This page last updated: 02/12/07 01:02pm
2.1.1 Release Notes
To install Splunk 2.1.1, see the Installation Manual for full instructions.
New Features
- The automatic update notice can be disabled.
- Splunk's command line can display License & Usage info.
- Splunk-2-Splunk discovered servers can be listed from the command line.
Resolved issues
- The multiple index pulldown menu has been restored.
- Hostname extracton for UDP syslog events will not truncate hostnames.
- Power users are able to create tags and rename sourcetypes without error.
- Adding an extra '/' in the index directory path will no longer cause problems.
- ODBC input now reads beyond the first 999 events on Oracle databases.
- Chained hosts in syslog events will now have the original hostname extracted correctly.
- Some Windows logs had been incorrectly classified as binary format. This is fixed.
- Saved Splunks with long search terms are now displayed properly in the Web interface.
- Under heavy server loads, search results will remain correctly sorted without affecting performance.
- Saved Splunks with spaces next to parentheses in their search terms, such as ( syslogd AND shutdown ), will work correctly.
- Setting the HTTP listening port to 0 disables the service, as intended by most admins.
- The Admin interface error "Unable to create initial Live Splunk" has been fixed.
- Live Splunks running a script as an alert action will now call the script when it resides $SPLUNK_HOME/bin/scripts/.
Known Issues
- Solaris users should not attempt to migrate a 2.0 index to 2.1.1 using the native package installation. Use the tarball installation instead. Native package installation on Solaris works fine, as does updating from 2.1 to 2.1.1. Only 2.0 -> 2.1.1 migration of the index on Solaris requires the tarball installation. Follow the migration instructions.
- Migration of 2.0 indexes over 100 million events will not work. Follow the instructions for a parallel installation instead.
- Internet Explorer 7 users may see "can't connect to splunk.com" notices in the Splunk Web interface. This is because the automatic update notice does not work properly with IE7.
- Internet Explorer 7 users will have problems with Splunk-2-Splunk distributed search mode. Specifically, the host list does not appear properly on the main page of the Splunk interface. Toggling the host list dropdown a few times will not help. We are working on a fix.
- Some customers may find that their splunkweb process terminates abruptly. Use the shell command "splunk restart splunkweb" to restart the Web interface. If the problem recurs, set up a monitor process to watch and restart the splunkweb process (the built-in splunkmon command only monitors the splunkd process.)
- Customers with thousands of .tar.gz files may experience slow performance. We are working on a fix or a workaround.
Comments
No comments have been submitted.