The Palo Alto Splunk app has been updated to version 6.0.1. When we go "Add-on settings" and "Account" the page loads forever. We double-checked that data is in the system, which is fine. How can we solve this issue, what troubleshooting steps are available?
thx.
solved, thanks.
How did you solve?
Thanks
Any update on how this was solved? I'm running Splunk 8.0.1 with v6.2.0 of the Palo Alto TA.
@chfeussner, To help future readers, please accept an answer or add a new answer with your solution and accept that.
I have seen this behavior before when there is a passwords.conf entry that is both exported globally and contains special characters that cannot be processed by the /storage/passwords endpoint. From the search bar in the Palo Alto App, run this command:
| rest "/services/storage/passwords?output_mode=json" | table clear_password
If you look through that list, it should show passwords from other TA's that have exported their passwords.conf (or all their KOs) globally - and some of those might contain those special characters causing that REST endpoint to throw errors, which in turn causes the screen to never load.
The other way to verify this is to open that setup page in Chrome and open Chrome dev tools, and look at the "network" tab to see if you're getting 500 errors from some of the AJAX calls.