Release notes
This topic contains information on new features, known issues, and updates as we version the Splunk App for Unix and Linux.
What's new
Here's what's new in the latest version of the Splunk App for Unix and Linux:
Publication date | Defect number | Description |
2016-7-18 | N/A | Bug fixes. |
2016-7-18 | N/A | The Splunk Add-on for Unix and Linux (Splunk_TA_Nix ) no longer comes with the Splunk App for Unix and Linux installation package. You remain able to download the Splunk Add-on for Unix and Linux separately from Splunkbase. The Splunk Supporting Add-on for Unix and Linux (SA-Nix ) remains a part of the Splunk App for Unix and Linux installation package.
|
2016-7-18 | TAG-9872 | On Splunk Cloud instances, you can now add data during the first-time run experience (the "Add Data" button now works as designed, rather than doing nothing when clicked.) |
Current known issues
The Splunk App for Unix and Linux has the following known issues:
Publication date | Defect number | Description |
2016-2-29 | TAG-10770 | When you upgrade to Splunk Enterprise 6.3.3 or later, Splunk Enterprise generates the following messages on startup:
These messages can be safely ignored. |
2015-11-13 | TAG-9506 | When you switch to the app, sometimes the system bar appears as it did in Splunk Enterprise version 5 or earlier. |
2015-11-13 | TAG-9620 | Search head clusters do not replicate some of the lookup tables for the app. |
2015-11-13 | TAG-9872 | On Splunk Cloud instances, you cannot add data during the first-time run experience. |
2015-9-21 | TAG-9872 | On a Splunk Cloud instance, the app does not let you add new sources during the first-time run if there are no preexisting sources. |
2015-9-21 | TAG-9577 | A configuration problem with the Splunk Supporting Add-on for Unix and Linux could cause reduced indexing performance if you install it on indexers. To avoid this issue, follow the updated documentation on installing the add-on. |
2015-9-21 | TAG-9313 | The "Home" and "Metrics" views sometimes do not display any data. To work around the problem, edit web.conf on the Splunk Enterprise instance that runs the app and add the following section:
[settings] minify_js = True |
2015-9-21 | TAG-9210 | The "Recent Headlines" page only displays one host for an alert, even if there are multiple hosts for an alert. |
2015-9-21 | TAG-4262 | On Mac OS X systems, all scripted inputs fail on directories whose names contain spaces. |
Before 2015-9-21 | None | On HP/UX systems, there is no way to obtain the number of threads on a system. This means that the vmstat scripted inputs will always return "?" for threads columns on HP/UX.
|
2015-9-21 | TAG-4261 | On Solaris systems, the hardware.sh scripted input sometimes returns empty values for some entries.
|
2015-9-21 | TAG-4211 | The Splunk Add-on for Unix and Linux collects system audit log data twice by default. |
Change Log (what's been fixed)
Publication date | Defect number | Description |
2016-7-18 | TAG-9872 | On Splunk Cloud instances, you can now add data during the first-time run experience (the "Add Data" button now works as designed, rather than doing nothing when clicked.) |
Search macros | Third-party software attributions/credits |
This documentation applies to the following versions of Splunk® App for Unix and Linux (Legacy): 5.2.0
Feedback submitted, thanks!