Splunk incident

Customer’s Search Heads may not be able to resolve DNS address for new Indexers | CINC-54644 (Degraded Search Performance)

Minor Resolved View vendor source →

Splunk experienced a minor incident on January 5, 2024 affecting Search and Index, lasting 6h 12m. The incident has been resolved; the full update timeline is below.

Started
Jan 05, 2024, 04:43 PM UTC
Resolved
Jan 05, 2024, 10:56 PM UTC
Duration
6h 12m
Detected by Pingoru
Jan 05, 2024, 04:43 PM UTC

Affected components

SearchIndex

Update timeline

  1. identified Jan 05, 2024, 04:43 PM UTC

    We have identified an issue that may degrade search performance beginning 02:00 AM UTC January, 5th 2024. Issue is actively being mitigated and monitored. Impacted customers may see search error and/or warning messages, such as: - “Error resolving: Name or service not known Socket error: Cannot resolve hostname” - “Unknown error for indexer: [...]. Search Results might be incomplete.” Your patience is greatly appreciated and we will provide more updates as we implement the fix.

  2. monitoring Jan 05, 2024, 06:44 PM UTC

    We have implemented a fix for this issue. During this time we are monitoring the results to confirm the resolution and will continue to provide any additional updates once available.

  3. monitoring Jan 05, 2024, 09:10 PM UTC

    We are continuing to monitor for any further issues.

  4. resolved Jan 05, 2024, 10:56 PM UTC

    This issue has been resolved. Teams will now begin their root cause analysis. If you believe that you are still impacted by this issue please contact customer support and reference CINC-54644.