<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ansible change interzone-default logging in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535096#M3335</link>
    <description>&lt;P&gt;Researching that error message, I think something else is not quite right with your Ansible environment. Are the paths set correctly? Have you got the correct Python interpreter? And got the dependencies installed in the right place?&lt;/P&gt;</description>
    <pubDate>Mon, 20 Mar 2023 15:35:38 GMT</pubDate>
    <dc:creator>JimmyHolland</dc:creator>
    <dc:date>2023-03-20T15:35:38Z</dc:date>
    <item>
      <title>Ansible change interzone-default logging</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/534909#M3332</link>
      <description>&lt;P&gt;I am trying to figure out a way that I can use Ansible playbook to override the interzone-default rule to add 'logging at session end'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have tried using panos_type_cmd but so far not having any luck.&amp;nbsp; Just gettin the following error:&lt;/P&gt;&lt;P&gt;"module_stdout": "",&lt;BR /&gt;"msg": "MODULE FAILURE\nSee stdout/stderr for the exact error",&lt;BR /&gt;"rc": 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what the task looks like in playbook:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;tasks&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;- &lt;/SPAN&gt;&lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;Set logging on interzone-default&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; paloaltonetworks.panos.panos_type_cmd&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; provider&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;'{{ device }}'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; xpath&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"/config/predefined/default-security-rules/rules/entry[@name='interzone-default']/"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cmd&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;edit&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; element&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;log-end&amp;gt;yes&amp;lt;/log-end&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Have also tried using 'set' command with no luck.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 17 Mar 2023 19:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/534909#M3332</guid>
      <dc:creator>Jaromme</dc:creator>
      <dc:date>2023-03-17T19:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Ansible change interzone-default logging</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535040#M3333</link>
      <description>&lt;P&gt;Those predefined inter and intra zone rules are slightly different, here's a task definition that works on my lab VM-Series, which I found using the GUI debug:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;    - name: Set logging on interzone-default
      paloaltonetworks.panos.panos_type_cmd:
        provider: '{{ device }}'
        xpath: |
          /config/devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']
          /rulebase/default-security-rules/rules/entry[@name='interzone-default']
        cmd: edit
        element:
          &amp;lt;entry name="interzone-default"&amp;gt;&amp;lt;action&amp;gt;deny&amp;lt;/action&amp;gt;&amp;lt;log-end&amp;gt;yes&amp;lt;/log-end&amp;gt;&amp;lt;/entry&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 10:40:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535040#M3333</guid>
      <dc:creator>JimmyHolland</dc:creator>
      <dc:date>2023-03-20T10:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: Ansible change interzone-default logging</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535092#M3334</link>
      <description>&lt;P&gt;Thanks Jimmy!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried the task you provided but am getting an error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"changed": true,&lt;BR /&gt;"msg": "non-zero return code",&lt;BR /&gt;"rc": 127,&lt;BR /&gt;"stderr": "/bin/sh: show: command not found\n",&lt;BR /&gt;"stderr_lines": [&lt;BR /&gt;"/bin/sh: show: command not found"&lt;BR /&gt;],&lt;BR /&gt;"stdout": "",&lt;BR /&gt;"stdout_lines": []&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 15:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535092#M3334</guid>
      <dc:creator>Jaromme</dc:creator>
      <dc:date>2023-03-20T15:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Ansible change interzone-default logging</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535096#M3335</link>
      <description>&lt;P&gt;Researching that error message, I think something else is not quite right with your Ansible environment. Are the paths set correctly? Have you got the correct Python interpreter? And got the dependencies installed in the right place?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 15:35:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535096#M3335</guid>
      <dc:creator>JimmyHolland</dc:creator>
      <dc:date>2023-03-20T15:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Ansible change interzone-default logging</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535110#M3336</link>
      <description>&lt;P&gt;Nevermind, it was just me being dumb.&amp;nbsp; I had two different playbooks I was testing and was running the wrong one.&amp;nbsp; It works, Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:03:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/ansible-change-interzone-default-logging/m-p/535110#M3336</guid>
      <dc:creator>Jaromme</dc:creator>
      <dc:date>2023-03-20T16:03:05Z</dc:date>
    </item>
  </channel>
</rss>

