This page last updated: 10/13/08 01:10pm
3.3.3
The following issues have been resolved in Splunk version 3.3.3:
- Executing the Splunk CLI command set server-type default after set server-type forwarder no longer leaves internal logging disabled. (SPL-16568)
- A crash related to high maxresults setting has been resolved. (SPL-16504)
- Various crashes related to HTTPRequestHandlerThread have been resolved (SPL-16475, SPL-15862)
- A crash related to indexpiperthread has been resolved. (SPL-15861)
- A listtails crash issue has been resolved. (SPL-16438).
- File system change monitor now properly recognizes sendEventMaxSize settings. (SPL-16352)
- The metadata command now works correctly when searching any specified index. (SPL-16312)
- When drilling down on host, source, or source type, the time range is no longer defaulted to "all time". (SPL-16204)
- A crash on startup related to deploying forwarders using the deployment server has been resolved. (SPL-16149)
- Forwarding machines will not crash if the deployment server crashes. (SPL-15877)
- Splunk now correctly recognizes the RFC3164-complaint <PRI> part of syslog messages. New key=value is no_appending_timestamp=<true|false>. This setting defaults to 'true'. (SPL-16129)
- An issue with the savedsearch command not reliably returning results has been resolved. (SPL-16091)
- A crash on 64-bit RedHat has been resolved. (SPL-16017)
- Splunk now correctly tokenizes items separated by a comma with a space after it. (SPL-16016)
- The default value for maxresults in savedsearches.conf is now 10,000 for 32-bit systems and 50,000 for 64-bit systems. (SPL-16007)
- Using ctable, counttable, and contingency when not in the Reports view now takes you to the Reports view. (SPL-15958)
- A crash related to PollDeploymentServerThread on forwarders has been resolved. (SPL-15877)
- Searching for events that don't contain any value for a specified item, as well as searching for ones where != value is now supported. (SPL-15868)
- Line breaking rules are now correctly applied to UDP inputs. (SPL-15598)
- A 64-bit-compatible version of the chroot package is now available for download. (SPL-13191)
- Transaction search now displays all matching lines in Splunk Web (SPL-13151)
Windows-specific issues
- Splunk now parses the Windows Event Log "message" field correctly. (SPL-16119)
- The exporttool command now works correctly on Windows. (SPL-15956)
- The Windows version of Splunk now includes the automated archiving scripts. (SPL-15940)
- The show source function now supports spaces in the filepath to the source. (SPL-15921)
- Splunk now correctly continues to retrieve data via WMI from remote WMI sources that have had their event log files backed up. (SPL-15911)
- The Browse button now is displayed correctly when uploading a local file through Splunk Web on IE7. (SPL-15867)
- Multi-line Windows Event Log events are now displayed correctly. (SPL-15471)
Comments
No comments have been submitted.