All Apps and Add-ons

Palo Alto Networks Add-on for Splunk: {"customized_settings"{}} shows up when setting up freshly installed TA

micmaher
Explorer

Hi,

I've a fresh Splunk installation. 1 SH which is also a Master for an indexer cluster with 2 indexers.

I just installed the Palo Alto Add-on and App on the SH. I then deployed to my indexers as a configuration bundle. So far so good.

Following the configuration guide on my master I opened Manage Apps https://localhost:8000/en-US/manager/search/apps/local

I located 'Palo Alto Networks Add-on for Splunk' and clicked 'Set-up'

When the set-up page loads I seen a single field with {"customized_settings"{}}

alt text

I tried uninstalling the app/add-on and starting again but there was no change.

Any ideas what this could be or how to start troubleshooting it?

Thanks,

Michael

0 Karma
1 Solution

panguy
Contributor

This has been fixed in version 6.0.0 of the app and add-on. Updates have been made to the configuration screen.

View solution in original post

panguy
Contributor

This has been fixed in version 6.0.0 of the app and add-on. Updates have been made to the configuration screen.

micmaher
Explorer

Yes that's the issue alright. Working with Chrome. I was running on a server so just had the built in IE browser installed.

Carl00
Engager

I got the same issue following the guide on http://pansplunk.readthedocs.io/en/latest/getting_started.html
The issue got resolved by simply using another browser (Firefox portable 55.1 @ https://mozilla-firefox-portable.en.uptodown.com/windows).

The js function 'enjectDialogForm(dialogId, formId, cols)' in C:\Program Files\Splunk\etc\apps\Splunk_TA_paloalto\appserver\static\js\setup.js doesn't load and that's why you're only seeing that message. The complete page as shown in the mentioned guide is saved under setup_page.js in the same folder as setup.js.

Please let me know if this resolved your problem. Try out return_page(); in your browser's console under the developer tools. If you're not able to run "return_page();" and retrieve a result the cause may be something else.

micmaher
Explorer

Yes that's the issue alright I was accessing from a server which only had IE installed. Working fine now with Chrome.

0 Karma

panguy
Contributor

Check to see if config files already exist in Splunk_TA_paloalto/local/

passwords.conf
splunk_ta_paloalto_account.conf
splunk_ta_paloalto_settings.conf

You will need to remove them restart Splunk and access the configuration screen again.

0 Karma

micmaher
Explorer

Thank panguy, no local folder exists. I've not made any modifications to the default folder either.

I have the Add-on in /etc/apps/ and also a copy in /etc/master-apps as I wanted it pushed to my indexer peers. I'm not sure if having it in both places can be a problem.

0 Karma

btorresgil
Builder

Hi Michael, what version of the Add-on are you using. Are you on the latest 3.8.2?

0 Karma

micmaher
Explorer

Yes 3.8.2 for the Add-On and also 5.4.2 for the Splunk App for PA Networks

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...