Fixed issues
Splunk Enterprise 9.3.2 was released on November 7, 2024. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once.
Data input issues
Date resolved
|
Issue number
|
Description
|
2024-08-22 |
SPL-261041, SPL-258768 |
dropEventsOnUploadError setting is not respected for ingest actions file system destination
|
Search issues
Date resolved
|
Issue number
|
Description
|
2024-09-06 |
SPL-262305, SPL-253147 |
Crashing thread: TcpOutEloop
|
2024-09-02 |
SPL-261475, SPL-261629, SPL-261630, SPL-261631, SPL-261707, SPL-261708 |
Unable to search _cmc_summary index on classic stacks (also affects any search with index=_* which includes surrounding searches)
|
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2024-09-06 |
SPL-261924, SPL-260972 |
Limit adhoc rsa artifact lifespan to a default of 24 hours
|
2024-09-04 |
SPL-260972, SPL-253823, SPL-261923, SPL-261924, SPL-261927 |
Limit adhoc rsa artifact lifespan to a default of 24 hours
|
2024-08-29 |
SPL-259287, SPL-254139, SPL-262990 |
Low Privileges user is able to modify dispatchAs field from Owner to User
|
Universal forwarder issues
Date resolved
|
Issue number
|
Description
|
2025-03-12 |
SPL-248479, SPL-253092 |
Forwarders enter a state of constant blocking, and Splunk Cloud indexers might fail to process events. This can result in the events being sent to a non-searchable queue, the Dead Letter Queue (DLQ), due to a Persistent Queue issue with the S2S protocol
|
Windows-specific issues
Date resolved
|
Issue number
|
Description
|
2024-09-06 |
SPL-262275, SPL-262271 |
Fix perfmon counter capped at 100
|
Feedback submitted, thanks!