Splunk® Enterprise

Release Notes

Acrobat logo Download manual as PDF


Splunk Enterprise version 9.0 will no longer be supported as of June 21, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Fixed issues

Splunk Enterprise 9.0.3 was released on December 14, 2022. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Search issues

Date resolved Issue number Description
2022-10-18 SPL-231441, SPL-223053 eventstats will generate less results when time range is large
2022-10-04 SPL-230007, SPL-224695 lookup files, created by outputlookup command, don't show up under 'Lookup table files' if executed on a newly created app
2022-10-04 SPL-230682 Tstats returns incorrect event counts when using append=true
2022-10-03 SPL-230857, SPL-229969 regex doesn't honor the caret symbol ^ (start of string) in some conditions.

Federated search issues

Date resolved Issue number Description
2022-10-04 SPL-230682 Tstats returns incorrect event counts when using append=true

Charting, reporting, and visualization issues

Date resolved Issue number Description
2022-11-15 SPL-231315, SPL-214759, SPL-232576 Custom VIZ - data chunk duplication
2022-11-14 SPL-232576, SPL-231315 Custom VIZ - data chunk duplication
2022-11-14 SPL-231838 Form fieldset input choice strings are not localized
2022-11-02 SPL-230996, SPL-217434 custom viz never receive meta.data.done = true with base post search

Indexer and indexer clustering issues

Date resolved Issue number Description
2022-10-13 SPL-228672, SPL-231396 validation of bundle returns "restart required" always on any app when there is a password field with encrypted bundles

Universal forwarder issues

Date resolved Issue number Description
2023-04-14 SPL-232147 Debian package failed to start on armv8 agent `re-pkg-arm64`
2023-03-28 SPL-237740, SPL-226003 When forwarding from an 9.0 instance with useAck enabled, ingestion stops after some time with errors: "Invalid ACK received from indexer="
2022-11-14 SPL-231927, SPL-227653 UF throws erroneous WARN for KVSTORE SSL misconfiguration on startup - server.conf//sslVerifyServerCert or "Starting migrate-kvstore."
2022-11-02 SPL-231793 Crashing in TcpOutEloop thread with assertion_failure="_refCount > 0"
2022-10-12 SPL-227653, SPL-231927 UF throws erroneous WARN for KVSTORE SSL misconfiguration on startup - server.conf//sslVerifyServerCert or "Starting migrate-kvstore."
2022-09-07 SPL-226003, SPL-237740 When forwarding from an 9.0 instance with useAck enabled, ingestion stops after some time with errors: "Invalid ACK received from indexer="

Monitoring Console issues

Date resolved Issue number Description
2022-11-09 SPL-231337, SPL-212019 Splunk Deployment Health on searchhead is Red and its status stuck in red

Splunk Web and interface issues

Date resolved Issue number Description
2022-11-14 SPL-231838 Form fieldset input choice strings are not localized

Admin and CLI issues

Date resolved Issue number Description
2022-11-01 SPL-230129, SPL-228453 After upgrade to 9.0.0.1 setSplunkEnv broken with error Warning:: command not found

Uncategorized issues

Date resolved Issue number Description
2022-11-10 SPL-232457, SPL-232588 Crashing thread: TcpOutEloop caused by No memory mapped at address
2022-10-31 SPL-223475, SPL-190358 Monitoring console Index Usage for maxTotalDataSizeMB does not handle SmartStore
2022-10-18 SPL-228392, SPL-228391 Data intended for Summary Indexes may be be misrouted to the default "main" index and lead to incomplete search results for searches using the Summary Index.
2022-10-10 SPL-231139, SPL-228404 Following upgrade to 9.0 customer HF blocks queues when Ingestion latency bug hits
2022-07-13 SPL-226400, SPL-226485 Queues blocked infinitely with useACK and autoBatch.
Last modified on 17 November, 2023
PREVIOUS
Field alias behavior change
  NEXT
Deprecated and removed in version 9.0

This documentation applies to the following versions of Splunk® Enterprise: 9.0.3


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters