This isn't an issue if you have the pancontent pack set up correctly, but I thought that the CSV Lookups app_list and threat_list were supposed to be pre-populated in the add-on , and then later updated by pancontentpack macro. I've noticed that these are both empty when downloading a fresh copy of the Add-on.
This Commit seems to confirm my suspicion
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/commit/646ff84dc69f5f38c1e754c3f60b545e29e838...
Both app_list.csv and threat_list.csv were emptied. I know I didn't have pancontentpack configured before, so perhaps I was just relying on the static app_list and threat_list lookups that came with the app and everything was mostly working OK. After I installed the latest version of the app, lost the default lookups, and didn't have pancontentpack working, dashboards were more broken.
Thanks for your feedback. You are correct they are suppose to be per-populated. I have created an issue on Github:
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/issues/13
We will work on getting this added in the next release.