Thycotic incident

Platform: US - Audit Event Processing Delays

Minor Resolved View vendor source →

Thycotic experienced a minor incident on July 21, 2026 affecting Platform and Secret Server Cloud, lasting 1d 18h. The incident has been resolved; the full update timeline is below.

Started
Jul 21, 2026, 09:55 PM UTC
Resolved
Jul 23, 2026, 03:57 PM UTC
Duration
1d 18h
Detected by Pingoru
Jul 21, 2026, 09:55 PM UTC

Affected components

PlatformSecret Server Cloud

Update timeline

  1. monitoring Jul 21, 2026, 09:55 PM UTC

    We are experiencing delays in audit event processing for customers in our US East region. Audit logs and audit activity may appear delayed or incomplete in the Delinea Platform and Secret Server Cloud interfaces. No audit events are being lost. All events are captured and will be processed. Core product functionality including secret access, authentication, and password management is not affected. Our engineering team has identified the root cause and has scaled database and processing resources to address the backlog. The backlog is actively draining.

  2. resolved Jul 23, 2026, 03:57 PM UTC

    The audit event processing backlog affecting customers in our US East region has been fully cleared. Audit logs are now current and up to date. No audit events were lost during this period. Thank you for your patience.

  3. postmortem Aug 20, 2026, 11:48 AM UTC

    ### Incident Overview On July 20, 2026, a subset of Delinea Platform customers in the US region experienced delays in audit event processing, resulting in a lag between when actions occurred and when the corresponding audit events appeared in logs. * Start: July 20, 2026, 10:54 AM UTC * End: July 23, 2026, 3:58 PM UTC ### Root Cause and Remediation The incident was caused by an increase in audit event volume following a recent Secret Server release, which exceeded the processing capacity of the audit event pipeline in the US region. As volume grew, events were queued for processing rather than delivered in real time, causing a backlog and a corresponding delay in audit log availability. No audit events were lost during this incident. Our engineering team scaled the underlying data processing capacity to work through the backlog while monitoring queue depth and processing rates. By July 23, 2026, all delayed events had been fully processed, audit logs were current, and normal operations had resumed. ### Preventative Actions * Improve automated scaling to the audit event pipeline so it can absorb increases in volume without creating a backlog or delaying log availability. * Improve monitoring and alerting audit processing volume and queue depth to detect potential delays earlier and respond before customers are impacted. We sincerely apologize for the disruption this caused and the inconvenience to your operations. We are committed to preventing recurrence through the above actions.