3.3.1
This documentation does not apply to the most recent version of Splunk.
This documentation applies to the following versions of Splunk:
3.3.1 , 3.3.2 , 3.3.3 , 3.3.4
3.3.1
The following issues have been resolved in this release of Splunk.
- The Power user role now allows use of Live Tail. (SPL-15337)
- Configuration files deployed by the Deployment server to
/usr/local now properly take precedence over other configuration files. (SPL-15204)
- Permissions for directories created by the Linux .rpm installation are now set correctly. (SPL-15198)
- Correct time is now displayed on AIX systems when not using Daylight Savings Time. (SPL-15114)
- An issue with data crossover between indexes when using the summary indexing feature has been resolved. (SPL-14936)
- Splunk now logs all successful login attempts rather than just the first one. All logout and login failure continue to be logged correctly. (SPL-14960)
- The User role can no longer add schedules to existing saved searches. (SPL-14867)
- Piping a search to timechart and sorting results according to tag value now works correctly. (SPL-14850)
- Debian package installation now completes correctly. (SPL-14934)
- The Back button now functions correctly when viewing reports. (SPL-14283, SPL-10705)
- Splunk no longer crashes if you fail to specify a valid value for
groupNameAttribute ( = cn) in authentication.conf when configuring an LDAP server. (SPL-13562)
- An issue with columns not being sorted correctly when you have only one row of results has been resolved. (SPL-14810)
- Distributed search now functions correctly across indexes. (SPL-14807)
- Splunk's LDAP integration now correctly handles spaces in a dn definition. (SPL-14718)
- XML output for REST endpoint queries against search results now displays full set of results. (SPL-14701)
- The file system change monitor feature now displays file permissions in octal rather than hex. (SPL-14352)
- Round-robin forwarding configuration now functions correctly when one of the Splunk servers stops and restarts. (SPL-13673)
- The
$SPLUNK_HOME/share/splunk/search_oxiclean/rss directory permissions on install have been corrected so RSS feeds can be created. (SPL-10695)
Windows-specific issues
- Multiple issues with migration from earlier versions of Splunk for Windows have been resolved. (SPL-14906)
- An issue with display of dashboards on reload of main Splunk Web page has been resolved. (SPL-15027)
- Changing the user Splunk runs as now works. (SPL-14871)
- Saving a search using the drop-down menu now correctly saves the alert properties for the alert. (SPL-14753)
- Splunk Alerts now support .bat scripts. (SPL-15012)
- The Message field is now extracted correctly in Windows Event Logs. (SPL-15064, SPL-15063)
- The ComputerName field is now displayed correctly for all Windows Event Logs. (SPL-15056)
- The SourceName is now extracted correctly for Windows Event Logs. (SPL-15055)
- Custom values for host set in
inputs.conf are no longer overwritten by localhost. (SPL-14997)
- Custom values of index set in
indexes.conf are now honored. (SPL-14996)