Splunk Search

Subsearch doesn't work after upgrade to 4.3.6

lqiao
Explorer

Hi,

I have a search as follows:
query 1 [search query 2]

I find in the internet that Searches that contain subsearches do not return data in environments where search heads are running version 5.0.x and indexers are running version 4.3.x. To work around this issue, upgrade indexers to the same version as the search heads. (SPL-62457).

But our indexers are running version 4.3.5.2 and we upgraded search head to 4.3.6. Then the above search doesn't return any data any more. It works fine with search-head 4.3.5.2.

My problem is the same as known issue SPL-62457? If I upgrade indexer also to 4.3.6, this problem will disappear?

Thank you very much for your kink answer.
Lu

Tags (2)
0 Karma

lqiao
Explorer

I found an answer to my own question. This problem is a known issue for release 4.3.6. See below:

http://docs.splunk.com/Documentation/Splunk/4.3.6/ReleaseNotes/KnownIssues

•Searches that contain subsearches do not return data in environments where search heads are running version 4.3.6 and indexers are running prior to 4.3.6. To work around this issue, upgrade indexers to the same version as the search heads. (SPL-65120)

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...