Splunk Stream

Release Notes

This documentation does not apply to the most recent version of Splunk Stream. For documentation on the most recent version, go to the latest release.

Fixed Issues

Fixed issues in Splunk App for Stream 6.3.1:

Defect number Description
STREAM-2122 src and dest fields are not being populated.
STREAM-2088 When upgrading to Stream version 6.3.0, the deploy_splunk_ta_stream.py scripted input overwrites any existing local/inputs.conf files, if an upgrade of Splunk_TA_stream is required. This affects the copies of Splunk_TA_stream in both etc/apps/ and etc/deployment-apps/ directories.
STREAM-2078 When creating a new distributed forwarder management group, if the "Include Ephemeral Streams" option is enabled, the front end UI regex check and the backend regex check are not in sync (one checks for "contains" and the other checks for "exact-match").
STREAM-1988 When searching on sourcetype=stream:tns the only streams visible are those generated by tnsping. Traffic generated by sqlplus or other Oracle client consumers is not decoded as TNS.
STREAM-1709 Lack of support for substitution of TNS bind variables led to limited information in SQL queries. Fix: Version 6.3.1 adds support for substitution of variable names with bind variable value. Supported cases include:
  • Bind variables that are specified in this format: BEGIN :BINDVAR=VALUE; END;
  • Bind variables that are loaded via SELECT VALUE IN TO :BINDVAR FROM TABLE

For the above cases, BINDVAR in subsequent queries will be substituted by the actual value assigned to the BINDVAR.

STREAM-1557 In certain cases, TCP packets captured out-of-order might generate invalid TCP flow events and lead to excessive memory usage.
Last modified on 21 October, 2015
Known issues   New Features

This documentation applies to the following versions of Splunk Stream: 6.3.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters