Outage in Splunk Cloud

CMC Apps Data Migration Impact on Custom Dashboards | CINC-60310

Resolved Minor
April 02, 2025 - Started 3 days ago - Lasted about 18 hours
Official incident page

Need to monitor Splunk Cloud outages?
Stay on top of outages with IsDown. Monitor the official status pages of all your vendors, SaaS, and tools, including Splunk Cloud, and never miss an outage again.
Start Free Trial

Outage Details

After March 27, 2025, a modification was enacted in the CMC applications (monitoring and summarizer) that led to the migration of summary events collected by saved searches from the index:summary to the index:_cmc_summary. As a result, dashboards and reports created by customers that depend on events from index:summary are currently non-functional. Our teams are actively working on deploying a patch to restore the functionality of these dashboards and reports; however, there may appear to be a data gap from the March 27 release date through to the time the patch is applied. To regain access to data from this period, customers are required to update their customer created searches and knowledge objects by replacing the phrase (index=summary) with (index=summary OR index=_cmc_summary). This update ensures compatibility with both current and future releases. ⚠ Note: To avoid any data gaps in your dashboards after March 27th, we recommend updating your dashboards and reports. This will ensure consistent data reporting.
Components affected
Splunk Cloud Search
Latest Updates ( sorted recent to last )
RESOLVED 2 days ago - at 04/02/2025 09:13PM

On March 27th, Splunk updated the CMC app to the latest version. Some customers may be depending on indexes within this app for their custom dashboards and reports, which may no longer function due to the index name change. For more information and guidance on updating your searches, please visit https://splunk.my.site.com/customer/s/article/CMC-new-summary-index.

IDENTIFIED 3 days ago - at 04/02/2025 03:33AM

After March 27, 2025, a modification was enacted in the CMC applications (monitoring and summarizer) that led to the migration of summary events collected by saved searches from the index:summary to the index:_cmc_summary. As a result, dashboards and reports created by customers that depend on events from index:summary are currently non-functional. Our teams are actively working on deploying a patch to restore the functionality of these dashboards and reports; however, there may appear to be a data gap from the March 27 release date through to the time the patch is applied. To regain access to data from this period, customers are required to update their customer created searches and knowledge objects by replacing the phrase (index=summary) with (index=summary OR index=_cmc_summary). This update ensures compatibility with both current and future releases.

⚠ Note: To avoid any data gaps in your dashboards after March 27th, we recommend updating your dashboards and reports. This will ensure consistent data reporting.

Be the first to know when Splunk Cloud and other third-party services go down

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 3908 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook