Palo Alto Network App for Splunk: No data showing in GlobalProtect dashboard and some other dashboards

New Member


I am working on upgrading from an older version of the Palo Alto Network App for Splunk. I have installed the TA on all indexers and the APP/TA on the search head. Most of the dashboards are being populated with data, but the GlobalProtect dashboard has nothing. I am seeing info in the pan_logs for GlobalProtect, but I don't see any reference to GP in the Pan Firewall Data Model.

I see that the dashboard panels are making reference to:
datamodel="pan_firewall" WHERE nodename="log.system.globalprotect"

I've looked through the entire data model and don't see any reference to globalprotect.

Splunk Version Version: 7.2.0 Build: 8c86330ac18
Palo Alto Networks Add-on 6.2.0
Palo Alto Networks App for Splunk 6.2.0

Data being sent from firewalls to splunk via UDP input



Tags (1)
0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.