4.0.4
This documentation applies to the following versions of Splunk:
4.0.4 , 4.0.5 , 4.0.6
4.0.4
The following issues have been resolved in this release of Splunk:
Resolved general issues
- This release contains numerous localization and internationalization fixes, extensions, and improvements.
- Splunk now runs correctly on unpatched versions of AIX 5.2. (SPL-26227)
- Splunk now reads tsidx files originally created in version 2.x correctly. (SPL-26169)
- An issue related to moving data buckets from 'cold' state to a 'frozen' state has been resolved. (SPL-26125)
- An issue with cold-to-frozen script failing has been resolved. (SPL-25810)
- DATETIME_CONFIG=CURRENT is now respected for files whose names include the date. (SPL-26311)
- An error involving out of range cron values when editing a saved search has been resolved. (SPL-26309)
- An issue with corrupted tcpout_connections messages in metrics.log has been resolved. (SPL-25807)
- An issue with the "business_week_to_date" timerange and timezones ahead of GMT has been resolved. (SPL-25629)
- An intermittent issue with AD LDAP auth not returning all the users when realNameAttribute = cn has been resolved. (SPL-25462)
- Running
clean globaldata now correctly deletes the files under fishbucket/db/. (SPL-25860)
- The
export eventdata command now functions correctly. (SPL-25804)
- The interactive field extractor now correctly escapes pipes (|) in the regex. (SPL-25793)
- An issue with sample events being overwritten in the interactive field extractor has been resolved. (SPL-25488)
- The 'delete' operator now works correctly on events timestamped in the future. (SPL-24676)
Resolved Splunk Web and Manager issues
- The timeline scale has been reinstated in Splunk Web. (SPL-25913)
- Results are no longer sent as part of an alert email when the box is unchecked in Manager. (SPL-25862)
- Firebug logging is less noisy. (SPL-25729)
- Clicking through transaction results no longer breaks the search string. (SPL-25697)
- The timerange calendar popup in Splunk Web now uses the server timezone (not the browser timezone). (SPL-25532)
- The indexing status dashboard now includes a module with information about license usage. (SPL-25518)
- The show source feature now works. (SPL-25868)
- Usernames are no longer case-sensitive in Splunk Web. (SPL-25903)
- Finalizing a search on the job status page in Manager now works immediately. (SPL-25561)
- Default time range options now display more compactly in Splunk Web. (SPL-25201)
- Issues with seemingly random Splunk Web timeouts have been resolved. (SPL-24389)
- The interface for restricting TCP inputs to one host has been added back into Manager. (SPL-24376)
- Disabling and re-enabling Splunk Web from the CLI now works correctly. (SPL-25669)
- Occasional "Timed out waiting for splunkweb to start" issue on 32-bit Solaris has been resolved. (SPL-26355)
- Changing the timerange on a search that has been run via a permalink no longer runs a search for *. (SPL-26319)
- The automatic source type option is no longer erroneously available in Manager for network inputs (UDP, TCP). (SPL-25549, SPL-22451)
- The Help link for the launcher now works in Firefox 3.5. (SPL-25486)
Resolved deployment server/client, and forwarder issues
- Enabling SplunkForwarder, SplunkLightForwarder, SplunkDesktop no longer disables deployment server and client functionality. (SPL-26024, SPL-26000)
- Deployment server now deploys to NATed clients. (SPL-26237)
- An issue with deployment clients not picking up Apps from deployment server has been resolved. (SPL-26058)
- New versions of Apps are now correctly deployed; default.meta is correctly overwritten. (SPL-25716)
- Deployment server now respects permissions of deployed files. (SPL-25715, SPL-24168)
- The "round robin" forwarder configuration now supports SSL. (SPL-18873)
- The syslog routing forwarder configuration is now working properly. (SPL-26153)
- The syslog routing forwarder configuration no longer appears to send an extra event to the syslog receiver (an empty line). (SPL-24995)
Resolved Windows-specific issues
- Splunk Web no longer shuts down when a user logs out of Windows. (SPL-25861)
- Splunk properly completes the uninstall when uninstalling on Windows 7. (SPL-26087)
- An issue with not being able to enable just WMI inputs during a commandline install has been resolved. (SPL-25869)
- Adding an input in Splunk Web on Windows now formats the stanza correctly in inputs.conf. (SPL-25857)
- Windows event log events are formatted correctly when viewed in Firefox. (SPL-26279)
- A crash on Windows related to changing Windows Event Log inputs while Security logs are being processed has been resolved. (SPL-25912)
- Disabling Windows Event Log inputs in Manager no longer throws an exception. (SPL-25874)
- Windows events now correctly display the "Event ID" label instead of "Event Code". (SPL-25604)
- A crash on Windows when removing TCP inputs using Manager has been resolved. (SPL-25500)
- Active Directory monitoring (ADmon) now respects the targetDC value specified in admon.conf. (SPL-25401)
Resolved App and App development issues
- The Windows App now uses summary indexing for front page displayed searches. This improves the performance. (SPL-26258)
- The Windows App has been updated to remove event types and searches that are not applicable to some Windows platforms. (SPL-26097)
- Enabling the *Nix App on a Windows host does not throw a "There is no query runner registered" error and will allow searching. (SPL-25598, SPL-25575)
- An issue with enabling previously disabled deployed Apps has been resolved. (SPL-25717)
- An issue with usage of vmstat.sh in the *Nix App on Solaris 9 has been resolved. (SPL-26019)
- Display organization of available views is now configurable the way it is for saved searches. (SPL-26267)
- Improperly structured XML in dashboards no longer causes tracebacks. (SPL-25864)
- Scripts that run as part of an App are now stopped when you disable the App. (SPL-25631)