- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
tstats reports for Traffic doesn't display and it seems summary indexing is not generating data. Can you please suggest a way to troubleshoot?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

The Overview is using real-time searches so you should be seeing data as long as data as flowing into Splunk.
https://answers.splunk.com/answers/215077/any-performance-issues-with-all-the-real-time-sear.html
Everything else is based on data model acceleration.
We have seen tstats delayed significantly. This may or may not be based on your volume of PAN data. You might want to ping PAN about tuning although we have given up and worked around it using summary indexing although Palo Alto will tell you that the latest version of the app is better tuned for data model acceleration -- it was many months of frustration.
https://answers.splunk.com/answers/326382/palo-alto-networks-app-for-splunk-data-model-frequ.html
https://answers.splunk.com/answers/318950/can-you-disable-the-acceleration-of-all-data-model.html
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

The Overview is using real-time searches so you should be seeing data as long as data as flowing into Splunk.
https://answers.splunk.com/answers/215077/any-performance-issues-with-all-the-real-time-sear.html
Everything else is based on data model acceleration.
We have seen tstats delayed significantly. This may or may not be based on your volume of PAN data. You might want to ping PAN about tuning although we have given up and worked around it using summary indexing although Palo Alto will tell you that the latest version of the app is better tuned for data model acceleration -- it was many months of frustration.
https://answers.splunk.com/answers/326382/palo-alto-networks-app-for-splunk-data-model-frequ.html
https://answers.splunk.com/answers/318950/can-you-disable-the-acceleration-of-all-data-model.html
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are seeing data coming real time and in the Palo Alto Overview Dashboard
