All Apps and Add-ons

Palo Alto Networks Add-on for Splunk: {"customized_settings"{}} shows up when setting up freshly installed TA

micmaher
Explorer

Hi,

I've a fresh Splunk installation. 1 SH which is also a Master for an indexer cluster with 2 indexers.

I just installed the Palo Alto Add-on and App on the SH. I then deployed to my indexers as a configuration bundle. So far so good.

Following the configuration guide on my master I opened Manage Apps https://localhost:8000/en-US/manager/search/apps/local

I located 'Palo Alto Networks Add-on for Splunk' and clicked 'Set-up'

When the set-up page loads I seen a single field with {"customized_settings"{}}

alt text

I tried uninstalling the app/add-on and starting again but there was no change.

Any ideas what this could be or how to start troubleshooting it?

Thanks,

Michael

0 Karma
1 Solution

panguy
Contributor

This has been fixed in version 6.0.0 of the app and add-on. Updates have been made to the configuration screen.

View solution in original post

panguy
Contributor

This has been fixed in version 6.0.0 of the app and add-on. Updates have been made to the configuration screen.

micmaher
Explorer

Yes that's the issue alright. Working with Chrome. I was running on a server so just had the built in IE browser installed.

Carl00
Engager

I got the same issue following the guide on http://pansplunk.readthedocs.io/en/latest/getting_started.html
The issue got resolved by simply using another browser (Firefox portable 55.1 @ https://mozilla-firefox-portable.en.uptodown.com/windows).

The js function 'enjectDialogForm(dialogId, formId, cols)' in C:\Program Files\Splunk\etc\apps\Splunk_TA_paloalto\appserver\static\js\setup.js doesn't load and that's why you're only seeing that message. The complete page as shown in the mentioned guide is saved under setup_page.js in the same folder as setup.js.

Please let me know if this resolved your problem. Try out return_page(); in your browser's console under the developer tools. If you're not able to run "return_page();" and retrieve a result the cause may be something else.

micmaher
Explorer

Yes that's the issue alright I was accessing from a server which only had IE installed. Working fine now with Chrome.

0 Karma

panguy
Contributor

Check to see if config files already exist in Splunk_TA_paloalto/local/

passwords.conf
splunk_ta_paloalto_account.conf
splunk_ta_paloalto_settings.conf

You will need to remove them restart Splunk and access the configuration screen again.

0 Karma

micmaher
Explorer

Thank panguy, no local folder exists. I've not made any modifications to the default folder either.

I have the Add-on in /etc/apps/ and also a copy in /etc/master-apps as I wanted it pushed to my indexer peers. I'm not sure if having it in both places can be a problem.

0 Karma

btorresgil
Builder

Hi Michael, what version of the Add-on are you using. Are you on the latest 3.8.2?

0 Karma

micmaher
Explorer

Yes 3.8.2 for the Add-On and also 5.4.2 for the Splunk App for PA Networks

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...