All Apps and Add-ons

Palo Alto Networks global protect only shows one month of data

goriyamasan
Engager

Hi,

We have been running PaloAlto Netowork for splunk for 6 months so far.
From time adjustment, I can only go back and see certain time which is less than a month.
When I look at actual logs, I see the past log still there. but it is not show up in the Global Protect dashboard.
What am I missing?

Thank you,

0 Karma

panguy
Contributor

The dashboard’s are built on accelerated data models. By default they are set to 7 days. You can increase the data acceleration from the data model UI. Documentation on this is available here.

https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Managedatamodels

goriyamasan
Engager

I found the setting in datamodel.conf.
Thank you so much for your help!!

0 Karma

goriyamasan
Engager

Thank you panguy for the answer!
I was able to find the data set and disabled acceleration to edit it.

But, I am having hard time finding where the range setting is.....

Thank you,

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...