Just did an upgrade this morning to the main Splunk app to version 4.3.1 build 119532, and ever since the Palo Alto app isn't functioning. I check inputs.conf, it was left alone by the upgrade and is still correct.
I have the same issue, it seems the transforms.conf are not working correctly. This is really irritating as there is a complete lack of documentation available for this app.
Please let us know if you find a solution