Splunk® Enterprise

Release Notes

Splunk Enterprise version 9.0 will no longer be supported as of June 14, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.0.5.1

Splunk Enterprise 9.0.5.1 was released on July 31, 2023. It delivers the update described in https://advisory.splunk.com/advisories/SVD-2023-0606.

Splunk Enterprise 9.0.5

Splunk Enterprise 9.0.5 was released on May 30, 2023. This release includes fixes for the following issues. It also delivers relevant updates from the 2023-06-01 Security Advisories list.

Issues are listed in all relevant sections. Some issues might appear more than once.

Data input issues

Date resolved Issue number Description
2023-04-12 SPL-235416 Case sensitive sourcetypes in Ingest Actions UI preview won't fetch results

Search issues

Date resolved Issue number Description
2023-05-02 SPL-237204, SPL-235493 iplocation command using improper mmdb file after upgrade from 8.1.1 to 9.0.2
2023-04-06 SPL-231830, SPL-239319, SPL-239320 SearchJob sometimes fails and returns error "Search <ID> not found. The search may have been cancelled while there are still subscribers"

Federated search issues

Date resolved Issue number Description
2023-05-04 SPL-239361, SPL-237883 Transparent Mode federated search - Using table and stats in the same federated search causes the search to return empty results , when run in smart or fast mode

Charting, reporting, and visualization issues

Date resolved Issue number Description
2023-05-26 SPL-240369, SPL-230171 Charts not showing in SimpleXML dashboard PDF export
2023-03-17 SPL-236371, SPL-228658 "Down Arrow" of chart legend scrolling does not work
2023-03-14 SPL-237216, SPL-236548 SXML dashboards without the "version=" stanza in the search app may have <set>..</set> tags changed to <set /> when upgrading to 9.0.3 or 9.0.4
2022-12-01 SPL-228658, SPL-236371, SCP-57718 "Down Arrow" for chart legend scrolling does not work

Indexer and indexer clustering issues

Date resolved Issue number Description
2023-03-17 SPL-235761, SPL-207384 Searches return incomplete results during addPeer/BatchAdding after CM restart.

Universal forwarder issues

Date resolved Issue number Description
2023-03-15 SPL-236429 Universal forwarder download for PPCLE kernel 3.0+ is unavailable for version 9.0.2, 9.0.3, 9.0.4
2023-03-01 SPL-236166, SPL-232028 Windows Defender logs stop being forwarded but other Winevent logs continue to forward until UF is restarted
2023-02-27 SPL-236097, CSPL-2216, SPL-236361, SPL-240877 UF 9.0.x migration fails when systemd errors especially in Docker Containers

Splunk Web and interface issues

Date resolved Issue number Description
2023-04-13 SPL-238486, SPL-235850 ui-prefs optimizations - Only use browser-based storage for ui-prefs
2023-04-06 SPL-231830, SPL-239319, SPL-239320 SearchJob sometimes fails and returns error "Search <ID> not found. The search may have been cancelled while there are still subscribers"

Windows-specific issues

Date resolved Issue number Description
2023-03-01 SPL-236166, SPL-232028 Windows Defender logs stop being forwarded but other Winevent logs continue to forward until UF is restarted
Last modified on 26 January, 2024
Field alias behavior change   Deprecated and removed in version 9.0

This documentation applies to the following versions of Splunk® Enterprise: 9.0.5


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters