All Apps and Add-ons

Palo Alto Networks Add-on for Splunk 6.0.1: app_list and threat_list empty

dgustafsonBMCM
Engager

This isn't an issue if you have the pancontent pack set up correctly, but I thought that the CSV Lookups app_list and threat_list were supposed to be pre-populated in the add-on , and then later updated by pancontentpack macro. I've noticed that these are both empty when downloading a fresh copy of the Add-on.

This Commit seems to confirm my suspicion
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/commit/646ff84dc69f5f38c1e754c3f60b545e29e838...

Both app_list.csv and threat_list.csv were emptied. I know I didn't have pancontentpack configured before, so perhaps I was just relying on the static app_list and threat_list lookups that came with the app and everything was mostly working OK. After I installed the latest version of the app, lost the default lookups, and didn't have pancontentpack working, dashboards were more broken.

0 Karma

panguy
Contributor

Thanks for your feedback. You are correct they are suppose to be per-populated. I have created an issue on Github:

https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/issues/13

We will work on getting this added in the next release.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...