<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to quickly find (and remove) unused objects in policy ? in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/230162#M1776</link>
    <description>&lt;P&gt;But with mirgation tool, I can't remove objects in place ? Or is it possible to import objects to Migration tool, and remove unused dirrectly from Migration tool ?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Sep 2018 15:24:02 GMT</pubDate>
    <dc:creator>niuk</dc:creator>
    <dc:date>2018-09-10T15:24:02Z</dc:date>
    <item>
      <title>How to quickly find (and remove) unused objects in policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/230055#M1774</link>
      <description>&lt;P&gt;Is there a way to quickly find (and remove) unused objects in policy ? I mean like address or service objects&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 19:56:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/230055#M1774</guid>
      <dc:creator>niuk</dc:creator>
      <dc:date>2018-09-07T19:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to quickly find (and remove) unused objects in policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/230078#M1775</link>
      <description>&lt;P&gt;The easiest way to do this is to utilize the Expedition tool to identify resources that are unused and delete them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Expedition-Migration-Tool/ct-p/migration_tool" target="_self"&gt;https://live.paloaltonetworks.com/t5/Expedition-Migration-Tool/ct-p/migration_tool&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expedition is a free tool made available by Palo Alto Network to assist with firewall migrations and optimization.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 18:29:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/230078#M1775</guid>
      <dc:creator>rhagen</dc:creator>
      <dc:date>2018-09-08T18:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to quickly find (and remove) unused objects in policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/230162#M1776</link>
      <description>&lt;P&gt;But with mirgation tool, I can't remove objects in place ? Or is it possible to import objects to Migration tool, and remove unused dirrectly from Migration tool ?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 15:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/230162#M1776</guid>
      <dc:creator>niuk</dc:creator>
      <dc:date>2018-09-10T15:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to quickly find (and remove) unused objects in policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/306879#M2136</link>
      <description>&lt;P&gt;Expedition can make changes directly on the firewall.&amp;nbsp; It has been a while since I have done it, but I believe you add the device under Devices and make the changes under your project &amp;gt; Export &amp;gt; API Output Manager.&amp;nbsp; You should know the difference between Atomic and SubAtomic changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also use "show | match &amp;lt;object-name&amp;gt;" in configuration mode (set format) and see where it is used in the configuration.&amp;nbsp; If the only line is the address object, it is not used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also delete the object.&amp;nbsp; If it is used, you will get an error right away.&amp;nbsp; If not, the delete will be accepted in the candidate configuration.&amp;nbsp; UPDATE:&amp;nbsp; I saw this on Reddit, and it works.&amp;nbsp; &lt;STRONG&gt;Select all the objects.&lt;/STRONG&gt;&amp;nbsp; (This may not be quick depending upon the number of objects.)&amp;nbsp; &lt;STRONG&gt;Select Delete and Yes.&amp;nbsp; All unused objects are deleted.&amp;nbsp; All used objects produce an error and are kept.&lt;/STRONG&gt;&amp;nbsp; Use Device &amp;gt; Config Audit to see which objects were deleted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once Expedition is setup, that is the quickest and easiest.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 20:25:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/306879#M2136</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-12T20:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to quickly find (and remove) unused objects in policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/524763#M3277</link>
      <description>&lt;P&gt;In case anyone is stumbling upon this thread in 2022... the suggested method above doesn't seem to work effectively or consistently. Running 9.1.x and our Panorama seems to stop checking after it reaches X errors or objects. I had to go back and select chunks of around 75 or less for it to effectively get rid of unused objects. This is rough when you have 4000+ objects...&lt;BR /&gt;&lt;BR /&gt;Is Palo is ever going to give us a feature to simply remove unused objects in bulk without having to use Expedition?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 15:36:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/524763#M3277</guid>
      <dc:creator>mmccorkle5</dc:creator>
      <dc:date>2022-12-21T15:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to quickly find (and remove) unused objects in policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/526343#M3291</link>
      <description>&lt;P&gt;There are a few options. You can talk to your Palo representatives about progressing feature request ID 3159&amp;nbsp; to have something in the GUI. Expedition is also an option. For automated solutions, you could use the API or one of the SDKs, in fact pan-os-php has some dedicated advice on this topic: &lt;A href="https://github.com/PaloAltoNetworks/pan-os-php/wiki/unused-objects," target="_blank"&gt;https://github.com/PaloAltoNetworks/pan-os-php/wiki/unused-objects,&lt;/A&gt;&amp;nbsp;but you could use Python or Go which also have SDKs. It just depends on your preferred approach. Hope that helps&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 15:02:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/526343#M3291</guid>
      <dc:creator>JimmyHolland</dc:creator>
      <dc:date>2023-01-09T15:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to quickly find (and remove) unused objects in policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/1220387#M3442</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SCM now has this feature.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/strata-cloud-manager/getting-started/security-posture/config-cleanup" target="_blank"&gt;https://docs.paloaltonetworks.com/strata-cloud-manager/getting-started/security-posture/config-cleanup&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do not use SCM currently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is probably obvious to most, but I just realize this recently.&amp;nbsp; You can use the Global Find drop down for any object.&amp;nbsp; If it is only used once in the configuration for the object itself, then it is unused.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1739469568949.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66037iB0B4B9130B3FB405/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1739469568949.png" alt="TomYoung_0-1739469568949.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 18:00:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/m-p/1220387#M3442</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-02-13T18:00:01Z</dc:date>
    </item>
  </channel>
</rss>

