I recently experienced a situation where an attempted push of firewall configuration was failing for a single production HA firewall. The error being received when attempting the push was the following:
vsys -> vsys1 -> profiles -> spyware -> PROFILE -> mica-engine-spyware-enabled unexpected here
vsys -> vsys1 -> profiles -> spyware is invalid
The validation error can be fixed by simply performing a restart of services on the Panorama server:
debug software restart process configd
debug software restart process management-server
After each command is run on Panorama, you’ll need to wait a couple of minutes for each to take effect before you may access the CLI again. If this process alone does not fix the issue then I would suggest getting a case opened with Palo Alto Support to find an alternative solution to the specific issue being experienced.
Panorama Push Failure