Fixed issues
Splunk Enterprise 9.1.8 was released on February 26, 2025. This release includes fixes for the following issues.
Issues are listed in all relevant sections. Some issues might appear more than once.
Universal forwarder issues
Date resolved | Issue number | Description |
---|---|---|
2024-11-19 | SPL-265068, SPL-266372, SPL-266374, SPL-266375, SPL-266377 | UF Windows installer re-grant user privileges during upgrade |
2024-11-14 | SPL-265723, SPL-254532 | UF 9.1.2 Windows Security events stop forwarding when Windows event log service is restarted |
2024-11-06 | SPL-265630, SPL-259202, SPL-265631, SPL-265632, SPL-265633 | Windows Universal Forwarder high cpu where Splunk user does not have read access to all of the files in the monitored directory |
2024-11-06 | SPL-259202, SPL-265630 | Windows Universal Forwarder high cpu where Splunk user does not have read access to all of the files in the monitored directory |
Windows-specific issues
Date resolved | Issue number | Description |
---|---|---|
2024-11-08 | SPL-265859, SPL-265863, SPL-265864, SPL-265865, SPL-265866 | A missing CloseHandle() can lead to memory leaks |
2024-11-06 | SPL-259202, SPL-265630 | Windows Universal Forwarder high cpu where Splunk user does not have read access to all of the files in the monitored directory |
Uncategorized issues
Date resolved | Issue number | Description |
---|---|---|
2024-10-09 | SPL-263863, SPL-259311 | Delayed creation of knowledge bundle |
2024-10-03 | SPL-259311, SPL-263863, SPL-263864, SPL-263865, SPL-263866 | Delayed creation of knowledge bundle |
Field alias behavior change | Deprecated and removed in version 9.1 |
This documentation applies to the following versions of Splunk® Enterprise: 9.1.8
Feedback submitted, thanks!