Splunk incident

DNS synchronization issue affecting HEC dash DNS records | #cinc-66607_cloud_multiple(Degraded Performance)

Minor Resolved View vendor source →

Splunk experienced a minor incident on May 28, 2026 affecting Ingest, lasting 59m. The incident has been resolved; the full update timeline is below.

Started
May 28, 2026, 06:22 AM UTC
Resolved
May 28, 2026, 07:21 AM UTC
Duration
59m
Detected by Pingoru
May 28, 2026, 06:22 AM UTC

Affected components

Ingest

Update timeline

  1. identified May 28, 2026, 06:22 AM UTC

    Some customers are experiencing ingestion issues due to a DNS synchronization issue affecting HEC dash DNS records using the format http-inputs-${stack}.splunkcloud.com. HEC ingestion using the current dot-format DNS records, http-inputs.${stack}.splunkcloud.com, is functioning correctly. As a mitigation, customers using the dash-format HEC endpoint should update their upstream systems to use the dot-format endpoint: http-inputs.${stack}.splunkcloud.com. Our engineering teams are working to restore the affected DNS records through Zone DNS synchronization. We will provide another update once DNS synchronization has completed or if there is a meaningful change in impact.

  2. resolved May 28, 2026, 07:21 AM UTC

    Some customers experienced traditional HEC ingestion issues due to a DNS synchronization issue affecting HEC dash DNS records using the format http-inputs-${stack}.splunkcloud.com. HEC ingestion using the current dot-format DNS records, http-inputs.${stack}.splunkcloud.com, is functioning correctly. This issue was resolved for affected customers by 07:00 UTC.