April 2026: Service Advisory: KVservice issues impacting Enterprise Security search performance
A KVservice issue in Splunk Cloud impacted Enterprise Security search performance for 1.3 hours, affecting ad-hoc, saved, and scheduled searches, particularly those using lookup commands for KV collections. Users experienced inability to save searches within the ES application, errors updating application settings like credentials, and failures in Mission Control and Analyst Queue dashboards. The engineering team identified the root cause and successfully implemented a fix, restoring full operational status to all searches and dashboards.