All Apps and Add-ons

Palo Alto Networks Apps - Only Realtime Event Feed Displays Data

cody_richardson
Path Finder

Hello all,

I've configured the Palo Alto Networks App & Add-on, and am receiving traffic on my Splunk Indexers and am able to search the data using my Search Heads.

In the Palo Alto Networks App, I navigate to Operations > Realtime Event Feed, and this dashboard displays statistics about live traffic and appears to be working normally.

However, if I navigate to any other dashboard, it shows there is no data. This is true even if I expand the search parameter to all-time.

Any ideas on how to resolve this?

Thank you!

0 Karma
1 Solution

cody_richardson
Path Finder

The other dashboards have started displaying data after selecting "all time" under the Presets. In addition, not all Dashboards show data -- just some.

Thank you.

View solution in original post

0 Karma

cody_richardson
Path Finder

The other dashboards have started displaying data after selecting "all time" under the Presets. In addition, not all Dashboards show data -- just some.

Thank you.

0 Karma

cody_richardson
Path Finder

Hi muralikoppula,

All Palo Alto datamodels have been accelerated already.

Thanks.

0 Karma

muralikoppula
Communicator

You need to accelerate Palo Alto datamodels..Check the below link

https://answers.splunk.com/answers/705888/palo-alto-networks-app-add-on-setup-1.html#answer-705942

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...