All Apps and Add-ons

Palo Alto Networks Add-on Configuration issue

chfeussner
Engager

The Palo Alto Splunk app has been updated to version 6.0.1. When we go "Add-on settings" and "Account" the page loads forever. We double-checked that data is in the system, which is fine. How can we solve this issue, what troubleshooting steps are available?

thx.

0 Karma
1 Solution

chfeussner
Engager
0 Karma

chfeussner
Engager

solved, thanks.

0 Karma

iarnopagliani
New Member

How did you solve?
Thanks

0 Karma

jstocker
New Member

Any update on how this was solved? I'm running Splunk 8.0.1 with v6.2.0 of the Palo Alto TA.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@chfeussner, To help future readers, please accept an answer or add a new answer with your solution and accept that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

panguy
Contributor
0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

I have seen this behavior before when there is a passwords.conf entry that is both exported globally and contains special characters that cannot be processed by the /storage/passwords endpoint. From the search bar in the Palo Alto App, run this command:
| rest "/services/storage/passwords?output_mode=json" | table clear_password
If you look through that list, it should show passwords from other TA's that have exported their passwords.conf (or all their KOs) globally - and some of those might contain those special characters causing that REST endpoint to throw errors, which in turn causes the screen to never load.
The other way to verify this is to open that setup page in Chrome and open Chrome dev tools, and look at the "network" tab to see if you're getting 500 errors from some of the AJAX calls.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...