<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1 in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188018#M19032</link>
    <description>&lt;P&gt;I opened a case with splunk. The built in data models work but they aren't accelerated. &lt;/P&gt;

&lt;P&gt;When I turn off acceleration in the PAN App, I don't get the errors from my indexers. Of course the pivots will take forever and the dashboards relay on acceleration so that's useless but at least I can now assume that the problem is data model acceleration.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jun 2014 00:12:09 GMT</pubDate>
    <dc:creator>dfronck</dc:creator>
    <dc:date>2014-06-19T00:12:09Z</dc:date>
    <item>
      <title>Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188015#M19029</link>
      <description>&lt;P&gt;I installed the Splunk for Palo Alto Networks app. I am getting data and my index and source types are correct. When I do searches, all the PA fields are getting extracted.&lt;/P&gt;

&lt;P&gt;However, I only the Overview dashboard works; it displays real-time information.&lt;/P&gt;

&lt;P&gt;The other dashboards and sub-dashboards under Traffic, Threat, Content and System all say "Search is waiting for input..." and the drop downs all say "Search produced no results."&lt;/P&gt;

&lt;P&gt;We are using a cluster so the app in installed on the heavy forwarder that receives the logs and a search head that can search all of our indexers.&lt;/P&gt;

&lt;P&gt;EDIT: Just realized that the heavy forwarder is still running v6.0.3. Maybe that's the issue. Upgrading tonight to find out.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2014 13:29:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188015#M19029</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2014-06-04T13:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188016#M19030</link>
      <description>&lt;P&gt;Didn't get to upgrade the forwarder but I don't see why that would cause an issue anyway.&lt;/P&gt;

&lt;P&gt;If I use Pivot or go to PAN App search and enter (with back quotes around the search)&lt;BR /&gt;
  | &lt;CODE&gt;_pan_dropdown(log.traffic.end, log.app)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I get the following error from all of my indexers.&lt;/P&gt;

&lt;P&gt;[index_server] The search for datamodel 'pan_logs' failed to parse, cannot get indexes to search&lt;/P&gt;

&lt;P&gt;Yet there are 300gb in /opt/splunk/var/lib/splunk/pan_logs/datamodel_summary on all of my indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188016#M19030</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2020-09-28T16:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188017#M19031</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I don't think this app works if your indexers are clustered.&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;I installed the app on my search head pool, heavy forwarders and indexers. As I stated above, on the search heads, I only get data in the Overview Dashboard.&lt;/P&gt;

&lt;P&gt;Using the app on the indexers, I get data on all of the dashboards but it's fairly useless because I only get the data that's on that singe indexer in the cluster.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2014 02:48:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188017#M19031</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2014-06-10T02:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188018#M19032</link>
      <description>&lt;P&gt;I opened a case with splunk. The built in data models work but they aren't accelerated. &lt;/P&gt;

&lt;P&gt;When I turn off acceleration in the PAN App, I don't get the errors from my indexers. Of course the pivots will take forever and the dashboards relay on acceleration so that's useless but at least I can now assume that the problem is data model acceleration.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2014 00:12:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188018#M19032</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2014-06-19T00:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188019#M19033</link>
      <description>&lt;P&gt;Let us know what support says. I am having this same exact issue.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2014 19:20:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188019#M19033</guid>
      <dc:creator>trademarq</dc:creator>
      <dc:date>2014-06-20T19:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188020#M19034</link>
      <description>&lt;P&gt;Trouble shooting with Splunk showed that I can go to the PAN App Search and enter "| datamodel pan_logs" and get results back.&lt;/P&gt;

&lt;P&gt;I also enabled acceleration on the built in apps and they worked.&lt;/P&gt;

&lt;P&gt;Support says the problem is in the App.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jun 2014 23:27:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188020#M19034</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2014-06-28T23:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188021#M19035</link>
      <description>&lt;P&gt;Looking at the search.log on the indexer shows, that the macro can not be found on the indexer:&lt;/P&gt;

&lt;P&gt;06-30-2014 14:49:08.773 ERROR TsidxStats - Error in 'SearchParser': Could not find macro 'pan_index' that takes 0 arguments. Expecting stanza name 'pan_index'.&lt;BR /&gt;
06-30-2014 14:49:08.773 INFO  TsidxStats - Could not obtain a valid set of indexes to search&lt;/P&gt;

&lt;P&gt;I fixed the problem with modifying the data model root object constraint from "&lt;CODE&gt;pan_index&lt;/CODE&gt;" to "index=pan_logs".&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:57:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188021#M19035</guid>
      <dc:creator>my2ndhead</dc:creator>
      <dc:date>2020-09-28T16:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188022#M19036</link>
      <description>&lt;P&gt;Thanks my2ndhead! That fixed it. It looks like the macro is not working so explicitly setting the root constraint to index=pan_logs "fixes" that.&lt;/P&gt;

&lt;P&gt;If you're having this problem, here are the steps to fix it.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Go to Data Models for the SplunkforPaloAltoNetworks app.&lt;/LI&gt;
&lt;LI&gt;Select Edit/Edit Acceleration and turn off acceleration.&lt;/LI&gt;
&lt;LI&gt;Then click "Palo Alto Networks Logs".&lt;/LI&gt;
&lt;LI&gt;Edit the "pan_index" constraint.&lt;/LI&gt;
&lt;LI&gt;Change "&lt;CODE&gt;pan_index" to index=&lt;/CODE&gt;pan_logs and save.&lt;/LI&gt;
&lt;LI&gt;Click "Back to Data Models".&lt;/LI&gt;
&lt;LI&gt;Select Edit/Edit Acceleration and turn on acceleration and set the Summary Range.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;All of the dashboards are working now.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 15:30:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188022#M19036</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2014-06-30T15:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188023#M19037</link>
      <description>&lt;P&gt;Thanks for this, but let me add, if you have a search head and multiple indexers, make the change on your search head, re-deploy the updated app to your indexers so they all receive the updated data model.&lt;/P&gt;

&lt;P&gt;Thanks  dfronck - your solution helped!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 20:42:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188023#M19037</guid>
      <dc:creator>emalenfant</dc:creator>
      <dc:date>2014-07-03T20:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Only the Overview dashboard has data PAN-App v4.1.1 Splunk v6.1.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188024#M19038</link>
      <description>&lt;P&gt;This change is no longer needed in version 4.1.2 and higher.  These versions of the Palo Alto Networks app contain the change already.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2014 23:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Only-the-Overview-dashboard-has-data-PAN-App-v4-1-1-Splunk-v6-1/m-p/188024#M19038</guid>
      <dc:creator>btorresgil</dc:creator>
      <dc:date>2014-10-10T23:44:31Z</dc:date>
    </item>
  </channel>
</rss>

