3.3
This documentation does not apply to the most recent version of Splunk.
This documentation applies to the following versions of Splunk:
3.3 , 3.3.1 , 3.3.2 , 3.3.3 , 3.3.4
3.3
The following issues have been resolved in version 3.3
- The free version of Splunk no longer returns an auth error when attempting to access REST endpoints. (SPL-13741)
- Spool input now consumes different files with the same name. (SPL-14536)
-
indexes.conf is now deployable. (SPL-14480)
-
Break_before_date in props.conf is now functional. (SPL-14363)
- All file types now show the correct timestamp in Splunk Web. (SPL-14347)
- Custom timerange now resets correctly when starting a new search. (SPL-14142)
- Subsearches that return 0 results are no longer ignored in the search pipeline. (SPL-14006)
- The User role can now search distributed search instance without
allow_livetail capability enabled. (SPL-13828)
- LDAP user DN to group member entry mapping is no longer case sensitive. (SPL-13752)
- Event type attribute values are no longer case-sensitive. (SPL-13577)
- Eventtypes with complex phrasing are now searchable and reportable. (SPL-11340)
- Auto tImestamp extraction now recognizes AM & PM in event data. (SPL-13736)
- The
filter option in the file system change monitor now works on Windows. (SPL-13610)
- The deployment server now restarts Splunk Web. (SPL-13281)
- The send email script no longer sends 2 emails. (SPL-6892)
- The search
idxprobe now looks into colddb. (SPL-14124)
- Metrics now have a tunable parameter for the number of results in sample period. (SPL-14090)
- Splunk now auto-extracts fields for
| idxprobe tsidx. (SPL-14062)
- Pie charts now show values. (SPL-13755)
- You can now specify
-format csv if specifying -header false when searching. (SPL-13392)
- The source for UDP inputs is now set correctly. (SPL-13739)
- On Windows and AIX, Splunk was using an out of date Olsen database to determine proper timezone offsets. This database has been updated. (SPL-14347)
- If you are using IE6, you will no longer see an error dialog saying
Error: Can't move focus to the control because it is invisible, not enabled or of a type that does not accept the focus. (SPL-13331)
- Issues with assigning multiple graph types to a saved search have been resolved. (SPL-9893)
- Dashboard loading issues arising from a security fix in the 3.2.3 release of Splunk have been resolved. (SPL-13639, SPL-13656)
- Windows only: Splunk now picks up new and changed files correctly without needing to restart. (SPL-14281)
- Windows only: Typeahead now correctly escapes '\' in Windows file-path. (SPL-14095)
- Windows only:
coldToFrozenScript = echo $DIR in indexes.conf now functions correctly. (SPL-14008)
- Windows Event Logs are input correctly when "Run Splunk" is unchecked at the end of the installation. (SPL-14121)
- Regexes with backslashes in them are now supported when specifying paths to files. (SPL-12679)