Skip to main content


Upgrading App and Add-on

It is recommended to uninstall older versions prior to upgrading to version 8.0.0+ of the app and add-on. Upgrading through the Splunk GUI process may leave artifacts of jQuery and python 2. This may result in compatibility error messages.


The Palo Alto Networks Splunk App and Add-on are designed to work together, and with Splunk Enterprise Security if available. The App requires the Add-on to be installed. The Add-on can be used with or without the App.

Where to install

Splunk NodeWhat to install
Search HeadAdd-on and App
IndexerAdd-on only
Heavy ForwarderAdd-on only
Universal ForwarderNone

Some organizations prefer not to install Add-ons on Search Heads. This is fine for log ingest, but will prevent some advanced features from functioning, such as Adaptive Response and Threat Intelligence.

Important Changes

Data Model acceleration is no longer enabled by default. Dashboards will not display any data until the data model is accelerated. See the section below titled "Data Model Acceleration".

Install the App and Add-on

Install the Palo Alto Networks App by downloading it from the App homepage, or by installing it from within Splunk.

Downloading the App and Add-on from within Splunk Enterprise.

Enable datamodel acceleration

If using the Palo Alto Networks App, you must enable datamodel acceleration to see data in the dashboards. Acceleration is on by default in App 6.0 and lower, and off by default in App 6.1 and higher (due to new Splunk app certification rules)

Enable it now by navigating to Settings -> Datamodels, then select each Palo Alto Networks datamodel and enable acceleration for a time period of your choice.

The time period represents how much data will show in the dashboards, and has a significant impact on storage usage. If unsure, set the acceleration time period to 7 days.

Datamodel acceleration is not required if using the Add-on only.

Alternative: Install from Github

This App is available on SplunkBase and Github. Optionally, you can clone the GitHub repository to install the App. Please feel free to submit contributions to the App using pull requests on GitHub.

From the directory $SPLUNK_HOME/etc/apps/, type the following command:

git clone SplunkforPaloAltoNetworks

From the directory $SPLUNK_HOME/etc/apps/, type the following command:

git clone Splunk_TA_paloalto

Data Model Acceleration

The app dashboard's requires data model acceleration. You must enable the data model that have been installed with the app.

From the Settings menu click on "Data models".![](/splunk/img/Screen Shot 2019-01-02 at 2.47.55 PM.png)

Click on "Edit Acceleration" for each of the data models for the Palo Alto Networks App and check the box next to "acceleration".

![](/splunk/img/Screen Shot 2019-01-02 at 2.48.53 PM.png)