<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Tips &amp;amp; Tricks: Filtering, Tags and Group Tags in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-filtering-tags-and-group-tags/ta-p/542463</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;Searching for the obvious can sometimes be hard. You simply might have overlooked something or you might have never needed it before. Things can become especially tricky when you have a security policy that's several hundreds of rules long.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luckily, Palo Alto Networks offers different ways to filter out what you're looking for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Simply typing any string you're interested in in the search bar and hitting 'enter' will already display any rule that contains the string as seen in the screenshot below, where I used the string "demo" as an example. Notice that the string is &lt;STRONG&gt;NOT&lt;/STRONG&gt; case sensitive :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="kiwi_5-1684315965856.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50208i29646A9716BDE85B/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_5-1684315965856.png" alt="kiwi_5-1684315965856.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BR /&gt;
&lt;P&gt;As seen in the example above, the search will display any rule where the string matches. The match can be in any of the columns and, depending on how big the result is, you might even have to restrict your search further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;MARK&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; Notice how in the example, rule #42 (Outbound-Trust) does not seem to have the string 'demo' anywhere. Why is it shown in the search result ? The answer to that is because the search will also look in the rule's description which isn't visible unless you go into the rule details:&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="kiwi_6-1684316386526.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50209i349C9F4037DFAB3D/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_6-1684316386526.png" alt="kiwi_6-1684316386526.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As mentioned, it's possible to narrow down your search further. To do so you could, for example, limit the search result to&amp;nbsp;the source zone specifically. For that, you can use the following search-filter : &lt;STRONG&gt;(name contains 'demo') and (from/member eq 'L3-Untrust')&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fear not, if you don't know the specific syntax for a filter, there are a couple of tricks you can use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could use the arrow next to the zone-name (or next to any other object you would like to filter on) and click on "&lt;STRONG&gt;Filter&lt;/STRONG&gt;". &amp;nbsp;This will automatically populate the search-filter:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="kiwi_7-1684317006050.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50211iCFC119312323810F/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_7-1684317006050.png" alt="kiwi_7-1684317006050.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;Alternatively, you can also drag and drop any object you want to filter on in the search filter:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="draganddrop.gif" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50214i05D9BDDC02C7415D/image-size/large?v=v2&amp;amp;px=999" role="button" title="draganddrop.gif" alt="draganddrop.gif" /&gt;&lt;/span&gt;
&lt;P&gt; &lt;/P&gt;
An alternative way to filter is by using tag groups (not to be confused with regular tags). By enabling the checkbox &lt;STRONG&gt;"View Rulebase as Groups"&lt;/STRONG&gt; you can display the rulebase using these group tags. Doing so will maintain the policy order and priority but it allows you to select the group tag and view all the rules that are grouped by that tag:&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="kiwi_0-1684323860011.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50219iA506B827114F0B29/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1684323860011.png" alt="kiwi_0-1684323860011.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;It's important to understand the difference between the regular tag vs the group tag in the security policy details.&amp;nbsp; As you can see you can perfectly add a policy rule to a group tag but not have a tag attached to the rule or even have a different tag and group tag:&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="kiwi_10-1684323180943.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50218i1AF2E3D77EFE9E96/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_10-1684323180943.png" alt="kiwi_10-1684323180943.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Feel free to share how filtering, tags and group tags have made your life easier!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Wed, 17 May 2023 19:34:11 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2023-05-17T19:34:11Z</dc:date>
    <item>
      <title>Tips &amp; Tricks: Filtering, Tags and Group Tags</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-filtering-tags-and-group-tags/ta-p/542463</link>
      <description>&lt;P&gt;Searching for the obvious can sometimes be hard. You simply might have overlooked something or you might have never needed it before. Things can become especially tricky when you have a security policy that's several hundreds of rules long.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 19:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-filtering-tags-and-group-tags/ta-p/542463</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-05-17T19:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Tips &amp; Tricks: Filtering, Tags and Group Tags</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-filtering-tags-and-group-tags/tac-p/590909#M725</link>
      <description>&lt;P&gt;Hi, is there any way that we can filter the rules based on IP addresses from &lt;STRONG&gt;all&lt;/STRONG&gt; devices groups (locations) using Panorama. Ive been looking up for this and couldnt find an answer for this. As of now if we want to filter an IP address in policies, it will only give us the rules within that specific device group. And if we search via global search, we only can exports the rules ID only (not the actual details of the rule itself with (source, destination, ports etc.). #filtering #securitypolicies #panorama&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 09:13:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-filtering-tags-and-group-tags/tac-p/590909#M725</guid>
      <dc:creator>amirminhat1</dc:creator>
      <dc:date>2024-07-02T09:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tips &amp; Tricks: Filtering, Tags and Group Tags</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-filtering-tags-and-group-tags/tac-p/591568#M728</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/540855925"&gt;@amirminhat1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm afraid it's not possible to search over all device-groups as shown in the example in this article.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Global search will cover a search globally but doesn't seem to provide you the flexibility you require.&lt;BR /&gt;&lt;BR /&gt;I suggest reaching out to your local SE for a feature request.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 09:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-filtering-tags-and-group-tags/tac-p/591568#M728</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-07-10T09:31:41Z</dc:date>
    </item>
  </channel>
</rss>

