All Apps and Add-ons

Why are graphs slow after upgrading Splunk for Palo Alto Networks to 4.2?

New Member

Last week we upgraded Splunk from 6.1 to 6.2 and the Palo Alto app ran fine. We then upgraded the Palo Alto app from 4.1 to 4.2. Ever since the 4.2 upgrade, the graphs run 30 - 60 minutes behind. Searches are fine and I can see the data coming into Splunk almost real-time in the app.

0 Karma
1 Solution

Builder

Most likely your datamodel acceleration is trying to rebuild after all the upgrades. Check the Palo Alto Networks data models to see if the acceleration is 100% built. If it isn't, verify that the percentage is increasing. You can speed up the process of datamodel rebuild by reducing the amount of data that is accelerated in the datamodel acceleration settings. The default is 1 year of data, but you can reduce it.

View solution in original post

Builder

Most likely your datamodel acceleration is trying to rebuild after all the upgrades. Check the Palo Alto Networks data models to see if the acceleration is 100% built. If it isn't, verify that the percentage is increasing. You can speed up the process of datamodel rebuild by reducing the amount of data that is accelerated in the datamodel acceleration settings. The default is 1 year of data, but you can reduce it.

View solution in original post

New Member

It must have been the acceleration, it was at 55% last week. Came in this morning and all is well.

0 Karma

Builder

Wonderful, I'm glad it's working now! Can you go ahead and mark my answer as correct? Thanks!

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!