Known and fixed issues for
This page lists selected known issues and fixed issues for this release of . Use the Version drop-down list to see known issues and fixed issues for other versions of .
See also the release notes for the Cloud Monitoring Console app and the Admin Configuration Service for their respective known and fixed issues.
Version 9.1.2308
This version includes the following known issues:
Date filed or added | Issue number | Description |
---|---|---|
2024-09-05 | SPL-262259 | Splunk to Splunk federated searches do not utilize the dispatch.index_earliest and dispatch.index_latest parameters in the saved search configuration when the search is dispatched to the remote search head, leading to incorrect results.
|
2024-08-27 | SPL-261604 | On-prem to Splunk Cloud transparent mode federated searches that use KVservice fail because the remote search head doesn't use the proxy bundle of the federated (local) search head.
|
2024-06-04 | SPL-237180 | Saved searches on Splunk Cloud Platform that are owned by nobody are scheduled using the default time zone settings in the user-prefs.conf file instead of the system time zone in Splunk Cloud. But, searches are run internally as splunk-system-user, which is tied to system time in Splunk Cloud Platform and is based on UTC (Coordinated Universal Time).
|
2024-4-12 | SPL-254077 | CIDR match for tstats with ipv6 addresses isn't supported. The Error in 'TsidxStats': WHERE clause is not an exact query |
2024-02-27 | SPL-251675 | Splunk Cloud Platform users, including sc_admin, who hold the "list_users_roles" role cannot edit custom roles in Splunk Web.
|
2024-02-11 | SPL-250916 | Add a filter to the GET SHs only of all deployment clients in check_bundles_ready of dc_helpers.py. |
2024-01-24 | SPL-249100 | WLM rules using numeric search_time_range predicate not honoring earliest and latest time modifiers for some user roles when launching search via curl command. |
2024-01-05 | SPL-240774 | The DELIMS setting or the kvdelim option may not be applied correctly when the k/v delim character appears 2 or more times in a field value
|
2023-09-20 | SPL-244927 | Federated searches that include 'table' or 'rex' commands return 0 events when run in verbose mode. |
2023-07-26 | SPL-242487 | Dashboard charts do not support screen reader or keyboard navigation. |
2023-07-20 | SPL-240969 | props and transforms created with 000-self-services (000-self-services/local/transforms.conf) as the destination app get removed during sync triggered by actions such as saving rulesets in Ingest Actions. Workaround: Do not save search time field transformations to the 000-self-services app. Move the existing 000-self-services/local/transformations.conf under a different app. |
2023-07-07 | SPL-241821 | Data Model Accelerations that have Automatic Rebuilds enabled may lead to unbounded memory growth due to search expansion, resulting in Out of Memory errors Workaround: For a data model that is experiencing high memory usage, perform the following steps:
See Accelerate data models in the Knowledge Manager Manual. Furthermore, applying index constraints to restrict the list of indexes searched for building a given DMA summary and applying tags allowlisting would help curtail the memory usage. |
2023-05-30 | Not applicable | ACS endpoint connections fail after June 4, 2023 or HEC sessions fail after June 14, 2023 with error messages that mention SSL, TLS, or HTTP error 503 or 525. See Cloud Platform Discontinuing support for TLS version 1.0 and 1.1. |
2023-05-10 | SPL-239808 | For customers on Google Cloud Platform (GCP), Splunk Secure Gateway does not work. All features including device management and registration are not functional. |
2023-05-08 | SPL-239663 | Search History uses All Time range. |
2023-05-02 | SPL-239436 | In federated search, outputlookup existence check on RSH causes search to terminate early although it is not run on RSH in standard mode Workaround: Define the lookup on both federated search head and remote search head. |
2023-04-28 | SPL-239339 | Workload Management ignores Place in Pool action. |
2023-04-24 | SPL-237902 | Ad hoc searches that specify earliest relative time offset assuming from 'now' should explicitly include 'latest=now' to avoid a potential time range inaccuracy. Workaround:
Ad hoc searches searches that use the earliest time modifier with a relative time offset should also include Running the same search without including |
2023-04-14 | SPL-238738 | Federated search does not support the "Show Source" field action in either standard or transparent mode. |
2023-03-14 | SPL-237265 | Sometimes when a search is aborted by workload rule, 'wlm_terminated' information message is not written to audit log |
2022-08-23 | SPL-228969 | Federated Search: In Splunk Web federated index UI you cannot provide data model Dataset Name values that contain a dot ( . ) character Workaround:
This is a limitation for users of standard mode federated search who want to set up federated indexes that map to data model datasets. It means that such users cannot set up federated indexes for data model datasets that are subordinate to a root dataset. For example, if the root data model dataset is |
2022-07-29 | SPL-227633 | Error : Script execution failed for external search command 'runshellscript' Workaround: The setting precalculate_required_fields_for_alerts=0 can be set on saved searches that have no other alert actions attached aside from the "Run A Script" action, to quash the error. For saved searches that have multiple alert action attached, this may not be safe as it will disable back propagation of required fields for all alert actions, which might result in the parent search extracting more fields than required, which could negatively impact performance for that search. |
2022-06-15 | SPL-226877 | Federated Search UI Error: Cannot create saved search dataset for federated index if dataset name contains space Workaround:
Use REST API to create the federated saved search instead: |
2021-04-30 | SPL-205069 | onunloadCancelJobs failed to cancel search job on Safari Workaround: Use another browser such as Chrome or Firefox |
This version fixes the following issues:
Date filed or added | Issue number | Description |
---|---|---|
2023-10-20 | SPL-241475 | False positive message that a restart is required. User 'admin' triggered the '_reload' action on app 'splunk_monitoring_console', and completing an implicit app deletion requires restart. No restart is required and this message can be ignored.
|
2024-08-30 | SPL-263575 | Update: Parallel reduce processing for the table command has been disabled in Splunk Cloud Platform as of August 30th, 2024.
|
2023-07-19 | SPL-242232 | Dashboard Studio - CSV export does not wrap string values with quotes |
2023-07-05 | SPL-241761 | Dashboard Studio - Table view export does not include all the data of the table in the CSV |
2023-06-29 | SPL-241368 | Updating HEC token in Splunk Web with upper case 'Default' as the index causes an empty index to be set. |
2023-05-22 | SPL-240242 | Federated Search: When exporting results, the remote search head (RSH) returns exceptions when it sees federated search head (FSH) socket errors. The RSH should ignore FSH socket errors. |
2023-05-09 | SPL-239689 | In transparent mode Federated Search for Splunk, custom search commands and the "outputlookup" command should run only on the local deployment. Instead they run on the remote deployment, leading to errors, incorrect results. |
2023-04-27 | SPL-239293 | Transparent Mode Federated Search: Check to turn off forwarding DMA or RA summarization search runs causes federated searches to fail. |
2023-04-17 | SPL-238767 | Standard mode federated search with longer-than-a-minute from command searches might encounter socket ReadWrite errors when the federated provider points to a cloud load balancer, due to idle timeout on the LoadBalancer config
|
2022-02-25 | SPL-219793 | Some commands in federated searches return incorrect resultCount values when run in Verbose mode
|
2022-02-08 | SPL-218842 | Some reporting commands in federated search return incorrect eventCount
|
What's new | Splunk Cloud Platform Field alias behavior change |
This documentation applies to the following versions of Splunk Cloud Platform™: 9.1.2308
Feedback submitted, thanks!