Known issues

The following tables include issues and workarounds for releases of Splunk Enterprise Security. Issues are listed in all relevant sections. Some issues appear more than once.

Splunk Enterprise Security 8.1.1 known issues

A list of key known issues in this version of Splunk Enterprise.

This section includes issues and workarounds for the 8.1.1 release of Splunk Enterprise Security. Issues are listed in all relevant sections. Some issues appear more than once.

Date filedIssue numberDescription
08-11-2025SOLNESS-52053Two RIR detections are disabled after upgrading to ES version 8.1. Workaround:
  1. Navigate to Content Management in Splunk Enterprise Security.
  2. Locate the following detections: 1. Risk Threshold Exceeded For Object Over 24 Hour Period 2. ATTACK Tactic Threshold Exceeded For Object Over Previous 7 Days
  3. Identify the “Most Recently Used” version: This is shown in the Version column on the Content Management page by default. It is also the version displayed by default in the Detection editor page when you select the detection.
  4. Re-enable the correct version: If the most recently used version displays as Disabled, select it and toggle it to Enabled.
  5. Save your changes: Confirm that the detections are active in the Content Management page.

Splunk Enterprise Security 8.1.0 known issues

A list of key known issues in this version of Splunk Enterprise Security.

This section includes issues and workarounds for the 8.1.0 release of Splunk Enterprise Security. Issues are listed in all relevant sections. Some issues appear more than once.

Date filedIssue numberDescription
08-11-2025SOLNESS-52053Two RIR detections are disabled after upgrading to ES version 8.1. Workaround:
  1. Navigate to Content Management in Splunk Enterprise Security.
  2. Locate the following detections: 1. Risk Threshold Exceeded For Object Over 24 Hour Period 2. ATTACK Tactic Threshold Exceeded For Object Over Previous 7 Days
  3. Identify the “Most Recently Used” version: This is shown in the Version column on the Content Management page by default. It is also the version displayed by default in the Detection editor page when you select the detection.
  4. Re-enable the correct version: If the most recently used version displays as Disabled, select it and toggle it to Enabled.
  5. Save your changes: Confirm that the detections are active in the Content Management page.