Known issues
Known issues in Splunk App for Stream 6.1.1:
Publication date | Defect number | Description |
---|---|---|
2015-11-16 | STREAM-2532 | Stream events are timestamped with index time in distributed Splunk Enterprise environment. |
2015-10-21 | STREAM-2277 | Back button does not show warning for unsaved changes. This can cause you to lose edits when modifying a stream. |
2015-10-21 | STREAM-2268 | imap "password" field is missing. |
2015-10-21 | STREAM-2262 | Aggregated streams don't emit "endtime field. |
2015-10-21 | STREAM-2259 | Saving stream with addToDefaultGroup=false fails. |
2015-10-21 | STREAM-2222 | Stream tries to open pcap adapter on inactive interface. |
2015-10-21 | STREAM-2193 | The stream id (labeled 'Name' in the Configure Streams UI) is case sensitive. This lets you create a stream with the same name as a default stream, for example, id "HTTP", which you can confuse with the default stream id "http." |
2015-10-21 | STREAM-2190 | Stream Forwarder skips IP packets with zero length (ip.len==0) in the IP header. |
2015-10-21 | STREAM-2183 | request_time, reply_time, and response_time flow metrics are not populated for all protocols. |
2015-10-21 | STREAM-2179 | Sparkline in Configure Streams UI under certain circumstances incorrectly shows zero traffic volume for protocols. |
2015-10-21 | STREAM-2169 | SSL key stored in local/directory. |
2015-10-21 | STREAM-2156 | streamfwd process may exhibit unbounded memory growth when running on Splunk Universal Forwarder instance that is unable to forward events, most commonly because of incorrect tcpout parameters in outputs.conf configuration.
|
2015-10-21 | STREAM-1834 | Inefficient captured packet queueing. |
2015-08-07 | STREAM-2190 | SDSSL skips IP packets with zero length (ip.len==0) in the IP header. |
2015-04-19 | STREAM-1913 | Splunkd does not reliably shut down streamfwd process. |
2015-04-19 | STREAM-1909 | SNMP events not returning key pieces of data due to lack of parsing from original binary format. |
2015-03-31 | STREAM-1864 | Incorrect multicast DNS request/response matching leads to unbounded event size build-up. |
2015-03-31 | STREAM-1846 | Dashboard searches fail for time periods greater than 60 minutes. |
2014-12-18 | STREAM-1589 | Some protocol events map to incorrect name. This occurs because Splunk_TA_stream 6.1.x reuses conflicting transforms.conf stanza names from Splunk_TA_nix .
|
2014-12-18 | STREAM-1572 | Initial configuration page for App for Stream does not load in Splunk Enterprise 6.0. Workaround: Upgrade Splunk Enterprise to version 6.1.x or later (version 6.2.1 recommended). |
2014-12-18 | STREAM-1550 | After manually deleting the splunk_app_stream and Splunk_TA_stream folders without stopping Splunk and then installing or upgrading the app, the Wire Data input stops working. Workaround: See this troubleshooting item.
|
2014-10-30 | STREAM-1282 | Unexplained "DPI error processing stream data" messages appear in streamfwd.log .
|
Fixed Issues |
This documentation applies to the following versions of Splunk Stream™: 6.1.1
Feedback submitted, thanks!