Splunk incident

Multiple Services Outage

Critical Resolved View vendor source →

Splunk experienced a critical incident on November 18, 2025 affecting Infrastructure, lasting 9h. The incident has been resolved; the full update timeline is below.

Started
Nov 18, 2025, 12:52 PM UTC
Resolved
Nov 18, 2025, 09:52 PM UTC
Duration
9h
Detected by Pingoru
Nov 18, 2025, 12:52 PM UTC

Affected components

Infrastructure

Update timeline

  1. investigating Nov 18, 2025, 12:52 PM UTC

    We are currently experiencing a KVService outage impacting services. Our teams are actively working to resolve the issue. We will provide an update within the next 60 minutes.

  2. investigating Nov 18, 2025, 02:01 PM UTC

    We are currently experiencing a global outage impacting multiple Splunk services including Vault, KVService, Identity and Access Control (IAC), Splunk Mobile app, VictorOps, and Ingest processor, Edge processor. Customers may experience service disruptions such as login failures, lookup access issues, and degraded performance. We acknowledge the impact and are actively working with our partners to restore full service.

  3. investigating Nov 18, 2025, 03:30 PM UTC

    We are still investigating the issue. Customers may experience service disruptions such as login failures, lookup access issues, and degraded performance. We acknowledge the impact and are actively working with our partners to restore full service.

  4. monitoring Nov 18, 2025, 04:34 PM UTC

    Splunk continues to monitor and remediate the services affected by this issue. Several services remain impacted; however, they are currently in a recovering state. We do not have an ETA for full recovery at this time, but our teams are working to restore services as quickly as possible. We appreciate your continued patience.

  5. monitoring Nov 18, 2025, 05:27 PM UTC

    Several Splunk services are still in a recovering state. Our teams continue to monitor progress and work through remaining backlogs to fully restore functionality. We will provide further updates as recovery advances.

  6. monitoring Nov 18, 2025, 06:24 PM UTC

    All impacted Splunk services are back up, with a few still in recovery and monitoring. Our teams continue to work through remaining backlogs and validate full functionality across all components.

  7. monitoring Nov 18, 2025, 09:20 PM UTC

    All impacted Splunk services are back up, with Ingest Processor still in recovery and monitoring. Our teams continue to work through remaining backlogs and validate full functionality across all components.

  8. resolved Nov 18, 2025, 09:52 PM UTC

    All impacted services have been fully remediated. Systems are operating normally, and no further impact is expected. We will continue to monitor to ensure full service stability. Thank you for your patience throughout this incident.