I have recently installed Splunk Enterprise Security v8.4 on a fresh Splunk instance after successfully using v8.2 on a previous instance. However I have an issue when using investigations. To even create an investigation I had to manually add the "default" investigation type. The issue I am having now is that the investigation pops up for a short time when refreshing the queue and then disappear after that. Is this a known issue, will this require an ESS reinstall?
@Ian0706 Your issue with investigations is actually documented in Splunk ES 8.4 under Known issues. No workaround mentioned yet. Hence, re-install of the same version won't be effective. We usually maintain n-1 versions in Splunk as a best practice to avoid such issues and going forward, please review Known issues for the version before doing a version upgrade to assess any potential impact due to upgrade.
Ref:
Known issues | Splunk Enterprise, Splunk Cloud Platform (last updated 2026-02-04T21:32:01.448Z)
>>
If this post addressed your question, you can:
Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.
>>
@Ian0706 Your issue with investigations is actually documented in Splunk ES 8.4 under Known issues. No workaround mentioned yet. Hence, re-install of the same version won't be effective. We usually maintain n-1 versions in Splunk as a best practice to avoid such issues and going forward, please review Known issues for the version before doing a version upgrade to assess any potential impact due to upgrade.
Ref:
Known issues | Splunk Enterprise, Splunk Cloud Platform (last updated 2026-02-04T21:32:01.448Z)
>>
If this post addressed your question, you can:
Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.
>>
Thank you for the help. I did not think to check for a known issues page, I guess this calls for a downgrade.
@Ian0706 No worries. Yes, since we don't have any workarounds published on this one yet.
I apologize for the awful GIF, i didn't know that it would play on a very fast repeat. However these investigations are also seen in the "mc_investigations_lookup".