All Apps and Add-ons

Palo Alto Networks App for Splunk: Why are tstats reports for Traffic not displaying and it seems summary indexing is failing?

LintuMathews
Explorer

tstats reports for Traffic doesn't display and it seems summary indexing is not generating data. Can you please suggest a way to troubleshoot?

0 Karma
1 Solution

the_wolverine
Champion

The Overview is using real-time searches so you should be seeing data as long as data as flowing into Splunk.
https://answers.splunk.com/answers/215077/any-performance-issues-with-all-the-real-time-sear.html

Everything else is based on data model acceleration.

We have seen tstats delayed significantly. This may or may not be based on your volume of PAN data. You might want to ping PAN about tuning although we have given up and worked around it using summary indexing although Palo Alto will tell you that the latest version of the app is better tuned for data model acceleration -- it was many months of frustration.

https://answers.splunk.com/answers/326382/palo-alto-networks-app-for-splunk-data-model-frequ.html
https://answers.splunk.com/answers/318950/can-you-disable-the-acceleration-of-all-data-model.html

View solution in original post

0 Karma

the_wolverine
Champion

The Overview is using real-time searches so you should be seeing data as long as data as flowing into Splunk.
https://answers.splunk.com/answers/215077/any-performance-issues-with-all-the-real-time-sear.html

Everything else is based on data model acceleration.

We have seen tstats delayed significantly. This may or may not be based on your volume of PAN data. You might want to ping PAN about tuning although we have given up and worked around it using summary indexing although Palo Alto will tell you that the latest version of the app is better tuned for data model acceleration -- it was many months of frustration.

https://answers.splunk.com/answers/326382/palo-alto-networks-app-for-splunk-data-model-frequ.html
https://answers.splunk.com/answers/318950/can-you-disable-the-acceleration-of-all-data-model.html

0 Karma

LintuMathews
Explorer

We are seeing data coming real time and in the Palo Alto Overview Dashboard

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...