All Apps and Add-ons
Highlighted

Why am I not getting any data on Palo Alto Networks App for Splunk?

Explorer

Hello
Splunk Version 6.2.1
Palo Alto Networks APP 6.0.1

The index seems to be correctly configured because I receive data if I search "eventtype=pan" or "index="pan_logs" on the App itself.

But I have no data at all under Activity, Threats or Operations tab...

I followed the troubleshooting steps available but found nothing, only something about NTP and time settings, but that's not clear that the NTP problem makes the data not to appear at all.
And the timestamp of logs seems correct:
alt text

What else can I check? This is my first configs on Splunk and I may have missed something.

Thanks for the help!

Highlighted

Re: Why am I not getting any data on Palo Alto Networks App for Splunk?

Contributor

Are some dashboards working or non at all? What version of the Add-on do you have installed?

0 Karma
Highlighted

Re: Why am I not getting any data on Palo Alto Networks App for Splunk?

Explorer

Yes, I have some working dashboards, but only for others App, like network ones.

The Add one is 6.0.2, but I think I don't need this Add On, I have configured nothing on it.

Thanks !

0 Karma
Highlighted

Re: Why am I not getting any data on Palo Alto Networks App for Splunk?

Influencer

Can you retrieve the search query for one of the non functioning dashboards and paste it here please?

0 Karma
Highlighted

Re: Why am I not getting any data on Palo Alto Networks App for Splunk?

Explorer

Firewall Event, Latest event code is this one:

| pan_tstats count FROM node(log.system) $serialnumber$ $vsys$ $description$ $logsubtype$ $severity$ $eventid$ `table(time log.serialnumber log.description log.logsubtype log.severity log.eventid)` | sort -time

0 Karma
Highlighted

Re: Why am I not getting any data on Palo Alto Networks App for Splunk?

Explorer

And what's displayed is "waiting for entries"

0 Karma
Highlighted

Re: Why am I not getting any data on Palo Alto Networks App for Splunk?

Contributor

The add-on is required for parsing. Does the operations > real time events dashboard work?

0 Karma
Highlighted

Re: Why am I not getting any data on Palo Alto Networks App for Splunk?

Explorer

Hello

On the "Real Time event feed", I have only the "Event type" graph that is filled.
On some dashboards, I have this warning " KVStore based automatic lookups are not supported (pan:threat)"

alt text

alt text

0 Karma
Highlighted

Re: Why am I not getting any data on Palo Alto Networks App for Splunk?

Explorer
0 Karma