Splunk Cloud Platform Maintenance Patch Release Information

List of issues that are fixed in maintenance patch releases of Splunk Cloud Platform. Maintenance patch release notes are updated Monday to Friday, typically around 2AM UTC and 12.30PM UTC. If your upgrade details aren't yet visible, please check back after this time.

List of issues that are fixed in maintenance patch releases of Splunk Cloud Platform. Maintenance patch release notes are updated Monday to Friday, typically around 2AM UTC and 12.30PM UTC. If your upgrade details aren't yet visible, please check back after this time.

10.3.2512.X Fixed Issues

This section includes information on fixed issues in 10.3.2512.X

10.3.2512.0

Publication Date: January 21, 2026

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 1
MEDIUM 0
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Distributed search and search head clustering issues

Issue Number Description
SPL-294630 Indexer cluster peer crashes at startup on Windows right after logging that it's downloaded its cluster bundle and it's about to restart.

10.2.2510.X Fixed Issues

This section includes information on fixed issues in 10.2.2510.X

10.2.2510.5

Publication Date: January 15, 2026

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 5
MEDIUM 1
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Splunk Web and interface issues

Issue Number Description
SPL-293084 splunkd crash occurring on stack ES SH by incorrect SPL

Uncategorized issues

Issue Number Description
SPL-289252 Update conf files to use python.required
SPL-289636 DDSS is not supported on GCP NOAH
SPL-289975 Integrate logging of BDM operations
SPL-291187 FIPS compliace for traefik
SPL-291572 Fix error reading app.conf file
SPL-293068 Add support for `python.required` for modular inputs configured through inputs.conf
SPL-293074 FS fails with socket error if one of the RSH hogs the results queue for more than 5 minutes
SPL-293682 SAML AuthN Requests do not contain a ReplyURL unless 'signAuthnRequest' is true
SPL-293767 In Azure DDAA when running get_buckets_to_restore() we don't account for all buckets
SPL-293789 Noah freezes buckets from ongoing restores
SPL-293973 Ensure that there is exactly 2 buckets per-Split for BDM
SPL-294211 Rapidly reissuing a BDM Split Operation is not idempotent

10.2.2510.4

Publication Date: January 07, 2026

Fixed Issues:

Upgrade issues

Issue Number Description
SPL-293092 MainThread crash on start after upgrading from v9.3.1

Distributed deployment, forwarder, deployment server issues

Issue Number Description
SPL-293203 Update serverclass.conf documentation

Uncategorized issues

Issue Number Description
SPL-292802 Integrate Localization Changes for Graphite 10.2
SPL-292853 Update grpcio Python package to 1.74.0

10.2.2510.3

Publication Date: December 23, 2025

Security Fixes:

Security Level Count
CRITICAL 1
HIGH 0
MEDIUM 0
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Saved search, alerting, scheduling, and job management issues

Issue Number Description
SPL-291897 Making copy of Saved Search object in scheduler hot path leads to large degradation or pause of scheduled search thruput
SPL-291889 Fetcher to Scheduler copy takes a long time, leading to a degradation of scheduled search throughput

Search issues

Issue Number Description
SPL-292039 Auto adjusting idle search processes on hostwide memory usage

Indexer and indexer clustering issues

Issue Number Description
SPL-292342 Manual/Automatic detention in gefyra: stop/pause remote queue input work
SPL-292428 Race condition caused repeated bucket rolls

Distributed search and search head clustering issues

Issue Number Description
SPL-292911 Bundle Replication Failure and searches not working in search Head Clustering (SHC)

Splunk Web and interface issues

Issue Number Description
SPL-292915 ES Content Updates app is missing on the rolo GCP sh noah stack

Uncategorized issues

Issue Number Description
SPL-286822 Make sure that Clustered BDM will not work with S2-enabled indexes
SPL-289606 IPC Broker client crashes the Supervisor if Splunk API is not available
SPL-290506 stop for Bulk Data Move operation
SPL-290897 Implement CM specific checks/errors based on populated DataMoveOptions
SPL-291545 deactivate grid layout css scaling flag
SPL-291830 INDX have finished the search properly but SH is not handling the closing properly and marking the search as failed
SPL-291870 Installing the same app everywhere by sh1 if installed only on sh1 has no effect
SPL-291903 Patch Traefik for remove reference for removing some of lego reference
SPL-291961 Newly created rules aren't affecting already running searches on single search head
SPL-291967 Reenable disabled unit tests for Azure
SPL-292100 Modify table names to use stack name as prefix
SPL-292126 GCP SSAI: Test GCP SSAI on a GCP Noah stack
SPL-292280 Remove unused documentation from authentication.conf
SPL-292338 Update to NFR license expiring 2026/12/31
SPL-292349 BDM fixes SPL-287548 and SPL-287221 to 10.2
SPL-292374 Better logging in case of config reading
SPL-292411 Consolidate the collection dump files(csv chunks) into larger files
SPL-292427 Clustered BDM needs to wait for completion of a split
SPL-292453 BDM dryrun not present in REST response and progress nor present in logs
SPL-292499 error seen in the sup-pkg-nascent-stdout.log: RetrieveAssignmentsFromCaptain failed. Max retries reached., code=1: "Failed to launch etcd"
SPL-292554 Package python opentelemetry packages for cloud stacks
SPL-292699 Copyright needs to cover 2005-2026
SPL-292733 DDAA GCP 'ExpireTime' as INT is not being indexed
SPL-292736 ReceiptValidator asserts on optional receipt.json field
SPL-292833 Prevent crashes when ingesting events with Full TimeZone names
SPL-292945 Disallow zlib compression for mongo network connectivity
SPL-293068 Add support for `python.required` for modular inputs configured through inputs.conf

10.2.2510.2

Publication Date: December 05, 2025

Fixed Issues:

Monitoring Console/DMC issues

Issue Number Description
SPL-290868 Investigate and repair broken links to Splunkbase apps

Search issues

Issue Number Description
SPL-290965 SELECT should remove _raw, _time fields if not specified
SPL-291803 Search results discrepancy for marker_name field

Saved search, alerting, scheduling, and job management issues

Issue Number Description
SPL-290996 High search periods lead to higher skips in pull

Admin and CLI issues

Issue Number Description
SPL-291409 BUG> Observing the warning "egrep: warning: egrep is obsolescent; using grep -E" when trying the start Splunk on version 10.

Uncategorized issues

Issue Number Description
SPL-272230 Validate Postgres in FIPS mode for SHC Linux
SPL-290876 Correct Python libraries dependencies for splunk 10.2
SPL-291408 GDI_QA has 2 failures in test_forwarding_mismatch.TestForwardingMismatch
SPL-291477 Remove non-compliant cipher suits from common criteria list
SPL-291484 Fallback download fails on TAI list generation
SPL-291579 Exit early by default on app_list generation if it already exists
SPL-291838 SPL-289747 Update SSG to 3.9.14 introduced one failure to test_btool_check at main/qa
SPL-289747 Update SSG to 3.9.14
SPL-291878 SPL-291871 SSAI fails because of conflicts with VersionControl on SHC
SPL-291871 SSAI fails because of conflicts with VersionControl on SHC

10.2.2510.1

Publication Date: November 25, 2025

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 1
MEDIUM 0
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Admin and CLI issues

Issue Number Description
SPL-290569 Short term fix: Redact fields that match server.conf | encrypt_fields before writing to conf.log
SPL-290961 Prevent customers from running splunk as root user

Indexer and indexer clustering issues

Issue Number Description
SPL-290600 test_northstar_source_indexer_crash

Splunk Web and interface issues

Issue Number Description
SPL-290707 MaxLength 10k chars for nav content textarea prevents client from editing nav
SPL-290861 MaxLength property prevents clients to enter all the data they need

Uncategorized issues

Issue Number Description
SPL-290356 Skip checking is port is already allocated for static ports in ipcbroker
SPL-290415 ASL integration broken on develop and 10.2
SPL-290640 Prevent splitting buckets that have already been split or merged
SPL-291027 Millions of KVStore read calls (storage/collections/data) per day can lead to performance degradation due to conf system stress

10.2.2510.0

Publication Date: November 12, 2025

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 7
MEDIUM 1
LOW 1
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Distributed search and search head clustering issues

Issue Number Description
SPL-249602 SHPoolingListeners::notifyPeerHeartbeat hangs while holding SHPCaptain mutex bringing down scheduler and SHC functionality
SPL-254144 During artifact replication, remove `.tar` file after `tar.gz` has been generated
SPL-285275 Create feature flag for uploading ad-hoc search artifacts to S3
SPL-285278 Update filtering under DispatchStorageManagerInfo::isDisallowedInRemoteStorage so that ad-hoc search artifacts are allowed in remote storage
SPL-287233 Superfluous WARN error message in search.log concerning search manifest granularity

Search issues

Issue Number Description
SPL-255514 timechart count" search is causing Splunk to crash with "Crashing thread: searchOrchestrator"
SPL-274995 outputlookup ignoring "output_format=splunk_mv_csv" when "append=t"
SPL-286507 SearchLogCopier tuning based on Skynet data
SPL-288225 KVStore: Arithmetic underflow in thread calculation causes excessive thread creation during restore collection to KV Service

Upgrade issues

Issue Number Description
SPL-265076 Upgrade Splunk is crashing after upgrading from 9.2.1 to 9.3.1.

Indexer and indexer clustering issues

Issue Number Description
SPL-282187 Splunk upgrade from v9.4.1 to v9.4.3 fails and rollsback on windows .

Universal forwarder issues

Issue Number Description
SPL-282328 Memory leak detected error on the universal forwarder with every restart

Admin and CLI issues

Issue Number Description
SPL-287312 End of Support for MacOS 13 Ventura in Splunk Enterprise 10.2

Splunk Web and interface issues

Issue Number Description
SPL-290442 goldmansachs> Editing private dashboards exceeds eai:data size limit (10000 chars)

Uncategorized issues

Issue Number Description
SPL-251730 Remove implicit conversion of other types into `Str`.
SPL-263177 Code Coverage Improvement for MongoDB 7.0 Upgrade Code
SPL-266575 Migrate mongo-c-driver to bazel
SPL-266594 Migrate krb5 to bazel
SPL-270309 FA 2.0 - Alpha 1.0 - splunkd <-> Leapfrog processor implementation
SPL-272304 Openssl3 upgrade RFC7519JsonWebToken::generateSignature creates a signature with 344 bytes instead of 256
SPL-273649 Improve efficiency of data lake indexing for ASL - extracting fields from Parquet
SPL-273827 KVStore Collection cache: Reaper can't reap the collection old cache entries if the collection is changing within the deletion time interval
SPL-274582 Rolling upgrade CLI help does not work for cluster-manager
SPL-275783 Functional testing Summarisation
SPL-276875 Purge buildit.py of all Hunk-related JARs
SPL-277354 Optimisation: upload an app to Noah bundle only if not present
SPL-279555 FPT_AEX_EXT.1.5 Safelogic's fips140-3/fips.so is built without stack protection
SPL-279838 Cisco SAL initiative + Federated Search-S3 Integration project
SPL-280592 Leverage the API created in SPL-280591 for setting the search process context
SPL-281077 Splunk Get Aws Credentials fails to connect to AWS GovCloud (US-ISO) STS endpoints due to incorrect domain resolution
SPL-281132 CM Peer REST handler for action move_data
SPL-281182 Update destination for stuck S3 jobs
SPL-281568 Code Coverage Improvement for MongoClient.cpp
SPL-281681 Add Unit Test Coverage for SSLOptions Module
SPL-281814 Internal error message has an extra space breaking KV extraction for search_id
SPL-281982 Add more logs around IndexedCSV area (eg. offset, etc.)
SPL-282309 Race condition seen in delta bundle replication - Rollout fleetwide
SPL-282342 Remove absolute addresses and function names from runtime backtraces so they can be used more widely.
SPL-282426 python.version re-architecture: Support new config setting python.required
SPL-282700 Implement indexes.conf's allowBulkDataMove for CMs
SPL-282837 misc_pool processes experience OOMs due to WLM limits
SPL-283116 Add graceful handling for HecJson serialization
SPL-283490 VersioningRepoManagerTest
SPL-283597 Implement logging of BDM operations
SPL-283653 Fix wrong FCV version for Legacy Upgrade
SPL-283762 SSLOptions Unit Test Cases - web.conf cert paths
SPL-283799 TLS 1.3 Support for Storage (S3, GCP, Azure storage clients)
SPL-284012 Conf Mod: Expose BTool functionality via REST API
SPL-284095 Remove "VersionControl" from all the file names under src/version_control
SPL-284126 Validate TLS data-plane certificate for SHC Linux Postgres
SPL-284199 Bump splunk-supervisor to 0.1.481 version in G/S
SPL-287090 splunk-supervisor gets in a restart loop if edge SCS configs are provided
SPL-284336 Fix RFS Bundle availability metric to have correct bundle type
SPL-284516 Support Indexing _key Field in IndexedCSV - Rollout fleetwide
SPL-284881 Remove @trace decorator wrapping process_list_entry function
SPL-285371 Use fixed IPC port for postgres_nanny and followups
SPL-285395 BDM REST API code for peer 'done'
SPL-285396 BDM CM handling of peer 'done'
SPL-283604 Implement processing of the notion of done for a peer for a BDM operation
SPL-285541 Introduce conditional import for CloudClient
SPL-285555 KVStore Splcore Updates
SPL-285583 Fix Validation for JSON parsing error
SPL-285960 Split BucketHistoryTable related tests from test_metadata_store
SPL-286010 Published dashboards don't correctly hide panels when no data
SPL-286062 Move metric processing inside the Ingest Processor activation block
SPL-286119 Update OpenSSL to 3.0.18/1.0.2zm to remediate CVE-2025-9230
SPL-286160 Augment conf changes (PropertyPages::deferredShare) for when, what and who makes changes
SPL-286211 On bootup, create public/private key pair on SHU captain
SPL-286226 Splunk Token Enhancements
SPL-286356 fastrunning_RegexHammerTest
SPL-286399 Exclude temporary and summarize searches from telemetry indexing and forwarding
SPL-286442 Fix error logs when Supervisor is listing hidden roles
SPL-286449 First Round Tweaks for Clustered BDM Implementation
SPL-286455 the page routing within admin.py
SPL-286609 Simultaneous v1 and v2 summarisation
SPL-286614 Fix: KeyValue always included in SAML Signature with Splunk as IdP
SPL-286813 NASCENT: Nascent FIPs test failure
SPL-286830 Change hard-coded "westus-2" to SalData.region in FederatedRestProviderHandler
SPL-286843 Rename replay flag from data_manager_replay_id to splunk_promote_id
SPL-286942 Fix Restore Fail for JSON parsing WARN
SPL-286958 Cluster Peer BDM Reporting Shenanigans
SPL-286960 Pin backup reads to writer node
SPL-287014 Update Azure Workload Identity library within the azure sdk so that SOK customers can enable it in their Splunk Smartstore deployment
SPL-287022 Creating private app from template fails
SPL-287151 Update SSG to 3.9.11
SPL-287310 Pure streaming optimization should not be enabled by default
SPL-287335 Rename s3replay datalake type to s3promote
SPL-287374 Set proper storage tier in Azure DDAA
SPL-287461 NASCENT: Upgrade etcd to 3.6.5
SPL-287480 In ColdStorageArchiver we copy just first 1000 objects in /deletes/ folder
SPL-287492 re-enabling CAA unit tests
SPL-287502 Implement backup_and_delete_bucket_metadata
SPL-287618 preventing subsearches from using Pure streaming optimizations added in SPL-284820
SPL-287637 DMC HEC input support for _meta in inputs.conf
SPL-287820 Update SSG to 3.9.12 (3.8.59)
SPL-287844 sal_token gettin printed in post command
SPL-287854 Need to escape with double quotes username when adding to groups
SPL-287871 Splunk Enterprise: Unlimited Apps Name Input allows unlimited characters causing Denial of Service
SPL-287896 Fix failing test_archive_restore_orchestration.py UTs
SPL-288075 Fix importtool ET, LT issue
SPL-288222 sdselect queries should not work on FA2.0 enabled stacks. When the user selects SPL1 version and enter an sdselect query, it should return an error.
SPL-288241 Fix SAL UI proxy routing and API field consistency issues
SPL-288302 Issue with SSL cert path config for Azure
SPL-288366 Unable to start splunkweb when upgrading from 10.0 to 10.2
SPL-288396 Add more hammer testing for CollectionCacheManager
SPL-288464 Fix federated index creation by adding aws_glue_table prefix to dataset response
SPL-288474 update .conf files in studio and exporter app to include python.required field
SPL-288567 Remove dataset_types from provider creation response
SPL-288780 move SAL test files to new federated folder
SPL-289010 Allow Azure environment variables to be used for workload identity related config
SPL-289045 Dynamodb distributed locking replies with 500 instead of 503
SPL-289048 Internal server error on installing Splunkbase app using link
SPL-289131 Fix double base64 encoding under OpenSSL3
SPL-289171 Splunkd crashes when attempting to remove a security token that is assigned to an LDAP user that has been removed.
SPL-289200 DO namespace change breaks ACC dispatch table config
SPL-289380 BucketSplitCmd breakage in PDT AND X509 pre-merge test breakage
SPL-289409 Make splunk-rolling-upgrade Python 13 compatible
SPL-289444 Fix BucketSplitCmdTest breakage in PDT
SPL-289450 Bulk Data Move max-workers handling
SPL-289470 Fix documentation of bulk_data_move Capability
SPL-289490 Check what the sitch is with cold buckets and BDM
SPL-289552 KV Store Backup fails with File Size Exceeded Limit
SPL-289609 Revert Sidecar Identities
SPL-289710 Setup certificates across SHU
SPL-289736 Update RapidDiag to 1.9.5
SPL-289786 Update Splunk web to use Python 3.13 as default Python interpreter
SPL-290290 Fix missing fields in SAML config assignment operator and add missing values in conf persistence.
SPL-290506 stop for Bulk Data Move operation

10.1.2507.X Fixed Issues

This section includes information on fixed issues in 10.1.2507.X

10.1.2507.16

Publication Date: January 21, 2026

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 2
MEDIUM 4
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Splunk Web and interface issues

Issue Number Description
SPL-292710 ES Content Updates app is missing on the rolo GCP sh noah stack

Distributed search and search head clustering issues

Issue Number Description
SPL-293979 clustered_bucket_database_granularity=index feature toggle breaks '|delete' command on classic clustering stacks

Uncategorized issues

Issue Number Description
SPL-289636 DDSS is not supported on GCP NOAH
SPL-291572 Fix error reading app.conf file
SPL-292166 Ingestor app uninstall/implicit remove reload(no restart)
SPL-293041 Fix on backend : Unlimited Apps Name Input allows unlimited characters causing Denial of Service
SPL-293681 SAML AuthN Requests do not contain a ReplyURL unless 'signAuthnRequest' is true
SPL-294132 Build supervisor with proper go build toolchain

10.1.2507.15

Publication Date: January 09, 2026

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 1
MEDIUM 0
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Splunk Web and interface issues

Issue Number Description
SPL-292914 ES Content Updates app is missing on the GCP sh stack
SPL-293083 splunkd crash occurring on stack ES SH by incorrect SPL

Upgrade issues

Issue Number Description
SPL-293091 MainThread crash on start after upgrading from v9.3.1

10.1.2507.14

Publication Date: December 23, 2025

Fixed Issues:

Saved search, alerting, scheduling, and job management issues

Issue Number Description
SPL-290995 High search periods lead to higher skips in pull
SPL-291890 Fetcher to Scheduler copy takes a long time, leading to a degradation of scheduled search throughput
SPL-291898 Making copy of Saved Search object in scheduler hot path leads to large degradation or pause of scheduled search thruput

Search issues

Issue Number Description
SPL-291641 Prevent stats from creating unlimited temp files without disk space restriction
SPL-291805 Search results discrepancy for marker_name field
SPL-292038 Auto adjusting idle search processes on hostwide memory usage

Uncategorized issues

Issue Number Description
SPL-289606 IPC Broker client crashes the Supervisor if Splunk API is not available
SPL-291960 Newly created rules aren't affecting already running searches on single search head
SPL-292154 INDX have finished the search properly but SH is not handling the closing properly and marking the search as failed
SPL-292556 ReceiptValidator asserts on optional receipt.json field
SPL-292733 DDAA GCP 'ExpireTime' as INT is not being indexed
SPL-292832 Prevent crashes when ingesting events with Full TimeZone names

10.1.2507.13

Publication Date: December 04, 2025

Fixed Issues:

Admin and CLI issues

Issue Number Description
SPL-290473 Redact fields that match server.conf | encrypt_fields before writing to conf.log

Monitoring Console/DMC issues

Issue Number Description
SPL-290867 Investigate and repair broken links to Splunkbase apps

Uncategorized issues

Issue Number Description
SPL-290701 Correct Python libraries dependencies for Splunk 10.1
SPL-291221 Deadlock between _workloadMutex and _workloadMetricsMutex while computing workload metrics
SPL-291483 Fallback download fails on TAI list generation
SPL-291578 Exit early by default on app_list generation if it already exists

10.1.2507.12

Publication Date: November 21, 2025

Fixed Issues:

Indexer and indexer clustering issues

Issue Number Description
SPL-286574 Updated timestamp in output of rest api services/cluster/manager/info is incorrect

Distributed search and search head clustering issues

Issue Number Description
SPL-289098 SHPoolingListeners::notifyPeerHeartbeat hangs while holding SHPCaptain mutex bringing down scheduler and SHC functionality

Splunk Web and interface issues

Issue Number Description
SPL-290860 MaxLength property prevents clients to enter all the data they need

Uncategorized issues

Issue Number Description
SPL-290291 Fix missing fields in SAML config assignment operator and add missing values in conf persistence.

10.1.2507.11

Publication Date: November 25, 2025

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 1
MEDIUM 0
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Distributed search and search head clustering issues

Issue Number Description
SPL-288714 Superfluous WARN error message in search.log concerning search manifest granularity

Upgrade issues

Issue Number Description
SPL-288840 Upgrade Splunk is crashing after upgrading from 9.2.1 to 9.3.1.

Indexer and indexer clustering issues

Issue Number Description
SPL-289711 Splunk cluster manager - cluster bundle is stuck in Bundle validation is in progress

Uncategorized issues

Issue Number Description
SPL-288478 Modify replication default timeout and failure behavior
SPL-288565 FPT_AEX_EXT.1.5 Safelogic's fips140-3/fips.so is built without stack protection
SPL-288699 preventing subsearches from using Pure streaming optimizations added in SPL-284820
SPL-284820 Slow performance for pure streaming searches when using federated search
SPL-289044 Dynamodb distributed locking replies with 500 instead of 503
SPL-289131 Fix double base64 encoding under OpenSSL3
SPL-289170 Splunkd crashes when attempting to remove a security token that is assigned to an LDAP user that has been removed.
SPL-289392 Setup certificates across SHU

10.0.2503.X Fixed Issues

This section includes information on fixed issues in 10.0.2503.X

10.0.2503.11

Publication Date: January 12, 2026

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 1
MEDIUM 2
LOW 1
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Saved search, alerting, scheduling, and job management issues

Issue Number Description
SPL-288831 Making copy of Saved Search object in scheduler hot path leads to large degradation or pause of scheduled search thruput
SPL-291891 Fetcher to Scheduler copy takes a long time, leading to a degradation of scheduled search throughput

Admin and CLI issues

Issue Number Description
SPL-290472 Redact fields that match server.conf | encrypt_fields before writing to conf.log
SPL-291227 Observing the warning "egrep: warning: egrep is obsolescent; using grep -E" when trying the start Splunk on version 10.

Monitoring Console/DMC issues

Issue Number Description
SPL-290865 Fix the links pointing to Splunkbase apps in Apps UI

Search issues

Issue Number Description
SPL-291639 Prevent stats from creating unlimited temp files without disk space restriction
SPL-291804 Search results discrepancy for marker_name field
SPL-292037 Auto adjusting idle search processes on hostwide memory usage

Distributed search and search head clustering issues

Issue Number Description
SPL-292912 Bundle Replication Failure and searches not working in search Head Clustering (SHC)

Splunk Web and interface issues

Issue Number Description
SPL-293082 splunkd crash occurring on stack ES SH by incorrect SPL

Upgrade issues

Issue Number Description
SPL-293089 MainThread crash on start after upgrading from v9.3.1

Distributed deployment, forwarder, deployment server issues

Issue Number Description
SPL-293201 Update serverclass.conf documentation

Uncategorized issues

Issue Number Description
SPL-289606 IPC Broker client crashes the Supervisor if Splunk API is not available
SPL-291958 Newly created rules aren't affecting already running searches on single search head
SPL-292078 Aging_out might OOM on older releases
SPL-292556 ReceiptValidator asserts on optional receipt.json field
SPL-292831 Prevent crashes when ingesting events with Full TimeZone names
SPL-293072 FS fails with socket error if one of the RSH hogs the results queue for more than 5 minutes
SPL-293678 SAML AuthN Requests do not contain a ReplyURL unless 'signAuthnRequest' is true

10.0.2503.10

Publication Date: November 22, 2025

Fixed Issues:

Indexer and indexer clustering issues

Issue Number Description
SPL-286573 updated timestamp in output of rest api services/cluster/manager/info is incorrect

Distributed search and search head clustering issues

Issue Number Description
SPL-289097 SHPoolingListeners::notifyPeerHeartbeat hangs while holding SHPCaptain mutex bringing down scheduler and SHC functionality

Splunk Web and interface issues

Issue Number Description
SPL-290858 MaxLength property prevents clients to enter all the data they need

Uncategorized issues

Issue Number Description
SPL-289131 Fix double base64 encoding under OpenSSL3
SPL-290288 Fix missing fields in SAML config assignment operator and add missing values in conf persistence.
SPL-290966 Remove size check for evtFormatMsg() in splunk_winevtlog

10.0.2503.9

Publication Date: November 04, 2025

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 1
MEDIUM 0
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Upgrade issues

Issue Number Description
SPL-288838 Upgrade Splunk is crashing after upgrading from 9.2.1 to 9.3.1.

Uncategorized issues

Issue Number Description
SPL-284619 Stop the request if content-length exceeds the limit.
SPL-285860 Rolling upgrade CLI help does not work for cluster-manager
SPL-288476 Modify replication default timeout and failure behavior
SPL-288564 FPT_AEX_EXT.1.5 Safelogic's fips140-3/fips.so is built without stack protection
SPL-288698 preventing subsearches from using Pure streaming optimizations added in SPL-284820
SPL-284820 Pure streaming queries take much longer for federated search
SPL-288866 AppExport throwing ImportError
SPL-289169 Splunkd crashes when attempting to remove a security token that is assigned to an LDAP user that has been removed.

9.3.2411.X Fixed Issues

This section includes information on fixed issues in 9.3.2411.X

9.3.2411.123

Publication Date: January 13, 2026

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 0
MEDIUM 1
LOW 2
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Search issues

Issue Number Description
SPL-292047 Auto adjusting idle search processes on hostwide memory usage

Splunk Web and interface issues

Issue Number Description
SPL-293086 splunkd crash occurring on stack ES SH by incorrect SPL

Uncategorized issues

Issue Number Description
SPL-289606 IPC Broker client crashes the Supervisor if Splunk API is not available
SPL-292336 Update to NFR license expiring 2026/12/31

9.3.2411.122

Publication Date: December 15, 2025

Fixed Issues:

Splunk Web and interface issues

Issue Number Description
SPL-285822 UI slowness/timeouts while accessing macros and searches

Admin and CLI issues

Issue Number Description
SPL-290471 Redact fields that match server.conf | encrypt_fields before writing to conf.log

Monitoring Console/DMC issues

Issue Number Description
SPL-290866 Fix the links pointing to Splunkbase apps in Apps UI

Search issues

Issue Number Description
SPL-291640 Prevent stats from creating unlimited temp files without disk space restriction

Saved search, alerting, scheduling, and job management issues

Issue Number Description
SPL-291892 Fetcher to Scheduler copy takes a long time, leading to a degradation of scheduled search throughput
SPL-291900 Making copy of Saved Search object in scheduler hot path leads to large degradation or pause of scheduled search thruput

Uncategorized issues

Issue Number Description
SPL-291959 Newly created rules aren't affecting already running searches on single search head
SPL-292077 Aging_out might OOM on older releases

9.3.2411.121

Publication Date: November 22, 2025

Fixed Issues:

Distributed search and search head clustering issues

Issue Number Description
SPL-289104 SHPoolingListeners::notifyPeerHeartbeat hangs while holding SHPCaptain mutex bringing down scheduler and SHC functionality

Splunk Web and interface issues

Issue Number Description
SPL-290859 MaxLength property prevents clients to enter all the data they need

Uncategorized issues

Issue Number Description
SPL-289168 Splunkd crashes when attempting to remove a security token that is assigned to an LDAP user that has been removed.
SPL-289441 Stop the request if content-length exceeds the limit.
SPL-290289 Fix missing fields in SAML config assignment operator and add missing values in conf persistence.

9.3.2411.120

Publication Date: November 05, 2025

Security Fixes:

Security Level Count
CRITICAL 0
HIGH 1
MEDIUM 1
LOW 0
Security fixes are listed here for initial context only. Definitive details and severity classifications may be published on the Splunk Product Security page at a later date.

Fixed Issues:

Upgrade issues

Issue Number Description
SPL-288880 Upgrade Splunk is crashing after upgrading from 9.2.1 to 9.3.1.

Uncategorized issues

Issue Number Description
SPL-285861 Rolling upgrade CLI help does not work for cluster-manager
SPL-287907 DMC HEC input support for _meta in inputs.conf
SPL-288477 Modify replication default timeout and failure behavior