Splunk® Universal Forwarder

Forwarder Manual

This documentation does not apply to the most recent version of Splunk® Universal Forwarder. For documentation on the most recent version, go to the latest release.

Fixed issues

The following issues were fixed in releases of the universal forwarder.


Version 9.2.1 was released on March 27, 2024. This release fixes the following universal forwarder issues. It also delivers relevant updates from the 2024-03-27 Security Advisories list.

Universal forwarder issues

Date resolved Issue number Description
2024-03-21 SPL-248587, SPL-252796, SPL-252797 Unable to install or upgrade to Splunk Universal Forwarder version 9.1.3
2024-02-23 SPL-251517, SPL-237849 CHECK_METHOD = modtime not working as expected in ver. 9.0.4 upgrading from 8.2.7.
2023-11-09 SPL-246709, SPL-245467 Global OPENSSL_CONF Env caused pre-flight check failure during installation

Version was released on February 8, 2024. This release introduces no changes to universal forwarder functionality. This release is provided only for version parity with Splunk Enterprise, which fixes the one issue described in Splunk Enterprise fixed issues.


Version 9.2.0 was released on January 31, 2024. This release fixes the following universal forwarder issues:

Universal forwarder issues

Date resolved Issue number Description
2023-11-03 SPL-245807, SPL-246456, SPL-246545, SPL-246546 Splunk AIX UF crashing when failed to connect to indexers
2023-11-02 SPL-246546, SPL-245807 Splunk AIX UF crashing. Crashing thread: TcpOutEloop
2023-10-24 SPL-244414 Crashing in TcpOutEloop thread after upgrade from 9.1.x
Last modified on 16 July, 2024
Known issues   Third-party software

This documentation applies to the following versions of Splunk® Universal Forwarder: 9.2.1

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters