All Apps and Add-ons

pantag: Palo Alto Networks Add-on (PanXapiError)

qawasmeh
New Member

Hi,

We are getting the below error while trying to use pantag command,

External search command 'pantag' returned error code 2. Script output = "ERROR 'PanXapiError' object has no attribute 'msg' "

Running this query:
index=paloalto 104.27.153.178 |dedup dest_ip|table dest_ip | pantag device="a.b.c.d" action="add" ip_field="dest_ip" tag="bad-actor" debug=t

common:176 - Debugging enabled
common:204 - Determining if required arguments are present
common:204 - Determining how firewalls should be contacted based on arguments
common:204 - Use Panorama: False
common:204 - VSys: vsys1
common:204 - Hostname: a.b.c.d
common:204 - Using serials from logs
common:204 - Begin get API key
common:204 - API Key found in Splunk credential store
common:204 - Registering tags on firewall : 104.27.153.178 - ['bad-actor']
common:184 - File "/opt/splunk/etc/apps/SplunkforPaloAltoNetworks/bin/panTag.py", line 249, in
main_splunk()
File "/opt/splunk/etc/apps/SplunkforPaloAltoNetworks/bin/panTag.py", line 236, in main_splunk
File "/opt/splunk/etc/apps/SplunkforPaloAltoNetworks/bin/lib/common.py", line 184, in exit_with_error
logger.error(''.join(traceback.format_stack()))
common:185 - 'PanXapiError' object has no attribute 'msg'

https://splunk.paloaltonetworks.com/commands.html

Current Application: Palo Alto Networks Add-on
App Version
6.1.1
App Build
6110

Any Ideas?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...