The Palo Alto app was previously working, all dashboards displayed data. Now it's not working. I'm working through the troubleshooting steps here https://splunk.paloaltonetworks.com/troubleshoot.html and pretty sure it's a parsing issue. I'm working with the Networking team (who set up the PA) to check the syslog settings. But in the meantime, when I go to the Configuration page, I get Buttercup and page not found. I'm assuming this is a separate issue, and I have no idea what to do. Can anyone help me?
We have only 1 Splunk server, running 22.214.171.124. It's on prem. Both the Palo Alto app (6.1.1) and TA (6.1.1) are installed.
Most of the app is fixed. All of the dashboards work. I had to go to Settings/Data Models and enable acceleration for the 4 SplunkforPaloAltoNetworks data models (Step 4. Check acceleration and summary indexing). And then I had to update it because the date was showing 12/31/69. Once I did that, the dashboards started populating.
Under Step 3. Verify logs are parsed correctly in the above link, it says to do a search for eventtype=pan_config. I was stuck there because I wasn't getting any results. I finally changed it to pan* and got results. There aren't any pan_config eventtypes.