All Apps and Add-ons

Palo Alto Networks Add-on Configuration issue

chfeussner
Engager

The Palo Alto Splunk app has been updated to version 6.0.1. When we go "Add-on settings" and "Account" the page loads forever. We double-checked that data is in the system, which is fine. How can we solve this issue, what troubleshooting steps are available?

thx.

0 Karma
1 Solution

chfeussner
Engager
0 Karma

chfeussner
Engager

solved, thanks.

0 Karma

iarnopagliani
New Member

How did you solve?
Thanks

0 Karma

jstocker
New Member

Any update on how this was solved? I'm running Splunk 8.0.1 with v6.2.0 of the Palo Alto TA.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@chfeussner, To help future readers, please accept an answer or add a new answer with your solution and accept that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

I have seen this behavior before when there is a passwords.conf entry that is both exported globally and contains special characters that cannot be processed by the /storage/passwords endpoint. From the search bar in the Palo Alto App, run this command:
| rest "/services/storage/passwords?output_mode=json" | table clear_password
If you look through that list, it should show passwords from other TA's that have exported their passwords.conf (or all their KOs) globally - and some of those might contain those special characters causing that REST endpoint to throw errors, which in turn causes the screen to never load.
The other way to verify this is to open that setup page in Chrome and open Chrome dev tools, and look at the "network" tab to see if you're getting 500 errors from some of the AJAX calls.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...