<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto App's Dashboards not showing any data. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515322#M63102</link>
    <description>&lt;P&gt;Hi R&lt;SPAN&gt;ichgalloway,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Nothing happens when I enabled the acceleration of all the datamodels and they build 100%.&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2020 22:43:42 GMT</pubDate>
    <dc:creator>ssharma09</dc:creator>
    <dc:date>2020-08-20T22:43:42Z</dc:date>
    <item>
      <title>Palo Alto App's dashboards not showing any data (App version 6.1.1, TA version 6.1.1, Splunk version 7.2.9).</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515108#M63100</link>
      <description>&lt;P&gt;I can't see any dashboard showing numbers (data) in Palo Alto App.&lt;/P&gt;
&lt;P&gt;- App version 6.1.1 &amp;amp; TA version 6.1.1&lt;/P&gt;
&lt;P&gt;- Splunk version 7.2.9&lt;/P&gt;
&lt;P&gt;- Data is being ingested from Syslog &amp;gt; UF to Splunk Cloud.&lt;/P&gt;
&lt;P&gt;- Data can be searched at Splunk from sourcetypes: pan:traffic, pan:system, pan:threat&lt;/P&gt;
&lt;P&gt;- Data model :&amp;nbsp;&lt;SPAN&gt;pan_firewall is accelerated and built 100%. (there was no data in other datamodels so I&amp;nbsp; disabled the acceleration on them)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;one of the search query from dashboard : Network Security&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;| tstats summariesonly=t count FROM datamodel="pan_firewall" WHERE&lt;STRONG&gt; nodename&lt;/STRONG&gt;="log.correlation" GROUPBY log.severity log.threat_category log.threat_name | rename log.* AS * | stats sum(count) AS count by threat_name threat_category severity&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*I'm wondering the field &lt;STRONG&gt;nodename (&lt;/STRONG&gt;not found in the datamodel), is being used in many other panels' search query which might be causing the issue. If so, how to fix that?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please advise. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 22:41:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515108#M63100</guid>
      <dc:creator>ssharma09</dc:creator>
      <dc:date>2020-09-25T22:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto App's Dashboards not showing any data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515210#M63101</link>
      <description>&lt;P&gt;The Palo Alto app makes extensive use of accelerated datamodels.&amp;nbsp; By turning off accelerations you have disabled some panels.&lt;/P&gt;&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;nodename&lt;/FONT&gt; keyword identifies a child within the datamodel rather than a field.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 13:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515210#M63101</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-20T13:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto App's Dashboards not showing any data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515322#M63102</link>
      <description>&lt;P&gt;Hi R&lt;SPAN&gt;ichgalloway,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Nothing happens when I enabled the acceleration of all the datamodels and they build 100%.&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 22:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515322#M63102</guid>
      <dc:creator>ssharma09</dc:creator>
      <dc:date>2020-08-20T22:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto App's Dashboards not showing any data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515440#M63111</link>
      <description>What do you mean by "nothing happens"? Apparently, something happens if the DMAs are successful.&lt;BR /&gt;Do the datamodels have data? No panel will work if there is no data to display. Are the DMs looking in the right indexes?</description>
      <pubDate>Fri, 21 Aug 2020 12:48:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515440#M63111</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-21T12:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto App's Dashboards not showing any data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515664#M63126</link>
      <description>&lt;P&gt;I'm concern about the dashboards which are using DM&amp;nbsp;&lt;SPAN&gt;pan_firewalland it is100% bild and has data in it but still those dashboards are not showing any data.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 22:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515664#M63126</guid>
      <dc:creator>ssharma09</dc:creator>
      <dc:date>2020-08-23T22:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto App's Dashboards not showing any data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515782#M63130</link>
      <description>You may need to debug the dashboard queries. Pick one and copy it into a search window. Delete everything after the first pipe (|) and run the search and verify the results. If it works then add the next pipe and repeat the process until you get no results. The last pipe added likely will be the cause of the problem. Perhaps you don't have a field or value the search expects.&lt;BR /&gt;Once you've identified the problem, correct the search to work in your environment.</description>
      <pubDate>Mon, 24 Aug 2020 13:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515782#M63130</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-24T13:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto App's Dashboards not showing any data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515949#M63143</link>
      <description>&lt;P&gt;I picked the search&lt;/P&gt;&lt;P&gt;WHERE nodename="log.correlation" GROUPBY log.severity log.threat_category log.threat_name | rename log.* AS * | stats sum(count) AS count by threat_name threat_category severity&lt;/P&gt;&lt;P&gt;and remove every thing after first pipe : result &amp;gt; no data&lt;/P&gt;&lt;P&gt;then, I just ran&amp;nbsp; :&amp;nbsp;| tstats summariesonly=t count FROM datamodel="pan_firewall"&lt;/P&gt;&lt;P&gt;it showed me data.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 07:20:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/515949#M63143</guid>
      <dc:creator>ssharma09</dc:creator>
      <dc:date>2020-08-25T07:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto App's Dashboards not showing any data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/516019#M63145</link>
      <description>&lt;P&gt;The tstats command you ran was partial, but still helpful.&amp;nbsp; It shows there is data in the accelerated datamodel.&lt;/P&gt;&lt;P&gt;Next, please run the complete tstats command&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats summariesonly=t count FROM datamodel="pan_firewall" WHERE nodename="log.correlation" GROUPBY log.severity log.threat_category log.threat_name &lt;/LI-CODE&gt;&lt;P&gt;If that returns no results then I suspect your data is missing one or more of the severity, threat_category, or threat_name fields.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 13:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/516019#M63145</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-25T13:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto App's Dashboards not showing any data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/518950#M63408</link>
      <description>&lt;P&gt;I'm in the exact same boat, guys. I put in just:&lt;/P&gt;&lt;P&gt;| tstats summariesonly=t count FROM datamodel="pan_firewall"&lt;/P&gt;&lt;P&gt;And I get data. When I put in:&lt;/P&gt;&lt;P&gt;| tstats summariesonly=t count FROM datamodel="pan_firewall" WHERE nodename="log.correlation" GROUPBY log.severity log.threat_category log.threat_name&lt;/P&gt;&lt;P&gt;I get nothing. I tried adding each argument in from the beginning and it immediately fails at the nodename designation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 20:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-App-s-dashboards-not-showing-any-data-App-version-6-1/m-p/518950#M63408</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2020-09-10T20:08:15Z</dc:date>
    </item>
  </channel>
</rss>

