All Apps and Add-ons

Palo Alto Add On - Can't consume Autofocus feeds


Hi all,


I configured an EDL and URL feed from Autofocus by following the steps in  However, when I try to review the details from the macros from the link above,  no results are returned.


From the log file: /opt/splunk/var/log/splunk/Splunk_TA_paloalto_minemeld_feed.log I get the following entry for the EDL feed:

2021-01-05 15:29:16,550 ERROR pid=208666 tid=MainThread | Get error when collecting events.
Traceback (most recent call last):
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/aob_py3/modinput_wrapper/", line 128, in stream_events
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/", line 72, in collect_events
    input_module.collect_events(self, ew)
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/", line 84, in collect_events
    mmf_entries = get_feed_entries(helper, name, start, stats)
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/", line 45, in inner
    ret_val = func(*args)
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/", line 157, in get_feed_entries
    feed_entries = resp.json()
  File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/aob_py3/requests/", line 897, in json
    return complexjson.loads(self.text, **kwargs)
  File "/opt/splunk/lib/python3.7/json/", line 348, in loads
    return _default_decoder.decode(s)
  File "/opt/splunk/lib/python3.7/json/", line 340, in decode
    raise JSONDecodeError("Extra data", s, end)
json.decoder.JSONDecodeError: Extra data: line 1 column 4 (char 3)


From the URL feed, I get:

2021-01-08 12:12:19,748 ERROR pid=15255 tid=MainThread | Failed to get entries for "af_daily": 401 Client Error: Unauthorized for url:


I have verified/retried the credentials and the API key (for Autofocus) to confirm that I have the correct value.



Note: I do get results from accessing the EDL/URL feeds manually via cURL.



Please let me know what else I can try.

Labels (2)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...