Have you created any custom rules around the Palo Alto data? I've seen this behavior if you have a rule with an action like "InferAlert" or "IncidentAlert" but the .DetectionIP field is being populated by the .DetectionTime or .InsertionTime event data.
It could also be that you've configured the log format on the PA to something other than what the connector expects so that the time-stamp is where our matcher expects an IP address to be. Has the default log format been messed with on the PA at all?