Hello guys, I recently encountered a problem on the search-head.
Data model of palo alto networks firewall logs can not build 100%. I tried rebuilding but still not build 100%.
Can you help me solve this problem?
Common reasons for datamodel build issues are explained here in the troubleshooting guide:
https://splunk.paloaltonetworks.com/troubleshoot.html#datamodel
Usually it boils down to not enough resources to keep up with the inflow of logs.
Let us know if that helps. Thanks!
thank! btorresgil