Hi,
I've a fresh Splunk installation. 1 SH which is also a Master for an indexer cluster with 2 indexers.
I just installed the Palo Alto Add-on and App on the SH. I then deployed to my indexers as a configuration bundle. So far so good.
Following the configuration guide on my master I opened Manage Apps https://localhost:8000/en-US/manager/search/apps/local
I located 'Palo Alto Networks Add-on for Splunk' and clicked 'Set-up'
When the set-up page loads I seen a single field with {"customized_settings"{}}
I tried uninstalling the app/add-on and starting again but there was no change.
Any ideas what this could be or how to start troubleshooting it?
Thanks,
Michael
This has been fixed in version 6.0.0 of the app and add-on. Updates have been made to the configuration screen.
This has been fixed in version 6.0.0 of the app and add-on. Updates have been made to the configuration screen.
Yes that's the issue alright. Working with Chrome. I was running on a server so just had the built in IE browser installed.
I got the same issue following the guide on http://pansplunk.readthedocs.io/en/latest/getting_started.html
The issue got resolved by simply using another browser (Firefox portable 55.1 @ https://mozilla-firefox-portable.en.uptodown.com/windows).
The js function 'enjectDialogForm(dialogId, formId, cols)' in C:\Program Files\Splunk\etc\apps\Splunk_TA_paloalto\appserver\static\js\setup.js doesn't load and that's why you're only seeing that message. The complete page as shown in the mentioned guide is saved under setup_page.js in the same folder as setup.js.
Please let me know if this resolved your problem. Try out return_page(); in your browser's console under the developer tools. If you're not able to run "return_page();" and retrieve a result the cause may be something else.
Yes that's the issue alright I was accessing from a server which only had IE installed. Working fine now with Chrome.
Check to see if config files already exist in Splunk_TA_paloalto/local/
passwords.conf
splunk_ta_paloalto_account.conf
splunk_ta_paloalto_settings.conf
You will need to remove them restart Splunk and access the configuration screen again.
Thank panguy, no local folder exists. I've not made any modifications to the default folder either.
I have the Add-on in /etc/apps/ and also a copy in /etc/master-apps as I wanted it pushed to my indexer peers. I'm not sure if having it in both places can be a problem.
Hi Michael, what version of the Add-on are you using. Are you on the latest 3.8.2?
Yes 3.8.2 for the Add-On and also 5.4.2 for the Splunk App for PA Networks