All Apps and Add-ons

Palo Alto Networks Add-on Configuration issue

chfeussner
Engager

The Palo Alto Splunk app has been updated to version 6.0.1. When we go "Add-on settings" and "Account" the page loads forever. We double-checked that data is in the system, which is fine. How can we solve this issue, what troubleshooting steps are available?

thx.

0 Karma
1 Solution

chfeussner
Engager
0 Karma

chfeussner
Engager

solved, thanks.

0 Karma

iarnopagliani
New Member

How did you solve?
Thanks

0 Karma

jstocker
New Member

Any update on how this was solved? I'm running Splunk 8.0.1 with v6.2.0 of the Palo Alto TA.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@chfeussner, To help future readers, please accept an answer or add a new answer with your solution and accept that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

I have seen this behavior before when there is a passwords.conf entry that is both exported globally and contains special characters that cannot be processed by the /storage/passwords endpoint. From the search bar in the Palo Alto App, run this command:
| rest "/services/storage/passwords?output_mode=json" | table clear_password
If you look through that list, it should show passwords from other TA's that have exported their passwords.conf (or all their KOs) globally - and some of those might contain those special characters causing that REST endpoint to throw errors, which in turn causes the screen to never load.
The other way to verify this is to open that setup page in Chrome and open Chrome dev tools, and look at the "network" tab to see if you're getting 500 errors from some of the AJAX calls.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...