Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Splunk Observability Cloud US0

Splunk customers using Splunk Unified Identity on v9.3.2411.117 might face issues logging into Splunk Observability Cloud

Resolved Major
September 29, 2025 - Started 7 months ago - Lasted 10 days
Official incident page

Incident Report

Splunk has identified a bug affecting all Unified Identity customers using Splunk Cloud version 9.3.2411.117 as their identity provider. Customers might be experiencing an inability to log in to Observability Cloud using the "Sign in via Splunk Cloud" workflow. The Splunk Cloud team is actively working on a solution, and the issue will be fully resolved once a patched version is released. The following workaround can be used by Customers using Unified Identity (without Centralized RBAC) until a patched version is released by the Splunk team 1. Customers using Unified Identity (without Centralized RBAC) can create a support case to have a set of users allow-listed for local login. 2. Once the users are allow-listed, the users will be able to login 3. After the patched version is released, the allowlist will be cleaned up There is no workaround for customers using Unified Identity (with Centralized RBAC) yet.

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

Start Free Trial
  • No credit card
  • 14-day trial
  • 2-minute setup
IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED 6 months ago - at 10/09/2025 08:46PM

This incident has been resolved.

IDENTIFIED 7 months ago - at 10/02/2025 06:28PM

The issue has been identified and a fix is being implemented. The expected ETA is Oct 3 (Friday) by 5 PM Pacific

INVESTIGATING 7 months ago - at 10/01/2025 10:54PM

We are currently investigating this issue.

MONITORING 7 months ago - at 10/01/2025 10:54PM

A fix has been implemented and we are monitoring the results.

INVESTIGATING 7 months ago - at 10/01/2025 05:03PM

Splunk has identified a bug affecting all Unified Identity customers using Splunk Cloud version 9.3.2411.117 as their identity provider. Customers might be experiencing an inability to log in to Observability Cloud using the "Sign in via Splunk Cloud" workflow. The Splunk Cloud team is actively working on a solution, and the issue will be fully resolved once a patched version is released.

The following workaround can be used by Customers using Unified Identity (without Centralized RBAC) until a patched version is released by the Splunk team

1. Customers using Unified Identity (without Centralized RBAC) can create a support case to have a set of users allow-listed for local login.
2. Once the users are allow-listed, the users will be able to login
3. After the patched version is released, the allowlist will be cleaned up

There is no workaround for customers using Unified Identity (with Centralized RBAC) yet.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook