All Apps and Add-ons

Why are Splunk for Palo Alto Networks Traffic and Wildfire dashboards suddenly not displaying?

rodgerkrau
New Member

Palo App for Splunk all of a sudden not displaying traffic dashboard or Wildfire. All other content working.

0 Karma

ccscott
New Member

This kinda sucks. I don't think it has ever worked though. Just one more thing in splunk that doesn't work and isn't supported by them. So far splunk has been the biggest waste of money ever.

0 Karma

madc0w
New Member

There is a bug and hopefully the developers will fix in a new version.

http://answers.splunk.com/answers/203043/pan-wildfirereport-and-pan-newapps-bug.html

0 Karma

rodgerkrau
New Member

Still an issue.. anyone else know a "fix"

0 Karma

ppablo
Retired

Hi @rodgerkrau

You might want to contact the developer of the app directly if you're not having any luck here in the Answers community. Their contact info is in the bottom right panel of the app's page http://apps.splunk.com/app/491/

0 Karma

rodgerkrau
New Member

I cant open an item directly (in the search) from the actual dashboard. no items display.

here is the code: | tstats sum(bytes_received) AS sbr sum(bytes_sent) AS sbs FROM pan_traffic WHERE earliest=-60m latest=now groupby app | eval sumBytes = sbr + sbs | stats values(sumBytes) AS Bytes by app

0 Karma

Lucas_K
Motivator

Check that someone hasn't disabled any savedsearches or data models that these rely on.

0 Karma

rodgerkrau
New Member

I get results!

0 Karma

barakreeves
Splunk Employee
Splunk Employee

from the search, what happens when you run: sourcetype=pan_wildfire_report OR sourcetype=pan_traffic ?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...