Splunk® Enterprise

Release Notes

This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Fixed issues

Splunk Enterprise 9.4.0 was released on December 16, 2024. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once.

Search issues

Date resolved Issue number Description
2024-09-02 SPL-261475, SPL-261629, SPL-261630, SPL-261631, SPL-261707, SPL-261708 Unable to search _cmc_summary index on classic stacks (also affects any search with index=_* which includes surrounding searches)
2024-08-26 SPL-261357 DeprecationWarning in sendemail.py for the urllib.splitquery method

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2024-09-06 SPL-261927, SPL-260972 Limit adhoc rsa artifact lifespan to a default of 24 hours

Charting, reporting, and visualization issues

Date resolved Issue number Description
2024-05-28 SPL-247466 Dashboard Studio layers button is not working in Windows 10

Universal forwarder issues

Date resolved Issue number Description
2025-03-12 SPL-248479, SPL-253092 Forwarders enter a state of constant blocking, and Splunk Cloud indexers might fail to process events. This can result in the events being sent to a non-searchable queue, the Dead Letter Queue (DLQ), due to a Persistent Queue issue with the S2S protocol

Splunk Web and interface issues

Date resolved Issue number Description
2024-07-09 SPL-256902 Splunk is crashing with "Crashing thread: WebuiStartup" when TLS is used for Splunk Web with an empty DNS under "X509v3 Subject Alternative Name" field of the certificate
2024-06-12 SPL-256517, SPL-255606, SPL-257761, SPL-257765, SPL-258420 upgrade splunk-utils and search-job packages to dynamically refresh CSRF token
Last modified on 17 March, 2025
Field alias behavior change   Deprecated and removed in version 9.4

This documentation applies to the following versions of Splunk® Enterprise: 9.4.0


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters