Splunk® Universal Forwarder

Forwarder Manual

Fixed issues

The following issues were fixed in releases of the universal forwarder.

9.4.1

Version 9.4.1 was released on February 26, 2025. This release fixes the following universal forwarder issues:

Universal forwarder issues

Date resolved Issue number Description
2024-11-20 SPL-265908, SPL-254532 UF 9.1.2 Windows Security events stop forwarding when Windows event log service is restarted
2024-11-19 SPL-265068, SPL-266372, SPL-266374, SPL-266375, SPL-266377 UF Windows installer re-grant user privileges during upgrade
2024-11-06 SPL-265633, SPL-265630 Windows Universal Forwarder high cpu where Splunk user does not have read access to all of the files in the monitored directory
2024-11-06 SPL-259202, SPL-265630 Windows Universal Forwarder high cpu where Splunk user does not have read access to all of the files in the monitored directory


If no issues are shown, there are no new Universal Forwarder specific fixes to highlight in this version.

9.4.0

Version 9.4.0 was released on December 16, 2024. This release fixes the following universal forwarder issues:

Universal forwarder issues

Date resolved Issue number Description
2025-03-12 SPL-248479, SPL-253092 Forwarders enter a state of constant blocking, and Splunk Cloud indexers may fail to process events. This can result in the events being sent to a non-searchable queue, the Dead Letter Queue (DLQ), due to a Persistent Queue issue with the S2S protocol


If no issues are shown, there are no new Universal Forwarder specific fixes to highlight in this version.

Last modified on 14 March, 2025
Known issues   Third-party software

This documentation applies to the following versions of Splunk® Universal Forwarder: 9.4.1


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters