Fixed issues
Splunk Enterprise 9.2.4 was released on November 7, 2024. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once.
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2024-09-06 |
SPL-261923, SPL-260972 |
Limit adhoc rsa artifact lifespan to a default of 24 hours
|
2024-09-04 |
SPL-260972, SPL-253823, SPL-261923, SPL-261924, SPL-261927 |
Limit adhoc rsa artifact lifespan to a default of 24 hours
|
2024-08-29 |
SPL-259283, SPL-254139, SPL-262989 |
Low Privileges user is able to modify dispatchAs field from Owner to User
|
Universal forwarder issues
Date resolved
|
Issue number
|
Description
|
2025-03-12 |
SPL-248479, SPL-253092 |
Forwarders enter a state of constant blocking, and Splunk Cloud indexers might fail to process events. This can result in the events being sent to a non-searchable queue, the Dead Letter Queue (DLQ), due to a Persistent Queue issue with the S2S protocol
|
Windows-specific issues
Date resolved
|
Issue number
|
Description
|
2024-09-06 |
SPL-262274, SPL-262271 |
Fix perfmon counter capped at 100
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2024-10-09 |
SPL-263864, SPL-259311 |
Delayed creation of knowledge bundle
|
2024-09-03 |
SPL-260042, SPL-257330 |
Fix the security vulnerabilites
|
2024-08-28 |
SPL-258019, SPL-261246, SPL-261247 |
User 'nobody' should be excluded from check when SAML settings applies
|
Feedback submitted, thanks!