Splunk® Enterprise

Release Notes

This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.2.2 was released on July 1, 2024. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Upgrade issues

Date resolved Issue number Description
2024-07-15 SPL-251301 Unable to install/upgrade Splunk Enterprise & UF RPM package v9.2.x on the same server.

Search issues

Date resolved Issue number Description
2024-03-20 SPL-248297 Higher memory usage than usual on Windows systems after upgrade from Splunk Enterprise version 9.0/8.x to version 9.1.x/9.2.x

Federated search issues

Date resolved Issue number Description
2024-04-26 SPL-254719, SPL-253248 Federated searches not completing with error "Socket error during transaction. Socket error: Success"
2024-04-22 SPL-254540, SPL-253986 Transparent Federated Search should not ignore federated service account index permission when fsh user is set to SPLUNK_SYSTEM_USER
2024-03-25 SPL-252488, SPL-248786, SPL-253755 Lookups in transparent mode don't use proper lookup when fsh and rsh have lookup with same name

Distributed search and search head clustering issues

Date resolved Issue number Description
2024-04-05 SPL-253660, SPL-253532, SPL-253661 Job Artifacts appear getting deleted unexpectedly

Universal forwarder issues

Date resolved Issue number Description
2024-07-15 SPL-251301 Unable to install/upgrade Splunk Enterprise & UF RPM package v9.2.x on the same server.
2024-03-13 SPL-252446, SPL-245954 UF memory utilization by splunk-winevtlog.exe increases until resources are exausted on Domain Controller
2024-03-12 SPL-245954, SPL-252444, SPL-252445, SPL-252446 UF memory utilization by splunk-winevtlog.exe increases until resources are exausted on Domain Controller

Distributed deployment, forwarder, deployment server issues

Date resolved Issue number Description
2024-04-25 SPL-252818, SPL-253411, SPL-254631 Deployment Server not displaying Apps correctly after 9.2.0.1 update

Uncategorized issues

Date resolved Issue number Description
2024-09-04 SPL-239645 Cascading bundle replication stops due to an outage of an indexer and SH Captain does not generate new KO bundles till restarted or captaincy is transferred to another SH member
2024-03-14 SPL-252573, SPL-251434 Crashing Thread: typing_0 in Heavy Forwarder
Last modified on 17 October, 2024
Field alias behavior change   Deprecated and removed in version 9.2

This documentation applies to the following versions of Splunk® Enterprise: 9.2.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters