Splunk experienced a critical incident on November 18, 2025 affecting Infrastructure, lasting 9h. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating Nov 18, 2025, 12:52 PM UTC
We are currently experiencing a KVService outage impacting services. Our teams are actively working to resolve the issue. We will provide an update within the next 60 minutes.
- investigating Nov 18, 2025, 02:01 PM UTC
We are currently experiencing a global outage impacting multiple Splunk services including Vault, KVService, Identity and Access Control (IAC), Splunk Mobile app, VictorOps, and Ingest processor, Edge processor. Customers may experience service disruptions such as login failures, lookup access issues, and degraded performance. We acknowledge the impact and are actively working with our partners to restore full service.
- investigating Nov 18, 2025, 03:30 PM UTC
We are still investigating the issue. Customers may experience service disruptions such as login failures, lookup access issues, and degraded performance. We acknowledge the impact and are actively working with our partners to restore full service.
- monitoring Nov 18, 2025, 04:34 PM UTC
Splunk continues to monitor and remediate the services affected by this issue. Several services remain impacted; however, they are currently in a recovering state. We do not have an ETA for full recovery at this time, but our teams are working to restore services as quickly as possible. We appreciate your continued patience.
- monitoring Nov 18, 2025, 05:27 PM UTC
Several Splunk services are still in a recovering state. Our teams continue to monitor progress and work through remaining backlogs to fully restore functionality. We will provide further updates as recovery advances.
- monitoring Nov 18, 2025, 06:24 PM UTC
All impacted Splunk services are back up, with a few still in recovery and monitoring. Our teams continue to work through remaining backlogs and validate full functionality across all components.
- monitoring Nov 18, 2025, 09:20 PM UTC
All impacted Splunk services are back up, with Ingest Processor still in recovery and monitoring. Our teams continue to work through remaining backlogs and validate full functionality across all components.
- resolved Nov 18, 2025, 09:52 PM UTC
All impacted services have been fully remediated. Systems are operating normally, and no further impact is expected. We will continue to monitor to ensure full service stability. Thank you for your patience throughout this incident.