There are a number of test searches which presume that events from PAN devices are in the pan_logs index. The same searches use index=* for sourcetype=opsec and sourcetype=cisco:asa. I'm not sure if there's a technical reason for the difference but I'd like to propose that these searches are changed from 'index=pan_logs' to 'index=*'.
Issue was noted in version 2.4.1.
You are correct; this is most definitely wrong, but the app is not intended to be directly executable; it is intended to be educational.
I am positive that the developers and contributors for this app would love the feedback, listen to your proposal and provide a reason if any. their names are in the app page https://splunkbase.splunk.com/app/3435/
good luck