All Apps and Add-ons

Palo Alto Networks global protect only shows one month of data

goriyamasan
Engager

Hi,

We have been running PaloAlto Netowork for splunk for 6 months so far.
From time adjustment, I can only go back and see certain time which is less than a month.
When I look at actual logs, I see the past log still there. but it is not show up in the Global Protect dashboard.
What am I missing?

Thank you,

0 Karma

panguy
Contributor

The dashboard’s are built on accelerated data models. By default they are set to 7 days. You can increase the data acceleration from the data model UI. Documentation on this is available here.

https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Managedatamodels

goriyamasan
Engager

I found the setting in datamodel.conf.
Thank you so much for your help!!

0 Karma

goriyamasan
Engager

Thank you panguy for the answer!
I was able to find the data set and disabled acceleration to edit it.

But, I am having hard time finding where the range setting is.....

Thank you,

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...