Splunk® Enterprise

Release Notes

Splunk Enterprise version 9.0 will no longer be supported as of June 14, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.0.6 was released on August 30, 2023. This release includes fixes for the following issues. It also delivers relevant updates from the 2023-08-30 Security Advisories list.

Issues are listed in all relevant sections. Some issues might appear more than once.

Search issues

Date resolved Issue number Description
2023-07-07 SPL-241609, SPL-227018 In rare cases in some buckets, searches can return some empty field values or missing events for indexed fields when the bucket contains small metadata files (between 4-8KB) leading to "not all cwpairs were found" in search.log

Charting, reporting, and visualization issues

Date resolved Issue number Description
2023-08-01 SPL-241621 After upgrading to Splunk 9.0.x, dashboards are slow to load

Distributed search and search head clustering issues

Date resolved Issue number Description
2023-07-13 SPL-241835, SPL-218169 For alerts with per-result throttling (suppression) in SHC, sometimes, based on timing, the originating SH that ran the seach will show different results (suppressed) than the replicated artefacts on other SHs (unsuppressed)
2023-07-12 SPL-218169, SPL-241835, SPL-241836 For alerts with per-result throttling (suppression) in SHC, sometimes, based on timing, the originating SH that ran the seach will show different results (suppressed) than the replicated artefacts on other SHs (unsuppressed)

Universal forwarder issues

Date resolved Issue number Description
2023-08-08 SPL-240820, SPL-242100, SPL-242101, SPL-242102, SPL-242103 Windows EventLog splunk-winevtlog.exe modular input crashing during AD object resolution

Splunk Web and interface issues

Date resolved Issue number Description
2023-07-11 SPL-241706, SPL-240758 "File Integrity checks found 4281 files that did not match the system-provided manifest." shows in message but does not appear in the "Integrity Check of Installed Files" dashboard.

Windows-specific issues

Date resolved Issue number Description
2023-08-08 SPL-240820, SPL-242100, SPL-242101, SPL-242102, SPL-242103 Windows EventLog splunk-winevtlog.exe modular input crashing during AD object resolution

Uncategorized issues

Date resolved Issue number Description
2023-05-23 SPL-234643 Splunkd abort - due to 3rd party S2S client unable to process ACKs.
Last modified on 31 October, 2023
Field alias behavior change   Deprecated and removed in version 9.0

This documentation applies to the following versions of Splunk® Enterprise: 9.0.6


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters