Splunk® Enterprise

Release Notes

This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.3.0 was released on July 24, 2024. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Data input issues

Date resolved Issue number Description
2024-03-12 SPL-252162 Creating FS Destination in SH member was rejected due to NFS server was not mounted on the SH member
2023-10-16 SPL-222366 Ingest Actions does not work with Splunk Free, Personalized Devtest, Developer, and Forwarder-only licenses

Search issues

Date resolved Issue number Description
2024-06-20 SPL-248552 ProcessDispatchedSearch error displayed - The process cannot access the file because it is being used by another process

Federated search issues

Date resolved Issue number Description
2024-04-26 SPL-254722, SPL-253248 Federated searches not completing with error "Socket error during transaction. Socket error: Success"
2024-03-21 SPL-242282, SPL-242864 Federated Searches fail for union commands when query optimization diverge between FSH x RSH
2024-03-21 SPL-219793 Some commands in federated searches return incorrect resultCount values when run in verbose mode
2024-01-25 SPL-249387, SPL-250067, SPL-250069, SPL-250567 Bugfix for remoteTLCmd duplicated during phase generation in Verbose Mode
2024-01-19 SPL-246556, SPL-249728, SPL-249746 Federated searches that contain stats count by a field that doesn't exist return 0 events when run in verbose mode

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2024-05-30 SPL-256696, SPL-256287 Scheduled search by user nobody(UTC) was not collecting data correctly for the schedule on May 1st, 2024

Indexer and indexer clustering issues

Date resolved Issue number Description
2024-05-23 SPL-256388, SPL-255517 Indexer Discovery deadlock during tcpout reload

Monitoring Console issues

Date resolved Issue number Description
2024-01-02 SPL-244687, SPL-249851 Bucket Health Status is not cleared even after 24 hours until a new bucket is created

Uncategorized issues

Date resolved Issue number Description
2024-10-02 SPL-256104 Maximum daily volume for a pool displayed as Unlimited, when license maximum typed in manually in 'A specific amount' field
2024-06-10 SPL-257082, SPL-255939 Crashing thread: TcpOutEloop and Shutdown on the Heavy Forwarder
2024-04-08 SPL-231246 S2 DMA data (on remote store) getting deleted , S3Client errors still persists caused by excessive statusCode=404
2024-02-09 SPL-239663 Search History uses All Time range
Last modified on 02 October, 2024
Field alias behavior change   Deprecated and removed in version 9.3

This documentation applies to the following versions of Splunk® Enterprise: 9.3.0

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters