<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215624#M23360</link>
    <description>&lt;P&gt;Are they parsed correctly meaning you see the expected fields?&lt;BR /&gt;
Next thing to try will be to look at the dashboard panel, move your mouse to the left bottom, an icon should appear to allow you to run the search.  Take a look at that search to determine where the issue is.  If the icon is not there then look at the job inspector to find the search it is running to fill the panel.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Aug 2016 18:59:13 GMT</pubDate>
    <dc:creator>kbrown_splunk</dc:creator>
    <dc:date>2016-08-09T18:59:13Z</dc:date>
    <item>
      <title>Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215614#M23350</link>
      <description>&lt;P&gt;I set up the Palo Alto Networks App for Splunk, but all of the dashboards are blank except for the overview. The firewall is configured to send the log data via syslog (not using 514 as it is already being used). I verified that I am getting traffic, threat, configuration log data, however, none of the dashboards are populating with new data other than the overview dashboard. &lt;/P&gt;

&lt;P&gt;I verified that I am getting new log data by running &lt;CODE&gt;pan_traffic&lt;/CODE&gt; and &lt;CODE&gt;pan_threat&lt;/CODE&gt; and selecting a 30 second time Window for real-time.&lt;/P&gt;

&lt;P&gt;I had this issue with 5.1.x and I upgraded to 5.2.0 since I had recently upgraded the PANOS (TA is at version 3.6.1), but the dashboards are still empty. I was prompted to set the app back up after the upgrade, but everything needed was already in the configuration file so I just clicked save. Same results, Overview works, but none of the other dashboards.&lt;/P&gt;

&lt;P&gt;Versions:&lt;BR /&gt;
Splunk: 6.3.3&lt;BR /&gt;
PAN App: 5.2.0&lt;BR /&gt;
TA: 3.6.1&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sean&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 19:47:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215614#M23350</guid>
      <dc:creator>seanbarbour</dc:creator>
      <dc:date>2016-08-08T19:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215615#M23351</link>
      <description>&lt;P&gt;Hi Sean,&lt;/P&gt;

&lt;P&gt;Have you tried going through the troubleshooting guide?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://pansplunk.readthedocs.io/en/latest/troubleshoot.html"&gt;http://pansplunk.readthedocs.io/en/latest/troubleshoot.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 23:07:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215615#M23351</guid>
      <dc:creator>panguy</dc:creator>
      <dc:date>2016-08-08T23:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215616#M23352</link>
      <description>&lt;P&gt;Yes. I checked the accelerated reports and confirmed that they were each (3) were at 100%. I chose to rebuild them in case something went wrong the first go. They have not finished yet.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 16:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215616#M23352</guid>
      <dc:creator>seanbarbour</dc:creator>
      <dc:date>2016-08-09T16:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215617#M23353</link>
      <description>&lt;P&gt;The reports finished but i am still not getting results. I did find that if I change the time range to all time I get results from last year. I had to stopped forwarding data from our firewall due to license over run, which is no longer an issue. &lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 17:23:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215617#M23353</guid>
      <dc:creator>seanbarbour</dc:creator>
      <dc:date>2016-08-09T17:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215618#M23354</link>
      <description>&lt;P&gt;Did you add &lt;/P&gt;

&lt;P&gt;no_appending_timestamp = true&lt;/P&gt;

&lt;P&gt;in inputs.conf UDP stanza?&lt;/P&gt;

&lt;P&gt;Can you also confirm clocks and timezones on the firewall and splunk server are the same.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:34:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215618#M23354</guid>
      <dc:creator>panguy</dc:creator>
      <dc:date>2020-09-29T10:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215619#M23355</link>
      <description>&lt;P&gt;Please confirm that your sourcetypes are correct.  They should start with pan:&lt;BR /&gt;
See:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://pansplunk.readthedocs.io/en/latest/getting_started.html#step-3-create-the-splunk-data-input"&gt;http://pansplunk.readthedocs.io/en/latest/getting_started.html#step-3-create-the-splunk-data-input&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also check to see if you have the your role "Indexes to search by default" with the paloalto index selected.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 18:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215619#M23355</guid>
      <dc:creator>kbrown_splunk</dc:creator>
      <dc:date>2016-08-09T18:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215620#M23356</link>
      <description>&lt;P&gt;The index is in the list of indexes to search and my inputs.conf file is as needed:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[udp://5141]
sourcetype = pan:log
no_appending_timestamp = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Aug 2016 18:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215620#M23356</guid>
      <dc:creator>seanbarbour</dc:creator>
      <dc:date>2016-08-09T18:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215621#M23357</link>
      <description>&lt;P&gt;inputs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[udp://5141]
sourcetype = pan:log
no_appending_timestamp = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Both are in the right time zone and are showing the same time.&lt;/P&gt;

&lt;P&gt;I checked out splunkd.log and found:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;08-09-2016 14:22:30.545 -0400 ERROR FrameworkUtils - Incorrect path to script: /.\bin\scripted_inputs\deploy_splunk_ta_paloalto.py.  Script must be located inside $SPLUNK_HOME/bin/scripts.
08-09-2016 14:22:30.545 -0400 ERROR ExecProcessor - Ignoring: "'/.\bin\scripted_inputs\deploy_splunk_ta_paloalto.py'
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Aug 2016 18:49:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215621#M23357</guid>
      <dc:creator>seanbarbour</dc:creator>
      <dc:date>2016-08-09T18:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215622#M23358</link>
      <description>&lt;P&gt;so if you search with just sourcetype=pan:log &lt;BR /&gt;
you get events?&lt;BR /&gt;
and those events have the expected fields?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 18:50:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215622#M23358</guid>
      <dc:creator>kbrown_splunk</dc:creator>
      <dc:date>2016-08-09T18:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215623#M23359</link>
      <description>&lt;P&gt;I get events. 3,602,097 events (Partial results for before 8/9/16 2:52:38.000 PM) ( I stopped the search)&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 18:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215623#M23359</guid>
      <dc:creator>seanbarbour</dc:creator>
      <dc:date>2016-08-09T18:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215624#M23360</link>
      <description>&lt;P&gt;Are they parsed correctly meaning you see the expected fields?&lt;BR /&gt;
Next thing to try will be to look at the dashboard panel, move your mouse to the left bottom, an icon should appear to allow you to run the search.  Take a look at that search to determine where the issue is.  If the icon is not there then look at the job inspector to find the search it is running to fill the panel.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 18:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215624#M23360</guid>
      <dc:creator>kbrown_splunk</dc:creator>
      <dc:date>2016-08-09T18:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215625#M23361</link>
      <description>&lt;P&gt;Search terms:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;None | tstats sum(bytes_sent) AS sumSent sum(bytes_received) AS sumReceived FROM pan_traffic where log_subtype=end groupby _time span=5m | timechart span=5m values("sumReceived") AS "Bytes Received" values("sumSent") AS "Bytes Sent"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is the search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats sum(bytes_sent) AS sumSent sum(bytes_received) AS sumReceived FROM pan_traffic where log_subtype=end groupby _time span=5m | timechart span=5m values("sumReceived") AS "Bytes Received" values("sumSent") AS "Bytes Sent" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Aug 2016 19:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215625#M23361</guid>
      <dc:creator>seanbarbour</dc:creator>
      <dc:date>2016-08-09T19:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk: Why are all dashboards blank except for Overview?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215626#M23362</link>
      <description>&lt;P&gt;I checked the acceleration on my install, as well. It was only at 32% so I started a rebuild.&lt;/P&gt;

&lt;P&gt;when the rebuild reached ~75% the other dashboards starting working; However, it is now at 98.63% and the other dashboards have stopped working again...&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2016 20:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Why-are-all-dashboards-blank/m-p/215626#M23362</guid>
      <dc:creator>agehring4823</dc:creator>
      <dc:date>2016-08-23T20:06:02Z</dc:date>
    </item>
  </channel>
</rss>

