Splunk Stream

Release Notes

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk Stream. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Known issues

Version 7.3.0 of Splunk Stream contains the following known issues.

If no issues appear below, no issues have yet been reported:

Date filed Issue number Description
2021-08-18 STREAM-4918 Stream is not decoded - OCI functions
2021-01-31 STREAM-4679, STREAM-4893 Stream app does not propagate HEC token to Independent Stream Forwarder

Workaround:
Available workaround:

Manually configure HEC token in streamfwd.conf file and ISF is able to connect to the inputs data manager and send the events successfully.

2020-12-08 STREAM-4641, STREAM-4635 Update the actual hostname if stream events host has value $decideOnStartup

Workaround:
Create the etc/system/local/inputs.conf file with the actual hostname manually.
2020-09-03 STREAM-4538 For SALT length greater than 31, Hash Salt functionality is not working on MD5 and SHA512 encoding
2020-08-20 STREAM-4523 Wired data stream fwd instance created is "enabled" instead of "disabled"
2020-01-06 STREAM-4301, STREAM-4409 Windows: Capture stops with "pcap_loop returned error code -1 read error: PacketReceivePacket failed; network capture stopped" and isn't restarted

Workaround:
Re-configure one of the streams assigned to the forwarder in the Stream app, for example, you can add/enable a dummy stream and disable it again later, or change on of the configuration options for an existing Stream

https://docs.splunk.com/Documentation/StreamApp/latest/User/ConfigureStreamsMetadata or restarting Splunk Forwarder service in Windows, for example through services.msc

Sample scenario where you might run into this: Reconfiguration of the NIC while Stream is running (for example, changing the flow control mode in our testing)

Last modified on 16 February, 2022
PREVIOUS
Fixed issues
  NEXT
Boost C++

This documentation applies to the following versions of Splunk Stream: 7.3.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters