All Apps and Add-ons

Palo Alto Networks global protect only shows one month of data

goriyamasan
Engager

Hi,

We have been running PaloAlto Netowork for splunk for 6 months so far.
From time adjustment, I can only go back and see certain time which is less than a month.
When I look at actual logs, I see the past log still there. but it is not show up in the Global Protect dashboard.
What am I missing?

Thank you,

0 Karma

panguy
Contributor

The dashboard’s are built on accelerated data models. By default they are set to 7 days. You can increase the data acceleration from the data model UI. Documentation on this is available here.

https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Managedatamodels

goriyamasan
Engager

I found the setting in datamodel.conf.
Thank you so much for your help!!

0 Karma

goriyamasan
Engager

Thank you panguy for the answer!
I was able to find the data set and disabled acceleration to edit it.

But, I am having hard time finding where the range setting is.....

Thank you,

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...