Known and fixed issues for
This page lists selected known issues and fixed issues for .
See also the release notes for the Cloud Monitoring Console app and the Admin Configuration Service for their respective known and fixed issues.
Version 8.2.2201
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2023-06-29 | SPL-241621 | Dashboards are loading slower than typical. Workaround: Set disable_highcharts_accessibility=true in web-features.conf to restore dashboard performance. |
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2022-08-12 | SPL-224045 | Data intended for Summary Indexes may be be misrouted to the default "main" index and lead to incomplete search results for searches using the Summary Index. |
2022-07-29 | SPL-227633 | Error : Script execution failed for external search command 'runshellscript' Workaround: The setting precalculate_required_fields_for_alerts=0 can be set on saved searches that have no other alert actions attached aside from the "Run A Script" action, to quash the error. For saved searches that have multiple alert action attached, this may not be safe as it will disable back propagation of required fields for all alert actions, which might result in the parent search extracting more fields than required, which could negatively impact performance for that search. |
2022-03-09 | SPL-220289 | Federated Search Transparent Mode: Commands that have subsearches like join and append may result in failures on RSH due to missing application context Workaround: If the search is being run in an application context that does not exist on the remote deployment, install the missing application on the remote deployment. |
2022-02-22 | SPL-219540 | outputlookup command in a federated search creates output on RSH |
2022-01-19 | SPL-217505 | Federated searches fail when 'table' command is used Workaround: Fix a federated search that runs into this issue by appending `| noop search_optimization.replace_table_with_fields=f` to the search string. |
2021-12-22 | PAPP-23255 | In version 4.1.73 of Phantom App on Splunk, there is an erroneous error message when syncing workbooks. The sync performs successfully, but upon completion, the error message states that the sync failed. You can safely ignore this error message. A fix will be included in the next GA release of Phantom App on Splunk. |
2021-10-21 | SPL-214005 | Victoria Experience self-service app install: Lookups deployed by apps cannot be managed via UI, Admin Config Service (ACS API), or Splunk REST APIs. Workarounds:
|
2021-04-30 | SPL-205069 | onunloadCancelJobs failed to cancel search job on Safari Workaround: Use another browser such as Chrome or Firefox |
This version fixes the following issue:
Date filed | Issue number | Description |
---|---|---|
2021-09-02 | SPL-211648 | In transparent mode, federated search with eventtype and macro is not applied to remote deployment search head |
Version 8.2.2112
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2022-08-12 | SPL-224045 | Data intended for Summary Indexes may be be misrouted to the default "main" index and lead to incomplete search results for searches using the Summary Index. |
2022-07-29 | SPL-227633 | Error : Script execution failed for external search command 'runshellscript' Workaround: The setting precalculate_required_fields_for_alerts=0 can be set on saved searches that have no other alert actions attached aside from the "Run A Script" action, to quash the error. For saved searches that have multiple alert action attached, this may not be safe as it will disable back propagation of required fields for all alert actions, which might result in the parent search extracting more fields than required, which could negatively impact performance for that search. |
2022-02-22 | SPL-219540 | outputlookup command in a federated search creates output on RSH |
2022-01-19 | SPL-217505 | Federated searches fail when 'table' command is used Workaround: Fix a federated search that runs into this issue by appending `| noop search_optimization.replace_table_with_fields=f` to the search string. |
2021-10-21 | SPL-214005 | Victoria Experience self-service app install: Lookups deployed by apps cannot be managed via UI, Admin Config Service (ACS API), or Splunk REST APIs. Workarounds:
|
2021-09-02 | SPL-211648 | In transparent mode, federated search with eventtype and macro is not applied to remote deployment search head |
2021-04-30 | SPL-205069 | onunloadCancelJobs failed to cancel search job on Safari Workaround: Use another browser such as Chrome or Firefox |
This version fixes the following issue:
Date filed | Issue number | Description |
---|---|---|
2021-12-03 | SPL-215861 | EPS drops after upgrade as a result of default 50k export cap in limits.conf. |
Version 8.2.2111
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2022-08-12 | SPL-224045 | Data intended for Summary Indexes may be be misrouted to the default "main" index and lead to incomplete search results for searches using the Summary Index. |
2022-07-29 | SPL-227633 | Error : Script execution failed for external search command 'runshellscript' Workaround: The setting precalculate_required_fields_for_alerts=0 can be set on saved searches that have no other alert actions attached aside from the "Run A Script" action, to quash the error. For saved searches that have multiple alert action attached, this may not be safe as it will disable back propagation of required fields for all alert actions, which might result in the parent search extracting more fields than required, which could negatively impact performance for that search. |
2022-02-22 | SPL-219540 | outputlookup command in a federated search creates output on RSH |
2022-01-19 | SPL-217505 | Federated searches fail when 'table' command is used Workaround: Fix a federated search that runs into this issue by appending `| noop search_optimization.replace_table_with_fields=f` to the search string. |
