<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EDL global find XML API in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598092#M118972</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/454064351"&gt;@jyao&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a great question, and the PANW documentation could be improved to make the answer more clear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You said "Neither can I get global find result on FW UI."&amp;nbsp; I assume that means the List Entries and Exceptions tab in the EDL configuration is blank.&amp;nbsp; The NGFW will not retrieve the contents of an EDL until it is enforced in a policy.&amp;nbsp; (An EDL will always be blank on Panorama since it doesn't perform a lookup.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;An IP List EDL can be used as a source or destination object in a security policy rule.&lt;/LI&gt;
&lt;LI&gt;A URL List EDL can be used as a URL Category in a security policy rule or a custom URL category in a URL Filtering security profile.&lt;/LI&gt;
&lt;LI&gt;A Domain List can be used under DNS Policies in an Anti-Spyware security profile.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Once the EDL is enforced in a policy the NGFW will retrieve the contents at the 1st commit and then the specified interval.&amp;nbsp; If the entries are still blank use the Test Source URL button to make sure it works &lt;EM&gt;and&lt;/EM&gt; use a browser to verify it has entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/view-external-dynamic-list-entries" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/view-external-dynamic-list-entries&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/enforce-policy-on-an-external-dynamic-list" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/enforce-policy-on-an-external-dynamic-list&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This previous Live Community post is helpful.&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/external-list-not-populating/td-p/406809" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/external-list-not-populating/td-p/406809&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone in the Live Community sees that I missed something, please let me know!&amp;nbsp; I will edit this post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 18 Sep 2024 09:42:47 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-09-18T09:42:47Z</dc:date>
    <item>
      <title>EDL global find XML API</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598063#M118965</link>
      <description>&lt;P&gt;Hi dear all,&lt;/P&gt;
&lt;P&gt;When I use&amp;nbsp;&lt;A href="https://192.168.85.61/api/?type=op&amp;amp;cmd=%3Crequest%3E%3Csystem%3E%3Cexternal-list%3E%3Cglobal-find%3E%3Cstring%3E%3C%2Fstring%3E%3C%2Fglobal-find%3E%3C%2Fexternal-list%3E%3C%2Fsystem%3E%3C%2Frequest%3E&amp;amp;REST_API_TOKEN=1280335800" target="_rest_api"&gt;/api/?type=op&amp;amp;cmd=&amp;lt;request&amp;gt;&amp;lt;system&amp;gt;&amp;lt;external-list&amp;gt;&amp;lt;global-find&amp;gt;&amp;lt;string&amp;gt;&amp;lt;/string&amp;gt;&amp;lt;/global-find&amp;gt;&amp;lt;/external-list&amp;gt;&amp;lt;/system&amp;gt;&amp;lt;/request&amp;gt;&lt;/A&gt;&amp;nbsp;to search EDL with entry string, I can only search with IP list, for example,&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;&amp;lt;request&amp;gt;&amp;lt;system&amp;gt;&amp;lt;external-list&amp;gt;&amp;lt;global-find&amp;gt;&amp;lt;string&amp;gt;5.167.66.138&amp;lt;/string&amp;gt;&amp;lt;/global-find&amp;gt;&amp;lt;/external-list&amp;gt;&amp;lt;/system&amp;gt;&amp;lt;/request&amp;gt;&lt;/EM&gt;, and I can get global find result as below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;lt;response status="success"&amp;gt;&lt;BR /&gt;&amp;lt;result&amp;gt;&lt;BR /&gt;&amp;lt;line&amp;gt;/config/devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']/external-list/entry[@name='blocklistde-all.list']&amp;lt;/line&amp;gt;&lt;BR /&gt;&amp;lt;/result&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;However, when I try to find URL or domain string, it cannot return any match even though the string is in the EDL entry list. Neither can I get global find result on FW UI.&lt;/P&gt;
&lt;P&gt;May I know if any of you have such experience?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 01:37:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598063#M118965</guid>
      <dc:creator>jyao</dc:creator>
      <dc:date>2024-09-18T01:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: EDL global find XML API</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598087#M118969</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/454064351"&gt;@jyao&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe this works for IP address only by design.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The firewall CLI also does not show the result of the command &lt;STRONG&gt;request system external-list global-find string "fqdn"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you want to have this added as a feature request please reach out your local SE to create this feature request for you after which you and others can add their vote to it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 09:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598087#M118969</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-09-18T09:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: EDL global find XML API</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598092#M118972</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/454064351"&gt;@jyao&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a great question, and the PANW documentation could be improved to make the answer more clear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You said "Neither can I get global find result on FW UI."&amp;nbsp; I assume that means the List Entries and Exceptions tab in the EDL configuration is blank.&amp;nbsp; The NGFW will not retrieve the contents of an EDL until it is enforced in a policy.&amp;nbsp; (An EDL will always be blank on Panorama since it doesn't perform a lookup.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;An IP List EDL can be used as a source or destination object in a security policy rule.&lt;/LI&gt;
&lt;LI&gt;A URL List EDL can be used as a URL Category in a security policy rule or a custom URL category in a URL Filtering security profile.&lt;/LI&gt;
&lt;LI&gt;A Domain List can be used under DNS Policies in an Anti-Spyware security profile.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Once the EDL is enforced in a policy the NGFW will retrieve the contents at the 1st commit and then the specified interval.&amp;nbsp; If the entries are still blank use the Test Source URL button to make sure it works &lt;EM&gt;and&lt;/EM&gt; use a browser to verify it has entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/view-external-dynamic-list-entries" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/view-external-dynamic-list-entries&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/enforce-policy-on-an-external-dynamic-list" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/enforce-policy-on-an-external-dynamic-list&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This previous Live Community post is helpful.&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/external-list-not-populating/td-p/406809" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/external-list-not-populating/td-p/406809&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone in the Live Community sees that I missed something, please let me know!&amp;nbsp; I will edit this post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 09:42:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598092#M118972</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-09-18T09:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: EDL global find XML API</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598693#M119082</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your reply. I have attached EDL to a policy and enforce it, and I can EDL entries with XML api cmd=&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;request&amp;gt;&amp;lt;system&amp;gt;&amp;lt;external-list&amp;gt;&amp;lt;show&amp;gt;&amp;lt;type&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN&gt;{type}&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN&gt;&amp;lt;num-records&amp;gt;1000&amp;lt;/num-records&amp;gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN&gt;&amp;lt;name&amp;gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;STRONG&gt;&lt;I&gt;{name}&lt;/I&gt;&lt;/STRONG&gt;&lt;I&gt;&lt;SPAN&gt;&amp;lt;/name&amp;gt;&amp;lt;/&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN&gt;{type}&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;/type&amp;gt;&amp;lt;/show&amp;gt;&amp;lt;/external-list&amp;gt;&amp;lt;/system&amp;gt;&amp;lt;/request&amp;gt;.&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;However, when I use '&lt;EM&gt;/api/?type=op&amp;amp;cmd=&amp;lt;request&amp;gt;&amp;lt;system&amp;gt;&amp;lt;external-list&amp;gt;&amp;lt;global-find&amp;gt;&amp;lt;string&amp;gt;{{EDLEntryString}}&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;&amp;lt;/string&amp;gt;&amp;lt;/global-find&amp;gt;&amp;lt;/external-list&amp;gt;&amp;lt;/system&amp;gt;&amp;lt;/request&amp;gt;&lt;/EM&gt;', I can only search IP string, but not domain or URL string can be searched. According to Kim's comment, this endpoint only works for IP addresses by design.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks again&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Jonathan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 22:54:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598693#M119082</guid>
      <dc:creator>jyao</dc:creator>
      <dc:date>2024-09-24T22:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: EDL global find XML API</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598698#M119084</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;May I know if I can get ip/url/domain EDL entries on Panorama? As I can only see&amp;nbsp;&lt;A href="https://192.168.85.182/php/rest/browse.php/op::request::system::external-list::show::type::predefined-ip" target="_blank"&gt;predefined-ip&amp;nbsp;&lt;/A&gt;&amp;nbsp;amd&amp;nbsp;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://192.168.85.182/php/rest/browse.php/op::request::system::external-list::show::type::predefined-url" target="_blank"&gt;predefined-url&lt;/A&gt;&amp;nbsp;types on my Pamorama instance, I am sure if it relates to my Pamorama license.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jyao_0-1727224085274.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62388i36559DCA08A13B04/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jyao_0-1727224085274.png" alt="jyao_0-1727224085274.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When I try to get entries of my custom EDL, the API returns below error:&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;response&lt;/SPAN&gt; &lt;SPAN&gt;status&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"error"&lt;/SPAN&gt; &lt;SPAN&gt;code&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"17"&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;msg&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;line&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;![CDATA[ request -&amp;gt; system -&amp;gt; external-list -&amp;gt; show -&amp;gt; type -&amp;gt; ip unexpected here]]&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;line&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;line&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;![CDATA[ request -&amp;gt; system -&amp;gt; external-list -&amp;gt; show -&amp;gt; type is invalid]]&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;line&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;msg&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;response&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jyao_1-1727224394762.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62389i7055FD4D32D23F9B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jyao_1-1727224394762.png" alt="jyao_1-1727224394762.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jonathan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 00:34:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-global-find-xml-api/m-p/598698#M119084</guid>
      <dc:creator>jyao</dc:creator>
      <dc:date>2024-09-25T00:34:03Z</dc:date>
    </item>
  </channel>
</rss>

