All Apps and Add-ons

Palo Alto Network App for Splunk: No data showing in GlobalProtect dashboard and some other dashboards

garrywilmeth
Explorer

Hello,

I am working on upgrading from an older version of the Palo Alto Network App for Splunk. I have installed the TA on all indexers and the APP/TA on the search head. Most of the dashboards are being populated with data, but the GlobalProtect dashboard has nothing. I am seeing info in the pan_logs for GlobalProtect, but I don't see any reference to GP in the Pan Firewall Data Model.

I see that the dashboard panels are making reference to:
datamodel="pan_firewall" WHERE nodename="log.system.globalprotect"

I've looked through the entire data model and don't see any reference to globalprotect.

Splunk Version Version: 7.2.0 Build: 8c86330ac18
Palo Alto Networks Add-on 6.2.0
Palo Alto Networks App for Splunk 6.2.0

Data being sent from firewalls to splunk via UDP input

Thanks,

Garry

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...