Splunk Observability Cloud AU0 incident

Users are not be able to log in to Splunk Observability cloud using Unified Identity.

Major Resolved View vendor source →

Splunk Observability Cloud AU0 experienced a major incident on March 4, 2026 affecting Datapoint Ingest and Splunk Observability Cloud Web Interface and 1 more component, lasting 2h 48m. The incident has been resolved; the full update timeline is below.

Started
Mar 04, 2026, 07:55 PM UTC
Resolved
Mar 04, 2026, 10:44 PM UTC
Duration
2h 48m
Detected by Pingoru
Mar 04, 2026, 07:55 PM UTC

Affected components

Datapoint IngestSplunk Observability Cloud Web InterfaceSplunk Log Observer Interface

Update timeline

  1. investigating Mar 04, 2026, 07:55 PM UTC

    Users may have issues with splunk unified identity login into Splunk Observability and Splunk Log Observer. We are investigating and will provide an update shortly.

  2. investigating Mar 04, 2026, 08:25 PM UTC

    We are continuing to investigate. Additionally some users may not be able to login using standard login interface as well.

  3. identified Mar 04, 2026, 08:34 PM UTC

    We have identified the root cause of this issue and are working on fixing it. We will provide an update once we have applied the fix.

  4. identified Mar 04, 2026, 09:06 PM UTC

    We are continuing to work on a fix for this issue.

  5. identified Mar 04, 2026, 09:48 PM UTC

    In addition to the issues observed with Splunk Unified Identity, users may have also seen some ingest datapoints being dropped. We are continuing to work on a fix for this issue.

  6. monitoring Mar 04, 2026, 10:02 PM UTC

    A fix has been implemented and we are monitoring the results.

  7. resolved Mar 04, 2026, 10:44 PM UTC

    This incident has been resolved.