All Apps and Add-ons

Palo Alto Networks global protect only shows one month of data

goriyamasan
Engager

Hi,

We have been running PaloAlto Netowork for splunk for 6 months so far.
From time adjustment, I can only go back and see certain time which is less than a month.
When I look at actual logs, I see the past log still there. but it is not show up in the Global Protect dashboard.
What am I missing?

Thank you,

0 Karma

panguy
Contributor

The dashboard’s are built on accelerated data models. By default they are set to 7 days. You can increase the data acceleration from the data model UI. Documentation on this is available here.

https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Managedatamodels

goriyamasan
Engager

I found the setting in datamodel.conf.
Thank you so much for your help!!

0 Karma

goriyamasan
Engager

Thank you panguy for the answer!
I was able to find the data set and disabled acceleration to edit it.

But, I am having hard time finding where the range setting is.....

Thank you,

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...