Splunk Cloud Platform

panuserupdate returned error

Yusuf
Observer

Hello Everyone,

I am just bringing up splunk within our environment, so a lot of functions are still new.

I am trying to use my windows event data to update users ID on panorama, however, running the below query in my es environment returns the error : External search command 'panuserupdate' returned error code 2. Script output = "ERROR Unable to get apikey from firewall: local variable 'username' referenced before assignment ".

The Query

index=wineventlog host=xxxxxx
| mvexpand Security_ID
| mvexpand Source_Network_Address
| dedup Security_ID Source_Network_Address
| search Security_ID!="NULL SID"
| rename Security_ID as user
| rename Source_Network_Address as src_ip
| panuserupdate panorama=x.x.x.x serial=000000000000
| fields user src_ip

Brief overview of my data ingestion: Panorama syslog is ingested to splunk cloud through Heavy forwarder. Palo Alto Add on for Splunk is installed on both HF and Splunk Cloud also, but no data is showing on the app. Every data is 0 0.  Also I do have a user account in Panorama with api permissions.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...