Palo Alto Networks App for Splunk leverages the data visibility provided by Palo Alto Networks next-generation firewalls and endpoint security with Splunk's extensive investigation and visualization capabilities to deliver an advanced security reporting and analysis tool.
I'm encountering an issue with KV store replication on our Splunk Cloud indexers. I get several errors stating:
"The 'minemeldfeeds_lookup' KV Store lookup table is empty or has not yet been replicated to the search peer (path used is: /opt/splunk/var/run/searchpeers/.... "
Has anyone encountered this before? I tried getting help with it from Splunk but that went no where so I guess I need to tell them what needs to be done. There's no admin access to any of the Splunk nodes in the cloud instance so my hands are a bit tied. Google wasn't entirely useful.
Any thoughts or ideas? I'm on Splunk 7.2.6 in the cloud instance and both the TA and app are 6.1.1
Hello all--
I'm encountering an issue with KV store replication on our Splunk Cloud indexers. I get several errors stating:
"The 'minemeldfeeds_lookup' KV Store lookup table is empty or has not yet been replicated to the search peer (path used is: /opt/splunk/var/run/searchpeers/.... "
Has anyone encountered this before? I tried getting help with it from Splunk but that went no where so I guess I need to tell them what needs to be done. There's no admin access to any of the Splunk nodes in the cloud instance so my hands are a bit tied. Google wasn't entirely useful.
Any thoughts or ideas? I'm on Splunk 7.2.6 in the cloud instance and both the TA and app are 6.1.1