I am trying to use the panupdate command to feed user/ip mapping data from splunk to PA. I have a search that is getting the addruser and addrip fields successfully. When I pipe my search to panupdate, however, I get the following error: Unknown search command 'panupdate'. I am running version 3.2 of the PAN app, and have verified that the panupdate command is installed, according to the app's 'view objects' manifest. Any suggestions?
Disregard this. I figured the problem out. I was trying to use the panupdate command from the main search app, not from within the PaloAlto app. Using panupdate within the PA app works great.