<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule creation/modification dates in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/rule-creation-modification-dates/m-p/180127#M1463</link>
    <description>&lt;P&gt;From my understanding, the only way to glean this information would be from the config audit versions (&lt;A href="https://10.73.52.118/api/?type=op&amp;amp;cmd=%3Cshow%3E%3Cconfig%3E%3Caudit%3E%3C%2Faudit%3E%3C%2Fconfig%3E%3C%2Fshow%3E&amp;amp;REST_API_TOKEN=965457492" target="_rest_api"&gt;/api/?type=op&amp;amp;cmd=&amp;lt;show&amp;gt;&amp;lt;config&amp;gt;&amp;lt;audit&amp;gt;&amp;lt;/audit&amp;gt;&amp;lt;/config&amp;gt;&amp;lt;/show&amp;gt;&lt;/A&gt;). However, looping through each of these every time would add a lot of complexity to your script, and you may not have the config version where the last change to the firewall was made.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you considered writing the creation/modification dates to the description field and then using logic to base rules to alert on on the description field?&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2017 20:52:48 GMT</pubDate>
    <dc:creator>nigelswift</dc:creator>
    <dc:date>2017-10-04T20:52:48Z</dc:date>
    <item>
      <title>Rule creation/modification dates</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/rule-creation-modification-dates/m-p/180116#M1462</link>
      <description>&lt;P&gt;I'm writing a script to alert when a new MAC address is seen for an IP address that's listed in an Internet-facing rule. I have it working pretty well, but I want to avoid alerting on rules that are themselves new. I'm calling the API via&amp;nbsp;/config/devices/entry/vsys/entry/rulebase/security/rules, but the data I get back doesn't include any creation/modification date information. Is there a way to get that information via the API? Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 20:38:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/rule-creation-modification-dates/m-p/180116#M1462</guid>
      <dc:creator>ekenda2</dc:creator>
      <dc:date>2017-10-04T20:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Rule creation/modification dates</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/rule-creation-modification-dates/m-p/180127#M1463</link>
      <description>&lt;P&gt;From my understanding, the only way to glean this information would be from the config audit versions (&lt;A href="https://10.73.52.118/api/?type=op&amp;amp;cmd=%3Cshow%3E%3Cconfig%3E%3Caudit%3E%3C%2Faudit%3E%3C%2Fconfig%3E%3C%2Fshow%3E&amp;amp;REST_API_TOKEN=965457492" target="_rest_api"&gt;/api/?type=op&amp;amp;cmd=&amp;lt;show&amp;gt;&amp;lt;config&amp;gt;&amp;lt;audit&amp;gt;&amp;lt;/audit&amp;gt;&amp;lt;/config&amp;gt;&amp;lt;/show&amp;gt;&lt;/A&gt;). However, looping through each of these every time would add a lot of complexity to your script, and you may not have the config version where the last change to the firewall was made.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you considered writing the creation/modification dates to the description field and then using logic to base rules to alert on on the description field?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 20:52:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/rule-creation-modification-dates/m-p/180127#M1463</guid>
      <dc:creator>nigelswift</dc:creator>
      <dc:date>2017-10-04T20:52:48Z</dc:date>
    </item>
  </channel>
</rss>

