All Apps and Add-ons

Palo Alto Add On - Can't consume Autofocus feeds


Hi all,


I configured an EDL and URL feed from Autofocus by following the steps in  However, when I try to review the details from the macros from the link above,  no results are returned.


From the log file: /opt/splunk/var/log/splunk/Splunk_TA_paloalto_minemeld_feed.log I get the following entry for the EDL feed:

2021-01-05 15:29:16,550 ERROR pid=208666 tid=MainThread | Get error when collecting events.
Traceback (most recent call last):
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/aob_py3/modinput_wrapper/", line 128, in stream_events
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/", line 72, in collect_events
    input_module.collect_events(self, ew)
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/", line 84, in collect_events
    mmf_entries = get_feed_entries(helper, name, start, stats)
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/", line 45, in inner
    ret_val = func(*args)
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/", line 157, in get_feed_entries
    feed_entries = resp.json()
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/aob_py3/requests/", line 897, in json
    return complexjson.loads(self.text, **kwargs)
  File "/opt/splunk/lib/python3.7/json/", line 348, in loads
    return _default_decoder.decode(s)
  File "/opt/splunk/lib/python3.7/json/", line 340, in decode
    raise JSONDecodeError("Extra data", s, end)
json.decoder.JSONDecodeError: Extra data: line 1 column 4 (char 3)


From the URL feed, I get:

2021-01-08 12:12:19,748 ERROR pid=15255 tid=MainThread | Failed to get entries for "af_daily": 401 Client Error: Unauthorized for url:


I have verified/retried the credentials and the API key (for Autofocus) to confirm that I have the correct value.



Note: I do get results from accessing the EDL/URL feeds manually via cURL.



Please let me know what else I can try.

Labels (2)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...