This post has been de-listed
It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.
So I just updated my splunk install, and recently replaced my firewalls to PA3260's (9.1.6).
I have most of the dashboards working. (at least for the components/licenses I own) But globalprotect shows blank. All the other sections show data. I can do a search on host=paloalto sourcetype="pan:globalprotect" and I get results back. With event_id's that show gateway logins/outs portal in/out etc. But the Dashboard itself doesn't show anything on the globalprotect dashboard. If I understand it correctly these dashboards are built on accelerated data models. Which are all accelerated/enabled. And now I'm at a loss.. Anyone have any suggestions?
Post Details
- Posted
- 3 years ago
- Reddit URL
- View post on reddit.com
- External URL
- reddit.com/r/Splunk/comm...