-246545, SPL-246546 Splunk AIX UF crashing when failed to connect to indexers
2023-11-02 SPL-246546, SPL-245807 Splunk AIX UF crashing. Crashing thread: TcpOutEloop
2023-10-24 SPL-244414 Crashing in TcpOutEloop thread after upgrade from 9.1.x

Monitoring Console issues

Date resolved Issue number Description
2024-02-27 SPL-242335, SPL-243122, SPL-243124, SPL-243125, SPL-243156, SPL-251683 Monitoring Console Several DMC dashboards fail to complete underlying searches

Splunk Web and interface issues

Date resolved Issue number Description
2023-09-25 SPL-244175, SPL-240690 Requests for ui-tour and ui-pref endpoints are frequently taking seconds to complete.
2023-07-11 SPL-241706, SPL-240758 "File Integrity checks found 4281 files that did not match the system-provided manifest." shows in message but does not appear in the "Integrity Check of Installed Files" dashboard.
2023-07-11 SPL-241705, SPL-240758 "File Integrity checks found 4281 files that did not match the system-provided manifest." shows in message but does not appear in the "Integrity Check of Installed Files" dashboard.

Uncategorized issues

Date resolved Issue number Description
2023-05-23 SPL-234643 Splunkd abort - due to 3rd party S2S client unable to process ACKs.
2023-03-28 SPL-224063, SPL-258953 metrics.log - tcpin_connections - logs are merging from different forwarders in single events
Last modified on 16 July, 2024
Field alias behavior change   Deprecated and removed in version 9.2

This documentation applies to the following versions of Splunk® Enterprise: 9.2.0

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters