All Apps and Add-ons

Palo Alto Apps SaaS Dashboard query not working

matman
New Member

I have setup a new Splunk instance with Palo Alto App 6.1 installed. Data is being received and some dashboards are populating. The SaaS dashboard however shows 0. When I edit the query and remove the where condition nodename="log.traffic.end", then data populates as expected.

If I check | tstats summariesonly=t count from datamodel="pan_firewall" GROUPBY nodename log.log_subtype I don't see a log.traffic.end nodename. If I check the data models, they are all 100% built.

Any thoughts?

0 Karma

btorresgil
Builder

Hi matman, App developers here. We'll check this out and let you know. Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...