Hello all,
I've configured the Palo Alto Networks App & Add-on, and am receiving traffic on my Splunk Indexers and am able to search the data using my Search Heads.
In the Palo Alto Networks App, I navigate to Operations > Realtime Event Feed, and this dashboard displays statistics about live traffic and appears to be working normally.
However, if I navigate to any other dashboard, it shows there is no data. This is true even if I expand the search parameter to all-time.
Any ideas on how to resolve this?
Thank you!
The other dashboards have started displaying data after selecting "all time" under the Presets. In addition, not all Dashboards show data -- just some.
Thank you.
The other dashboards have started displaying data after selecting "all time" under the Presets. In addition, not all Dashboards show data -- just some.
Thank you.
Hi muralikoppula,
All Palo Alto datamodels have been accelerated already.
Thanks.
You need to accelerate Palo Alto datamodels..Check the below link
https://answers.splunk.com/answers/705888/palo-alto-networks-app-add-on-setup-1.html#answer-705942