<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Networks App for Splunk - Dashboards just stopped working in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371157#M44827</link>
    <description>&lt;P&gt;It does not work even if the source code is copied as it is･･&lt;BR /&gt;
There is a problem with constructing a data model, not a dashboard.&lt;/P&gt;

&lt;P&gt;If you do not understand Splunk well, we recommend that you contact support.&lt;/P&gt;</description>
    <pubDate>Sat, 01 Apr 2017 15:41:28 GMT</pubDate>
    <dc:creator>HiroshiSatoh</dc:creator>
    <dc:date>2017-04-01T15:41:28Z</dc:date>
    <item>
      <title>Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371136#M44806</link>
      <description>&lt;P&gt;Hello. I've been running this app within Splunk for a few months. I have two PANs sending syslog feeds and am capturing just about everything. All severities and URLs. The traffic and threat dashboards were populating just fine and then I open them up today and BAM. Nothing. I haven't changed a thing on either the PANs or the Splunk server. Any thoughts as to what might cause this? &lt;BR /&gt;
The first graph in traffic is "bytes transferred over time". It just says "Search is waiting for input" and when I click on the little "i" it says "Unknown sid". &lt;/P&gt;

&lt;P&gt;Thanks in advance! &lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 23:13:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371136#M44806</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-22T23:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371137#M44807</link>
      <description>&lt;P&gt;Did you see troubleshooting?&lt;BR /&gt;
Please read the data model part.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://pansplunk.readthedocs.io/en/latest/troubleshoot.html"&gt;http://pansplunk.readthedocs.io/en/latest/troubleshoot.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Check acceleration settings in the data model under Settings &amp;gt; Data Model &amp;gt; and fine the Palo Alto Networks datamodels. (There may be 1 or 3 datamodels depending on the App version)&lt;/P&gt;

&lt;P&gt;Settings&amp;gt;Data models&amp;gt;Palo Alto Networks FirewallLogs&lt;BR /&gt;
ACCELERATION&amp;gt;Rebuild&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2663iF83FC853502B7B0A/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 02:00:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371137#M44807</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2017-03-23T02:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371138#M44808</link>
      <description>&lt;P&gt;Thanks for your response, HiroshiSatoh! &lt;/P&gt;

&lt;P&gt;I followed all troubleshooting methods contained in the link you provided. The times are synced on the PAN and the Splunk, the config files are correct, the acceleration settings for the 3 models related to the app is correct. The logs are coming in, appear to be correct. The search "eventtype=pan" produces logs coming in, in real-time. The overview dashboard is populated, as are every other one. So, I'm still stuck with the Traffic and Threat dashboards not populating. &lt;/P&gt;

&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 22:35:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371138#M44808</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-23T22:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371139#M44809</link>
      <description>&lt;P&gt;The overview dashboard searches direct logs, but Traffic and Threat dashboards uses a data model.&lt;BR /&gt;
How about rebuilding the data model?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 03:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371139#M44809</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2017-03-24T03:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371140#M44810</link>
      <description>&lt;P&gt;Ok. That's new to me but I will look it up. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 04:49:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371140#M44810</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-24T04:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371141#M44811</link>
      <description>&lt;P&gt;Hello. I've rebuilt all of the data models and the dashboards are still not populating. I've set the time value to "all time" and am not seeing anything. Please let me know what else I should try. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 21:01:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371141#M44811</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-24T21:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371142#M44812</link>
      <description>&lt;P&gt;Hello. I've rebuilt all of the data models and the dashboards are still not populating. I've set the time value to "all time" and am not seeing anything. Please let me know what else I should try. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 21:03:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371142#M44812</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-24T21:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371143#M44813</link>
      <description>&lt;P&gt;Can I search with this search sentence? Is field extraction done?&lt;/P&gt;

&lt;P&gt;index=XXX (Sourcetype = pan_traffic OR sourcetype = pan: traffic)&lt;/P&gt;

&lt;P&gt;※Field definition↓&lt;BR /&gt;
[extract_traffic]&lt;BR /&gt;
DELIMS = ","&lt;BR /&gt;
FIELDS = "future_use1","receive_time","serial_number","type","log_subtype","future_use2","generated_time","src_ip","dest_ip","src_translated_ip","dest_translated_ip","rule","src_user","dest_user","app","virtual_system","src_zone","dest_zone","src_interface","dest_interface","log_forwarding_profile","future_use3","session_id","repeat_count","src_port","dest_port","src_translated_port","dest_translated_port","flags","protocol","action","bytes","bytes_out","bytes_in","packets","start_time","duration","category","future_use4","sequence_number","action_flags","src_location","dest_location","future_use5","packets_out","packets_in","session_end_reason","devicegroup_level1","devicegroup_level2","devicegroup_level3","devicegroup_level4","vsys_name","dvc_host","action_source"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:21:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371143#M44813</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2020-09-29T13:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371144#M44814</link>
      <description>&lt;P&gt;Index=main sourcetype="pan:traffic" yields many results. &lt;BR /&gt;
&lt;IMG src="http://imgur.com/X6dvs85" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 20:41:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371144#M44814</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-27T20:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371145#M44815</link>
      <description>&lt;P&gt;&lt;A href="http://imgur.com/X6dvs85"&gt;http://imgur.com/X6dvs85&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 20:42:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371145#M44815</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-27T20:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371146#M44816</link>
      <description>&lt;P&gt;It is caused by failing to ACCELERATION the data model and create the summary.&lt;BR /&gt;
I do not recommend it, but I think that it will be displayed if you change the search macro.&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;summariesonly=t&lt;BR /&gt;
↓&lt;/P&gt;

&lt;H2&gt;summariesonly=f&lt;/H2&gt;</description>
      <pubDate>Tue, 28 Mar 2017 13:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371146#M44816</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2017-03-28T13:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371147#M44817</link>
      <description>&lt;P&gt;I'm sorry, I don't understand your recommendation. Are there any log files that might give me more information? Should I consider uninstalling and reinstalling the Palo Alto addon? Please let me know how we can try to move forward. I need to get those dashboards running as soon as possible and I don't want to lose any data in the meantime. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 19:41:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371147#M44817</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-28T19:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371148#M44818</link>
      <description>&lt;P&gt;Also, if you could add as many things to try as possible in the next thread that would be much appreciated. I'm coming up on a deadline here. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 22:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371148#M44818</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-28T22:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371149#M44819</link>
      <description>&lt;P&gt;I think that it is caused by insufficient memory and can not ACCELERATION.&lt;/P&gt;

&lt;P&gt;Can I execute this search statement?&lt;/P&gt;

&lt;P&gt;|tstats summariesonly=f sum(log.bytes_out) AS sumSent sum(log.bytes_in) AS sumReceived FROM datamodel="pan_firewall" WHERE nodename="log.traffic.end" groupby _time span=5m | timechart span=5m values("sumReceived") AS "Bytes Received" values("sumSent") AS "Bytes Sent"&lt;/P&gt;

&lt;P&gt;Panel「Bytes Transfered Over Time」search sentence.&lt;/P&gt;

&lt;P&gt;summariesonly=t&lt;BR /&gt;
↓&lt;BR /&gt;
summariesonly=f&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:25:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371149#M44819</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2020-09-29T13:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371150#M44820</link>
      <description>&lt;P&gt;I had to switch to verbose mode, but that search worked. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://imgur.com/a/mzS5Q"&gt;http://imgur.com/a/mzS5Q&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 17:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371150#M44820</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-29T17:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371151#M44821</link>
      <description>&lt;P&gt;and what does this mean at the end of each of your transmissions?&lt;/P&gt;

&lt;P&gt;"summariesonly=t&lt;BR /&gt;
↓&lt;BR /&gt;
summariesonly=f"&lt;/P&gt;

&lt;P&gt;Where am I supposed to find that?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 17:42:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371151#M44821</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-29T17:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371152#M44822</link>
      <description>&lt;P&gt;You can change it from here.&lt;BR /&gt;
Settings&amp;gt;Advanced search&amp;gt;Search macros&lt;BR /&gt;
・_pan_dropdown(2)&lt;BR /&gt;
・_pan_ep_dropdown(2)&lt;BR /&gt;
・pan_tstats&lt;/P&gt;

&lt;P&gt;※But this is a workaround. It is not a root cause solution.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:25:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371152#M44822</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2020-09-29T13:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371153#M44823</link>
      <description>&lt;P&gt;Ok. Did you see my previous responses? The Bytes Transfered Over Time search worked just fine. I also watched my working memory on the server while I brought up the Traffic Dashboard. There was plenty of available RAM on the server. &lt;BR /&gt;
Next thoughts, please? Since I'm only able to get one response per day, please put as many things to try as possible in your responses. &lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 15:12:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371153#M44823</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-30T15:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371154#M44824</link>
      <description>&lt;P&gt;I changed the search macros to "summariesonly=f". Traffic dashboard still does not work&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 17:20:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371154#M44824</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2017-03-30T17:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks App for Splunk - Dashboards just stopped working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371155#M44825</link>
      <description>&lt;P&gt;I put in the following query, copied directly from your source code in the Traffic Dashboard:&lt;BR /&gt;
| &lt;CODE&gt;pan_tstats&lt;/CODE&gt; sum(log.bytes_out) AS sumSent sum(log.bytes_in) AS sumReceived FROM &lt;CODE&gt;node(log.traffic.end)&lt;/CODE&gt; $action$ $src_ip$ $dest_ip$ $dest_port$ "$user|s$" $app$ groupby _time span=5m | timechart span=5m values("sumReceived") AS "Bytes Received" values("sumSent") AS "Bytes Sent"&lt;/P&gt;

&lt;P&gt;I get this error:&lt;/P&gt;

&lt;P&gt;Error in 'TsidxStats': WHERE clause is not an exact query&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:26:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-App-for-Splunk-Dashboards-just-stopped/m-p/371155#M44825</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2020-09-29T13:26:07Z</dc:date>
    </item>
  </channel>
</rss>

