All Apps and Add-ons

Why am I not getting any data on Palo Alto Networks App for Splunk?

TRBVBQ
Explorer

Hello
Splunk Version 6.2.1
Palo Alto Networks APP 6.0.1

The index seems to be correctly configured because I receive data if I search "eventtype=pan" or "index="pan_logs" on the App itself.

But I have no data at all under Activity, Threats or Operations tab...

I followed the troubleshooting steps available but found nothing, only something about NTP and time settings, but that's not clear that the NTP problem makes the data not to appear at all.
And the timestamp of logs seems correct:
alt text

What else can I check? This is my first configs on Splunk and I may have missed something.

Thanks for the help!

TRBVBQ
Explorer

alt text

0 Karma

TRBVBQ
Explorer

Hello

On the "Real Time event feed", I have only the "Event type" graph that is filled.
On some dashboards, I have this warning " KVStore based automatic lookups are not supported (pan:threat)"

alt text

alt text

0 Karma

panguy
Contributor

The add-on is required for parsing. Does the operations > real time events dashboard work?

0 Karma

panguy
Contributor

Are some dashboards working or non at all? What version of the Add-on do you have installed?

0 Karma

TRBVBQ
Explorer

Yes, I have some working dashboards, but only for others App, like network ones.

The Add one is 6.0.2, but I think I don't need this Add On, I have configured nothing on it.

Thanks !

0 Karma

tiagofbmm
Influencer

Can you retrieve the search query for one of the non functioning dashboards and paste it here please?

0 Karma

TRBVBQ
Explorer

Firewall Event, Latest event code is this one:

| pan_tstats count FROM node(log.system) $serial_number$ $vsys$ $description$ $log_subtype$ $severity$ $event_id$ table(_time log.serial_number log.description log.log_subtype log.severity log.event_id) | sort -_time

0 Karma

TRBVBQ
Explorer

And what's displayed is "waiting for entries"

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...