I have setup a new Splunk instance with Palo Alto App 6.1 installed. Data is being received and some dashboards are populating. The SaaS dashboard however shows 0. When I edit the query and remove the where condition nodename="log.traffic.end", then data populates as expected.
If I check | tstats summariesonly=t count from datamodel="pan_firewall" GROUPBY nodename log.log_subtype I don't see a log.traffic.end nodename. If I check the data models, they are all 100% built.
Any thoughts?
Hi matman, App developers here. We'll check this out and let you know. Thanks!