Splunk Observability Cloud AU0 incident
Users are not be able to log in to Splunk Observability cloud using Unified Identity.
Splunk Observability Cloud AU0 experienced a major incident on March 4, 2026 affecting Datapoint Ingest and Splunk Observability Cloud Web Interface and 1 more component, lasting 2h 48m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating Mar 04, 2026, 07:55 PM UTC
Users may have issues with splunk unified identity login into Splunk Observability and Splunk Log Observer. We are investigating and will provide an update shortly.
- investigating Mar 04, 2026, 08:25 PM UTC
We are continuing to investigate. Additionally some users may not be able to login using standard login interface as well.
- identified Mar 04, 2026, 08:34 PM UTC
We have identified the root cause of this issue and are working on fixing it. We will provide an update once we have applied the fix.
- identified Mar 04, 2026, 09:06 PM UTC
We are continuing to work on a fix for this issue.
- identified Mar 04, 2026, 09:48 PM UTC
In addition to the issues observed with Splunk Unified Identity, users may have also seen some ingest datapoints being dropped. We are continuing to work on a fix for this issue.
- monitoring Mar 04, 2026, 10:02 PM UTC
A fix has been implemented and we are monitoring the results.
- resolved Mar 04, 2026, 10:44 PM UTC
This incident has been resolved.