Fixed issues
Splunk Enterprise 9.0.2 was released on November 2, 2022. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once.
Data input issues
Date resolved
|
Issue number
|
Description
|
2022-09-09 |
SPL-217790 |
INGEST_EVAL using numbers adds up to license
|
2022-09-09 |
SPL-229853, SPL-229208 |
PowerShell Modular input stopped working after UF 9.0 upgrade
|
Search issues
Date resolved
|
Issue number
|
Description
|
2022-08-19 |
SPL-227728, SPL-226351 |
Mcatalog subsearch hitting maxout limit preventing metric rollup from populating results correctly.
|
2022-08-16 |
SPL-228048, SPL-217977 |
Splunk crashes on Crashing thread: BucketSummaryActorThread for specific users and searches related to lookups
|
Federated search issues
Date resolved
|
Issue number
|
Description
|
2022-08-19 |
SPL-227530, SPL-234988 |
Splunk-to-Splunk federated search: After upgrade, the remote search head gets stuck in a loop of transferring proxy bundles to the remote indexers and failing
|
Saved search, alerting, scheduling, and job management issues
Date resolved
|
Issue number
|
Description
|
2022-09-09 |
SPL-228900, SPL-220208 |
Summary Director consuming excessive amounts of CPU and RAM in certain situations
|
2022-08-17 |
SPL-220208, SPL-228900, SPL-223021, SPL-223025, SPL-226444, SPL-228628 |
Summary Director consuming excessive amounts of CPU and RAM in certain situations
|
Charting, reporting, and visualization issues
Date resolved
|
Issue number
|
Description
|
2022-08-16 |
SPL-227909, SPL-228844 |
Inconsistent behavior for new dashboard with showing/not showing data/search results from default token
|
2022-08-04 |
SPL-227157, SPL-226132 |
User with format phxxxx cannot open a dashboard on 9.x
|
Distributed search and search head clustering issues
Date resolved
|
Issue number
|
Description
|
2022-09-29 |
SPL-229744, SPL-226835 |
cl-core-prod - tags are only showing 1 eventtype on the SH UI which are causing dashboards/searches to fail
|
2022-09-21 |
SPL-222917, SPL-230428 |
Crash in indexer discovery service on search head
|
2022-09-12 |
SPL-227395, SPL-228155 |
Deployer push is taking longer time
|
Data model and pivot issues
Date resolved
|
Issue number
|
Description
|
2022-09-09 |
SPL-228900, SPL-220208 |
Summary Director consuming excessive amounts of CPU and RAM in certain situations
|
2022-08-17 |
SPL-220208, SPL-228900, SPL-223021, SPL-223025, SPL-226444, SPL-228628 |
Summary Director consuming excessive amounts of CPU and RAM in certain situations
|
Universal forwarder issues
Date resolved
|
Issue number
|
Description
|
2022-09-21 |
SPL-222917, SPL-230428 |
Crash in indexer discovery service on search head
|
2022-09-09 |
SPL-229853, SPL-229208 |
PowerShell Modular input stopped working after UF 9.0 upgrade
|
Admin and CLI issues
Date resolved
|
Issue number
|
Description
|
2022-09-06 |
SPL-226016, SPL-226271, SPL-229579 |
Splunk crashed with SplunkConfigChangeWatcherThread if there is a symbolic link to a directory while config_change_tracker is enabled
|
Uncategorized issues
Date resolved
|
Issue number
|
Description
|
2022-10-03 |
SPL-229884, SPL-219397 |
Workload Management causing splunkd to hang for minutes when enabled. WorkloadManagementRunnerThread - performMonitoringAction_locked trans.runSync() failed
|
2022-09-09 |
SPL-228227, SPL-216816 |
Splunk 8.2.4 Splunkd.service file is referencing non-existing paths when cgroup-v2 is used (kernel v 5.0+)
|
2022-09-01 |
SPL-222543, SPL-224946 |
Unable to generate diag - "UnicodeDecodeError: 'utf-8' codec can't decode byte XxXX in position YY: invalid start byte"
|
Feedback submitted, thanks!