All Apps and Add-ons

Why are graphs slow after upgrading Splunk for Palo Alto Networks to 4.2?

sysops_mls
New Member

Last week we upgraded Splunk from 6.1 to 6.2 and the Palo Alto app ran fine. We then upgraded the Palo Alto app from 4.1 to 4.2. Ever since the 4.2 upgrade, the graphs run 30 - 60 minutes behind. Searches are fine and I can see the data coming into Splunk almost real-time in the app.

0 Karma
1 Solution

btorresgil
Builder

Most likely your datamodel acceleration is trying to rebuild after all the upgrades. Check the Palo Alto Networks data models to see if the acceleration is 100% built. If it isn't, verify that the percentage is increasing. You can speed up the process of datamodel rebuild by reducing the amount of data that is accelerated in the datamodel acceleration settings. The default is 1 year of data, but you can reduce it.

View solution in original post

btorresgil
Builder

Most likely your datamodel acceleration is trying to rebuild after all the upgrades. Check the Palo Alto Networks data models to see if the acceleration is 100% built. If it isn't, verify that the percentage is increasing. You can speed up the process of datamodel rebuild by reducing the amount of data that is accelerated in the datamodel acceleration settings. The default is 1 year of data, but you can reduce it.

sysops_mls
New Member

It must have been the acceleration, it was at 55% last week. Came in this morning and all is well.

0 Karma

btorresgil
Builder

Wonderful, I'm glad it's working now! Can you go ahead and mark my answer as correct? Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...