All Apps and Add-ons

Palo Alto Networks Apps - Only Realtime Event Feed Displays Data

cody_richardson
Path Finder

Hello all,

I've configured the Palo Alto Networks App & Add-on, and am receiving traffic on my Splunk Indexers and am able to search the data using my Search Heads.

In the Palo Alto Networks App, I navigate to Operations > Realtime Event Feed, and this dashboard displays statistics about live traffic and appears to be working normally.

However, if I navigate to any other dashboard, it shows there is no data. This is true even if I expand the search parameter to all-time.

Any ideas on how to resolve this?

Thank you!

0 Karma
1 Solution

cody_richardson
Path Finder

The other dashboards have started displaying data after selecting "all time" under the Presets. In addition, not all Dashboards show data -- just some.

Thank you.

View solution in original post

0 Karma

cody_richardson
Path Finder

The other dashboards have started displaying data after selecting "all time" under the Presets. In addition, not all Dashboards show data -- just some.

Thank you.

0 Karma

cody_richardson
Path Finder

Hi muralikoppula,

All Palo Alto datamodels have been accelerated already.

Thanks.

0 Karma

muralikoppula
Communicator

You need to accelerate Palo Alto datamodels..Check the below link

https://answers.splunk.com/answers/705888/palo-alto-networks-app-add-on-setup-1.html#answer-705942

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...