Known issues

The following tables include issues and workarounds for releases of Splunk Enterprise Security. Issues are listed in all relevant sections. Some issues appear more than once.

Splunk Enterprise Security 8.7.0 known issues

Known issues in Splunk Enterprise Security release 8.7.0

Following are some of the known issues in this Splunk Enterprise Security version:

Date created Issue Description
05-19-2025 SECHELP-29

Error Definition is invalid error is displayed when you try to access a modified dashboard after upgrading to ES version 8.0.40 or higher.

Workaround: If a dashboard displays Definition is invalid error, close the error message, edit the dashboard in the UI, make a small change, and save. This updates the definition to the new schema. You can revert the change and save again if required.

07-08-2026 SECHELP-689 Multiple findings are not deselected when you select the "Save" button in Splunk Enterprise Security version 8.5.1.
07-27-2026 SECHELP-727

Your role must not possess the managed capabilities that are assigned using the Roles and capabilities page in Splunk Enterprise Security. For example, if you want to provide managed access for editing lookups to the role: Edit lookups, this role cannot consist of edit_managed_configurations capability, which can trigger and update the configuration of the lookup.

For example if a user intend to provide "Edit lookups" managed access, the role should not consist of edit_managed_configurations, edit_lookups capabilities for the workflow action to trigger and update the configuration. For more information, see Manage capabilities for a role.

Date created Issue Description
08-28-2026 ARI-619

Watermark on all world maps on Entity Analysis Page