1/11/2024 0 Comments Splunk lookup threshold![]() Buckets are occasionally named with an incorrect timerange, which makes them unsearchable.The panel correctly shows the results (under the progress indicator) but the progress indicator shows that the search has not yet completed (even though it has). Splunk fails to hide the job progress indicator on some dashboard panels even after the search job has completed.Dynamic, time-sensitive lookup table is not returning expected results.Erroneous “non-SSL content” warnings on login screen.A crash in the splunk-optimize process with “Integer Divide by Zero” in the crash dump has been resolved.Some strings in the “Build event type” screen are not localizable.Command arguments are now output in crash logs for easier diagnosis.The preview_freq setting in nf (which controls how frequently the real-time window of a search is updated) was not being honored.The interactive field extractor (IFX) now works correctly in IE7 and IE8.This is intended to resolve performance bottlenecks in situations where there is a large amount of metadata being processed. A per-index serviceMetaPeriod option has been added to nf so you can set how often metadata files (mappings of host, source, sourcetype to numeric IDs) get written to disk.Preview of large sets of results when using the concurrency search command is not working correctly and will ultimately display 0 results when the search completes.The default value of maxvalues in nf has been set to 0 so that distinct count searches return an unlimited number of values.No changes have been made to the terms of the agreement. The formatting of EULA (license-eula.txt) has been improved, and minor clarifications made.Forwarders crashing after propagation of new nf changes deployment topology from single indexer to two indexers with autoLB.Running a real-time search that uses a lookup table over a long period (Users with edit_user capability can now list users.Unauthorized users can create Windows Event Log inputs an error message stating the addition failed is displayed, but the input is created.ADmon does not retrieve all the contents if the number of records in Active Directory is more than ~1000.A crash in Splunk Web/CherryPy that writes “root:120 – ENGINE: Error in HTTP server” in the web-service.log has been resolved.The diff command no longer supports the -tofile argument.Splunk Web audit log now logs username when they log out.There’s a misleading success message if you edit a field alias and you don’t have the correct permissions (and your changes are not saved).The xmlkv command limited to 50K results.The same operation hangs when you use Splunk Web. Using the CLI to perform a distributed search to Windows Server 2008 R2 with a bundle having more than 8 lookup files fails.PDF printing is limited to only the admin user.Setting a large number of role attributes via Splunk Web may remove settings for that role.(The value of server.thread_pool under the stanza in $SPLUNK_HOME/etc/system/local/web.conf has been raised to 50.) This can result in users being unable to log into a new web session. Splunk Web may gradually degrade in performance if the number of concurrent active requests is greater than the thread threshold’s earlier default value of 10.Alt+Click does not include the escape character “\” when it’s needed.Pressing Enter on the interactive field extractor (IFX) “Save Field Extraction” form closes the form and does not save the field extraction.The splunkd.log file will show an error similar to “The event is missing source information”. Splunk can lose track of “source” information when monitoring compressed files.OpenSSL has been upgraded to 0.9.8p to address CVE-2010-3864.The following issues have been resolved in this release of Splunk: Splunk provides the ability for users to search, monitor and analyze live streaming IT data as well as terabytes of historical data, all from the same interface.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |