Splunk incident
Customer’s Search Heads may not be able to resolve DNS address for new Indexers | CINC-54644 (Degraded Search Performance)
Splunk experienced a minor incident on January 5, 2024 affecting Search and Index, lasting 6h 12m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- identified Jan 05, 2024, 04:43 PM UTC
We have identified an issue that may degrade search performance beginning 02:00 AM UTC January, 5th 2024. Issue is actively being mitigated and monitored. Impacted customers may see search error and/or warning messages, such as: - “Error resolving: Name or service not known Socket error: Cannot resolve hostname” - “Unknown error for indexer: [...]. Search Results might be incomplete.” Your patience is greatly appreciated and we will provide more updates as we implement the fix.
- monitoring Jan 05, 2024, 06:44 PM UTC
We have implemented a fix for this issue. During this time we are monitoring the results to confirm the resolution and will continue to provide any additional updates once available.
- monitoring Jan 05, 2024, 09:10 PM UTC
We are continuing to monitor for any further issues.
- resolved Jan 05, 2024, 10:56 PM UTC
This issue has been resolved. Teams will now begin their root cause analysis. If you believe that you are still impacted by this issue please contact customer support and reference CINC-54644.