Service Advisory: KVservice issues impacting Enterprise Security search performance

Major Impact Identified Ongoing April 9, 2026

Incident Lifecycle

Investigating Identified

Incident Timeline

Identified
Our engineering teams have narrowed the scope of the issue: searches utilizing the | lookup or | inputlookup commands for KV collections were failing. This impact extended to the Mission Control and Analyst Queue dashboards.

Additionally, we have identified the root cause and are actively mitigating the impact. Once mitigation is complete, we will continue to monitor the environment to ensure service stability for all users.

We will continue to provide status updates as more information bec...
Apr 9, 2026 at 1:04 AM UTC
Investigating
Our engineering team has identified an issue with the KVservice that is currently impacting search performance for ad-hoc, saved, and scheduled searches.

Additional symptoms may include, but not limited to:
- Inability to save searches within the Enterprise Security (ES) application.
- Errors when attempting to update application settings, such as credentials.

This is an active investigation. We are working to resolve this as quickly as possible and will provide status updates as more infor...
Apr 9, 2026 at 12:10 AM UTC
Was your business affected by this Splunk outage?
Set up instant alerts for Splunk — be the first to know about outages via email, Slack, Teams, or Discord.