Splunk incident
DNS synchronization issue affecting HEC dash DNS records | #cinc-66607_cloud_multiple(Degraded Performance)
Splunk experienced a minor incident on May 28, 2026 affecting Ingest, lasting 59m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- identified May 28, 2026, 06:22 AM UTC
Some customers are experiencing ingestion issues due to a DNS synchronization issue affecting HEC dash DNS records using the format http-inputs-${stack}.splunkcloud.com. HEC ingestion using the current dot-format DNS records, http-inputs.${stack}.splunkcloud.com, is functioning correctly. As a mitigation, customers using the dash-format HEC endpoint should update their upstream systems to use the dot-format endpoint: http-inputs.${stack}.splunkcloud.com. Our engineering teams are working to restore the affected DNS records through Zone DNS synchronization. We will provide another update once DNS synchronization has completed or if there is a meaningful change in impact.
- resolved May 28, 2026, 07:21 AM UTC
Some customers experienced traditional HEC ingestion issues due to a DNS synchronization issue affecting HEC dash DNS records using the format http-inputs-${stack}.splunkcloud.com. HEC ingestion using the current dot-format DNS records, http-inputs.${stack}.splunkcloud.com, is functioning correctly. This issue was resolved for affected customers by 07:00 UTC.