2021-12-03 | SPL-215861 | EPS drops after upgrade as a result of default 50k export cap in limits.conf. |
2021-10-21 | SPL-214005 | Victoria Experience self-service app install: Lookups deployed by apps cannot be managed via UI, Admin Config Service (ACS API), or Splunk REST APIs. Workarounds:
|
2021-09-02 | SPL-211648 | In transparent mode, federated search with eventtype and macro is not applied to remote deployment search head |
2021-04-30 | SPL-205069 | onunloadCancelJobs failed to cancel search job on Safari Workaround: Use another browser such as Chrome or Firefox |
This version fixes the following Issues:
Date filed | Issue number | Description |
---|---|---|
2021-10-21 | SPL-213892 | Splunkbase apps installed via self-service cannot be upgraded in Victoria Experience version 8.2.2109. The following error message appears: |
Version 8.2.2109
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2022-02-22 | SPL-219540 | outputlookup command in a federated search creates output on RSH |
2022-01-19 | SPL-217505 | Federated searches fail when 'table' command is used Workaround: Fix a federated search that runs into this issue by appending `| noop search_optimization.replace_table_with_fields=f` to the search string. |
2021-12-03 | SPL-215861 | EPS drops after upgrade as a result of default 50k export cap in limits.conf. |
2021-10-21 | SPL-213892 | Splunkbase apps installed via self-service cannot be upgraded in Victoria Experience version 8.2.2109. The following error message appears: |
2021-10-21 | SPL-214005 | Victoria Experience self-service app install: Lookups deployed by apps cannot be managed via UI, Admin Config Service (ACS API), or Splunk REST APIs. Workarounds:
|
2021-09-02 | SPL-211648 | In transparent mode, federated search with eventtype and macro is not applied to remote deployment search head |
2021-04-30 | SPL-205069 | onunloadCancelJobs failed to cancel search job on Safari Workaround: Use another browser such as Chrome or Firefox |
This version fixes the following Issues:
Date filed | Issue number | Description |
---|---|---|
2021-08-12 | SPL-210244 | No default value selected on radio buttons in Simple XML dashboards |
2021-08-05 | SPL-209879 | Unable to upload private apps in .tar.gz format on Victoria Experience. Workaround: Upload the app in .tar format |
Version 8.2.2107
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2021-12-03 | SPL-215861 | EPS drops after upgrade as a result of default 50k export cap in limits.conf. |
2021-10-21 | SPL-214005 | Victoria Experience self-service app install: Lookups deployed by apps cannot be managed via UI, Admin Config Service (ACS API), or Splunk REST APIs. Workarounds:
|
2021-08-12 | SPL-210244 | No default value selected on radio buttons in Simple XML dashboards |
2021-08-05 | SPL-209879 | Unable to upload private apps in .tar.gz format on Victoria Experience. Workaround: Upload the app in .tar format |
2021-05-24 | SPL-206131 | Examples Hub does not load when using a reverse proxy |
2021-04-30 | SPL-205069 | onunloadCancelJobs failed to cancel search job on Safari Workaround: Use another browser such as Chrome or Firefox |
Version 8.2.2106
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2021-08-05 | SPL-209879 | Unable to upload private apps in .tar.gz format on Victoria Experience. Workaround: Upload the app in .tar format |
2021-05-24 | SPL-206131 | Examples Hub does not load when using a reverse proxy |
2021-04-30 | SPL-205069 | onunloadCancelJobs failed to cancel search job on Safari Workaround: Use another browser such as Chrome or Firefox |
This version fixes the following Issues:
Date filed | Issue number | Description |
---|---|---|
2021-06-29 | SPL-207228 | Invalid UTF-8 bytes (stats search corruption) in audit.log search results break search head cluster heartbeat communication |
2021-05-13 | SPL-205645 | Index deletion fails in deployments on Victoria Experience |
2021-05-11 | SPL-205528 | manager/search/datainputstats only displays a maximum of 30 modular inputs |
Version 8.2.2105
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2021-05-24 | SPL-206131 | Examples Hub does not load when using a reverse proxy |
2021-05-13 | SPL-205645 | Index deletion fails in deployments on Victoria Experience |
2021-05-11 | SPL-205528 | manager/search/datainputstats only displays a maximum of 30 modular inputs |
2021-04-30 | SPL-205069 | onunloadCancelJobs failed to cancel search job on Safari Workaround: Use another browser such as Chrome or Firefox |
This version fixes the following issues:
Date filed | Issue number | Description |
---|---|---|
2021-06-30 | SPL-207554 | Savedsearches.conf not in sync/not replicating to all SHC members |
Version 8.2.2104
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2021-05-24 | SPL-206131 | Examples Hub does not load when using a reverse proxy |
Version 8.1.2103
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2021-05-24 | SPL-206131 | Examples Hub does not load when using a reverse proxy |
This version fixes the following issues:
Date filed | Issue number | Description |
---|---|---|
2021-04-21 | SPL-201945 | streamstats command not functioning as expected after upgrade |
Version 8.1.2101
This version includes the following known issues:
Date filed | Issue number | Description |
---|---|---|
2022-12-02 | SPL-226717 | The behavior of the maxspan and maxpause arguments for the transaction command are currently reversed from the way they are documented in transaction in the Splunk Platform Search Reference. This bug will be fixed in a future release. The following are the current behaviors for the
|
2021-04-21 | SPL-201945 | streamstats command not functioning as expected after upgrade |
New features | Splunk Cloud Platform Field alias behavior change |
This documentation applies to the following versions of Splunk Cloud Platform™: 8.2.2201
Feedback submitted, thanks!