Splunk® Enterprise

Release Notes

This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.1.5 was released on July 1, 2024. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.


Search issues

Date resolved Issue number Description
2024-03-20 SPL-248297 Higher memory usage than usual on Windows systems after upgrade from Splunk Enterprise version 9.0/8.x to version 9.1.x/9.2.x

Federated search issues

Date resolved Issue number Description
2024-04-26 SPL-254718, SPL-253248, SPL-255069 Federated searches not completing with error "Socket error during transaction. Socket error: Success"
2024-04-22 SPL-254539, SPL-253986 Transparent Federated Search should not ignore federated service account index permission when fsh user is set to SPLUNK_SYSTEM_USER
2024-03-25 SPL-252487, SPL-248786 Lookups in transparent mode don't use proper lookup when fsh and rsh have lookup with same name
2024-03-07 SPL-248311, SPL-242049 Kvstore files are not converted to csv files in the bundles when local indexers are not present even when remote providers are present

Distributed search and search head clustering issues

Date resolved Issue number Description
2024-04-05 SPL-253661, SPL-253660, SPL-253665 Job Artifacts appear getting deleted unexpectedly

Indexer and indexer clustering issues

Date resolved Issue number Description
2024-04-23 SPL-253649, SPL-246435 Rolling Restart generate fix-up task that search factor taking hours complete as search files replication fails.

Universal forwarder issues

Date resolved Issue number Description
2024-03-13 SPL-252445, SPL-245954 UF memory utilization by splunk-winevtlog.exe increases until resources are exausted on Domain Controller
2024-03-12 SPL-245954, SPL-252444, SPL-252445, SPL-252446 UF memory utilization by splunk-winevtlog.exe increases until resources are exausted on Domain Controller

Uncategorized issues

Date resolved Issue number Description
2024-09-04 SPL-239645 Cascading bundle replication stops due to an outage of an indexer and SH Captain does not generate new KO bundles till restarted or captaincy is transferred to another SH member
2024-03-14 SPL-252572, SPL-251434 Crashing Thread: typing_0 in Heavy Forwarder
Last modified on 17 October, 2024
Field alias behavior change   Deprecated and removed in version 9.1

This documentation applies to the following versions of Splunk® Enterprise: 9.1.5


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters