Back

Splunk, Inc.
Patches for Splunk Enterprise x64
Windows
16 patches available
Splunk Enterprise collects data from any source, including metrics, logs, clickstreams, sensors, stream network traffic, web servers, custom applications, hypervisors, containers, social media and cloud services.nIt enables to search, monitor and analyze that data to discover powerful insights across multiple use cases like security, IT operations, application delivery, industrial data and IoT.
Splunk Enterprise x64 Version 9.4.2.0
Release Date
4/28/2025
Bug Fix?
Yes
Minor Release?
No
Patch Notes

Fixed issues$$$Splunk Enterprise 9.4.2 was released on April 28; 2025. This release includes fixes for the following issues.$$$$$$Issues are listed in all relevant sections. Some issues might appear more than once.$$$$$$Search issues$$$Date resolvedtIssue numbertDescription$$$2025-02-06tSPL-270114; SPL-267619tUpdated saved searches in custom app enters in a fragile throttling state$$$Federated search issues$$$Date resolvedtIssue numbertDescription$$$2025-01-14tSPL-268208; SPL-266456tFederated Search & Analytics - Users unable to assign role-based access control to federated indexes using the Roles Web Page$$$Saved search; alerting; scheduling; and job management issues$$$Date resolvedtIssue numbertDescription$$$2025-02-06tSPL-270114; SPL-267619tUpdated saved searches in custom app enters in a fragile throttling state$$$Universal forwarder issues$$$Date resolvedtIssue numbertDescription$$$2025-02-28tSPL-271696; SPL-266416tCrashing thread - WinEventLogInputProcessor on Universal forwarders after upgrading to 9.2.1. and even after upgrading to the 9.3.2$$$2025-02-17tSPL-266416; SPL-271693; SPL-271695; SPL-271696; SPL-271694tCrashing thread - WinEventLogInputProcessor on Universal forwarders after upgrading to 9.2.1. and even after upgrading to the 9.3.2$$$Splunk Web and interface issues$$$Date resolvedtIssue numbertDescription$$$2025-01-16tSPL-269111; SPL-268776tUser unable to delete private report$$$Uncategorized issues$$$Date resolvedtIssue numbertDescription$$$2025-03-13tSPL-269230; SPL-272608; SPL-272609; SPL-272610; SPL-272612; SPL-272615tSmartStore unable to connect to S3 with timezone earlier than UTC$$$2024-11-23tSPL-266774; SPL-266800; SPL-266801; SPL-266802; SPL-266803; SPL-266804; SPL-266805tEnable regex processor cpu profiling metrics.$$$
Splunk Enterprise x64 Version 9.4.1.0
Release Date
2/26/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Fixed issues$$$Splunk Enterprise 9.4.1 was released on February 26; 2025. This release includes fixes for the following issues.$$$$$$Issues are listed in all relevant sections. Some issues might appear more than once.$$$$$$Charting; reporting; and visualization issues$$$Date resolvedtIssue numbertDescription$$$2024-11-18tSPL-265872; SPL-265697tStudio web vitals data telemetry is logging PII via urls$$$Universal forwarder issues$$$Date resolvedtIssue numbertDescription$$$2024-11-20tSPL-265908; SPL-254532tUF 9.1.2 Windows Security events stop forwarding when Windows event log service is restarted$$$2024-11-19tSPL-265068; SPL-266372; SPL-266374; SPL-266375; SPL-266377tUF Windows installer re-grant user privileges during upgrade$$$2024-11-06tSPL-265633; SPL-265630tWindows Universal Forwarder high cpu where Splunk user does not have read access to all of the files in the monitored directory$$$2024-11-06tSPL-259202; SPL-265630tWindows Universal Forwarder high cpu where Splunk user does not have read access to all of the files in the monitored directory$$$Windows-specific issues$$$Date resolvedtIssue numbertDescription$$$2024-11-08tSPL-265859; SPL-265863; SPL-265864; SPL-265865; SPL-265866tA missing CloseHandle() can lead to memory leaks$$$2024-11-06tSPL-259217; SPL-265734; SPL-265735; SPL-265736; SPL-265737tDenylist is not working (blacklist1 = EventCode=4662 Message=Account Name:(?!\s*admin1))$$$2024-11-06tSPL-259202; SPL-265630tWindows Universal Forwarder high cpu where Splunk user does not have read access to all of the files in the monitored directory
Splunk Enterprise x64 Version 9.4.0.0
Release Date
12/11/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

**File not scanned for VT due to size**$$$Whats New in 9.4$$$New feature; enhancement; or changetDescription$$$Deployment server version 9.4tDeployment Server provides a centralized location and user-interface to manage; maintain; and troubleshoot all types of Splunk agents; such as the Universal Forwarder and the Heavy Forwarder.$$$Deployment Server 9.4.0 provides the following new capabilities:$$$$$$Overview of the health and status of your agents$$$A new UI with a shorter load time and updated user experience$$$A11y compliance$$$Stats V1 removaltVersion 1 of the stats command has been removed and replaced with version 2 of the stats command.$$$Enhancement to the foreach commandtA new auto_collections mode has been added the foreach command. The auto_collections mode dynamically iterates over a JSON array or multivalue field depending on which element is present in the search. See foreach in the Search Reference.$$$Federated Search for Splunk: Metric indexes now supported as a new dataset type for federated searchestWith this release; Federated Search for Splunk adds a new dataset type for standard mode federated searches: metric indexes. You can now run federated searches over metric index datasets. Additional error handling has been added to ensure that you apply event generating commands to event index datasets and apply metric generating commands to metric index datasets.$$$This is a breaking change for previous federated searches of metric indexes. If you are upgrading from a previous version of the Splunk platform; you must define new federated indexes for metric index datasets.$$$$$$For more information about defining federated indexes that map to metric index datasets; see Map a federated index to a remote Splunk dataset in Federated Search.$$$$$$For more information about writing federated searches for metric index datasets; see Run federated searches over remote Splunk platform deployments in Federated Search.$$$$$$Federated Search for Splunk: Support for eventcount across Standard and Transparent mode.tThe eventcount command is now supported by Federated Search for Splunk. This support includes the option to have eventcount return event counts for indexes on remote Splunk platform deployments that are designated as federated providers. eventcount search results now include a provider column that identifies the federated providers that listed indexes belong to.$$$$$$For more information; see eventcount in the Search Reference.$$$$$$Federated Search for Splunk: Standard mode federated search support for the mcatalog command.tThe mcatalog command is now supported for standard mode federated searches. For more information; see the following topics:$$$Run federated searches over remote Splunk platform deployments; in Federated Search.$$$mcatalog; in the Search Reference.$$$Upgrade KV store server version from 4.2 to 7.0tSplunk Enterprise 9.4 requires that you upgrade to KV store server version 7.0. Your deployment automatically upgrades your KV store during your upgrade to Splunk Enterprise 9.4. This new server version includes security enhancements and improves the performance of your KV store. See Upgrade the KV store server version in the Admin manual to plan your upgrade.$$$Internal Library SettingstThe Internal Library Settings page is removed. Deprecated libraries and unsupported hotlinked imports are restricted; and Splunk Cloud Platform no longer offers a self-service option to use them. For more information about Internal Library Settings; see Control access to jQuery and other internal libraries in the jQuery Upgrade Readiness manual.$$$Dashboard Studio enhancementstSee Whats new in Dashboard Studio.$$$SPL2 public betatThis version of Splunk will support SPL2 via API; to help admins create powerful apps to gain more control over their ecosystem while allowing developers massive flexibility for the custom apps they can build.$$$Admins and developers can ship SPL2 module files that define custom functions; views; data types;
Splunk Enterprise x64 Version 9.3.2.0
Release Date
11/7/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

**File not scanned for VT due to size**$$$Whats New in 9.3.2$$$Splunk Enterprise 9.3.2 was released on November 7; 2024. It resolves the issues described in Fixed issues(https://docs.splunk.com/Documentation/Splunk/9.3.2/ReleaseNotes/Fixedissues)
Splunk Enterprise x64 Version 9.3.1.0
Release Date
9/12/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

**File not scanned for VT due to size**$$$$$$Whats New in 9.3.1$$$Splunk Enterprise 9.3.1 was released on September 12; 2024. It resolves the issues described in Fixed issues.$$$$$$New feature; enhancement; or changetDescription$$$Duo Security authentication - support for the Universal PrompttUsers can use the Universal Prompt experience for Duo Security multifactor authentication. The Universal Prompt is a more advanced and secure authentication experience than the Traditional Prompt used on previous Splunk Enterprise versions. See About multifactor authentication with Duo Security.$$$$$$If you still use the Traditional Prompt for Duo multifactor authentication; take the following steps by December 31; 2024:$$$$$$Upgrade Splunk Enterprise to one of the versions that support the Universal Prompt; like 9.3.1 or higher.$$$Migrate to the Universal Prompt. See Migrate from the Duo Traditional Prompt to the Duo Universal Prompt .$$$$$$December 31; 2024 is the last day of support for the Traditional Prompt.
Splunk Enterprise x64 Version 9.3.0.0
Release Date
7/24/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

**File not scanned for VT due to size**$$$$$$Refer-https://docs.splunk.com/Documentation/Splunk/9.3.0/ReleaseNotes/MeetSplunk
Splunk Enterprise x64 Version 9.2.2.0
Release Date
7/1/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Refer-https://docs.splunk.com/Documentation/Splunk/9.2.2/ReleaseNotes/Fixedissues
Splunk Enterprise x64 Version 9.2.1.0
Release Date
3/21/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Refer-https://docs.splunk.com/Documentation/Splunk/9.2.1/ReleaseNotes/Fixedissues
Splunk Enterprise x64 Version 9.2.0.1
Release Date
2/8/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Refer-https://docs.splunk.com/Documentation/Splunk/9.2.0/ReleaseNotes/Fixedissues#Splunk_Enterprise_9.2.0.1
Splunk Enterprise x64 Version 9.1.3.0
Release Date
1/22/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Refer-https://docs.splunk.com/Documentation/Splunk/9.1.3/ReleaseNotes/Fixedissues
Splunk Enterprise x64 Version 9.1.2.0
Release Date
11/16/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Refer-https://docs.splunk.com/Documentation/Splunk/9.1.2/ReleaseNotes/Fixedissues
Splunk Enterprise x64 Version 9.1.1.0
Release Date
8/30/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Refer-https://docs.splunk.com/Documentation/Splunk/9.1.1/ReleaseNotes/MeetSplunk#What.27s_New_in_9.1.1
Splunk Enterprise x64 Version 9.1.0.2
Release Date
7/31/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Fixed issues$$$Splunk Enterprise 9.1.0.2$$$$$$Splunk Enterprise 9.1.0.2 was released on July 31; 2023. It delivers the update described in https://advisory.splunk.com/advisories/SVD-2023-0606.
Splunk Enterprise x64 Version 9.0.4.0
Release Date
2/14/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Whats New in 9.0.4$$$Splunk Enterprise 9.0.4 was released on February 14; 2023. It delivers relevant fixes described in the February 14; 2023 quarterly security patch on the Splunk Product Security page. This release also introduces the following change and resolves the issues described in Fixed issues.$$$$$$The search_listener request parameter for the Splunk REST API search/jobs endpoint is disabled.
Splunk Enterprise x64 Version 9.0.3.0
Release Date
12/14/2022
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Splunk Enterprise 9.0.3 was released on December 14; 2022.$$$$$$New Feature or EnhancementtDescription$$$New flag to enable translation of user content.tA new flag in web-features.conf enables translation of user content in Simple XML dashboards.$$$Warning for use of S2S V3 or lower.tWarning for use of S2S V3 or lower.$$$Migration script to update Search & Reporting v=null dashboards to v=1.1tWhen Splunk is upgraded or starts up; update Simple XML dashboards in the Search & Reporting app with no version attribute to v=1.1.
Splunk Enterprise x64 Version 9.0.1.0
Release Date
8/16/2022
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

It delivers relevant fixes described in the August 16; 2022 quarterly security patch on the Splunk Product Security page(. This release resolves the issues described in Fixed issues(https://docs.splunk.com/Documentation/Splunk/9.0.1/ReleaseNotes/Fixedissues).$$$$$$Following are the enhancements$$$$$$Ingest Actions enhancementst$$$1)Set Index capability in Ingest Actions rulesets$$$2)New health report indicator: S3 Output$$$3)Security fixes
Interested in automating patching for Adobe Acrobat?