All Apps and Add-ons

Palo Alto Networks Add-on for Splunk 6.0.1: app_list and threat_list empty

dgustafsonBMCM
Engager

This isn't an issue if you have the pancontent pack set up correctly, but I thought that the CSV Lookups app_list and threat_list were supposed to be pre-populated in the add-on , and then later updated by pancontentpack macro. I've noticed that these are both empty when downloading a fresh copy of the Add-on.

This Commit seems to confirm my suspicion
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/commit/646ff84dc69f5f38c1e754c3f60b545e29e838...

Both app_list.csv and threat_list.csv were emptied. I know I didn't have pancontentpack configured before, so perhaps I was just relying on the static app_list and threat_list lookups that came with the app and everything was mostly working OK. After I installed the latest version of the app, lost the default lookups, and didn't have pancontentpack working, dashboards were more broken.

0 Karma

panguy
Contributor

Thanks for your feedback. You are correct they are suppose to be per-populated. I have created an issue on Github:

https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/issues/13

We will work on getting this added in the next release.

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...