All Apps and Add-ons

Why is the Threat Dashboard blank after upgrading the Palo Alto Networks App for Splunk from 3.x to 5.0.1?

itreghenssler
Explorer

Using Splunk 6.2
Upgraded the Palo Alto Networks App for Splunk from 3.x (no TA installed) to 5.0.1 and after waiting for the data models to update to 100%, all of the Content dashboards are populating, but nothing under Threat - all of the dashboard objects show the grey warning triangle and 'tstats' Additionally, within the overview dashboard, the EventTypes panel is blank (no warning, but no data) and the Applications by Destination IP Location shows nothing, where prior it did show locations.

Prior to the upgrade all were working without issue for over a year.

I followed the steps in the upgrade guide and under troubleshooting. Created the inputs.conf file in the correct location for the PA App, deleted the lookups folder from the SplunkforPaloAltoNetworks folder (all default), verified that the data is flowing (as indicated by the Content dashboard and I can view/search the log data).

What did I miss?

0 Karma

itreghenssler
Explorer

I found the issue with the Threat Dashboard:
This was the default search string in the panels:

| `tstats' count FROM...

changing that to:

| `pan_tstats' count FROM...

There are several other panels where the sourcetype or field names needed to be changed. For example dst_ip is now dest_ip.

Resolved the issue with the panels in that view.

I still have not figured out the fix for Threat Details panels. If anyone knows the proper syntax for those, any help appreciated.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...