Splunk® Enterprise

Release Notes

This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.1.3 was released on January 22, 2024. This release includes fixes for the following issues. It also delivers relevant updates from the 2024-01-22 Security Advisories list.

Issues are listed in all relevant sections. Some issues might appear more than once.


Data input issues

Date resolved Issue number Description
2023-11-09 SPL-246769, SPL-243845 HTTP Input HEC input ignores _meta in inputs.conf

Search issues

Date resolved Issue number Description
2023-11-07 SPL-246383, SPL-246534, SPL-246535, SPL-246536, SPL-246537, SPL-246538, SPL-246539 Excessive logging in AuditLogger of "action=admin_all_objects, info=denied" after upgrade from 9.0.4 to 9.1.1
2023-10-24 SPL-246047, SPL-190401 Crash in NewTransamProcessor
2023-10-10 SPL-245341, SPL-239942 Fix the issue that splunk search cannot be finalized when indexer is slow

Federated search issues

Date resolved Issue number Description
2024-01-02 SPL-237796, SPL-248319 In transparent mode Federated Search for Splunk, the makeresults command returns more rows than expected

Charting, reporting, and visualization issues

Date resolved Issue number Description
2023-11-08 SPL-244788, SPL-247096, SPL-247097 "Awaiting user confirmation" error when img src is a token that is set to a URL after SXML dashboard loads

Distributed search and search head clustering issues

Date resolved Issue number Description
2023-10-24 SPL-246047, SPL-190401 Crash in NewTransamProcessor

Universal forwarder issues

Date resolved Issue number Description
2023-11-09 SPL-246708, SPL-245467 Global OPENSSL_CONF Env caused pre-flight check failure during installation
2023-11-02 SPL-246545, SPL-245807 Splunk forwarder crashing on AIX when failed to connect to indexers
2023-10-27 SPL-246142, SPL-233334 Warnings "user splunk does not exist" observed while installing rpm builds for Universal Forwarder
2023-10-24 SPL-244414 Crashing in TcpOutEloop thread after upgrade from 9.1.x

Uncategorized issues

Date resolved Issue number Description
2023-12-15 SPL-248187, SPL-248140 Slow indexer detection calculate send queue bytes
2023-11-17 SPL-246640 web.conf server.socket_host no longer overrides splunk-launch.conf SPLUNK_BINDIP
2023-11-09 SPL-246766, SPL-245974 HTTP Event Collector s2s endpoint ignores all inputs.conf.spec.
Last modified on 20 June, 2024
Field alias behavior change   Deprecated and removed in version 9.1

This documentation applies to the following versions of Splunk® Enterprise: 9.1.3


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters