<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: looking for efficient way to clear specific security rule hit counts in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-efficient-way-to-clear-specific-security-rule-hit/m-p/598862#M119108</link>
    <description>&lt;P&gt;Luckily, I have a small deployment and so I will just run the clear command on each active firewall.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2024 14:32:48 GMT</pubDate>
    <dc:creator>1treelanedrv</dc:creator>
    <dc:date>2024-09-26T14:32:48Z</dc:date>
    <item>
      <title>looking for efficient way to clear specific security rule hit counts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-efficient-way-to-clear-specific-security-rule-hit/m-p/598660#M119068</link>
      <description>&lt;P&gt;I have Panorama managing 2 HA paired firewalls.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The security rules are pushed to both HA pairs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to clear the hit counts for specific rules.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I login to the active firewall then I can run this command and it works fine.&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show rule-hit-count vsys vsys-name vsys1 rule-base security rules list [ "asdf1" "asdf2" "asdf3" ]&lt;/LI-CODE&gt;
&lt;P&gt;And the clear version of that is&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;clear rule-hit-count vsys vsys-name vsys1 rule-base security rules list [ "asdf" "asdf2" "asdf3" ]&lt;/LI-CODE&gt;
&lt;P&gt;However, in Panorama, things are different. I can only show one rule.&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; show rule-hit-count device-group ASDF-DG post-rulebase security rules rule-name "asdf"&lt;/LI-CODE&gt;
&lt;P&gt;and then get weird trying to clear. It makes me specify a rule name and then asks for a list of rules.&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;clear rule-hit-count device-group ASDF-DF rulebase security rules rule-name "asdf" device [serial number] vsys list ?
  [        Start a list of values.
  &amp;lt;value&amp;gt;  vsys name&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a better way to clear a specific list of security rules from Panorama?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or should we just login to both active firewalls and clear it with the command from above?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 15:30:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-efficient-way-to-clear-specific-security-rule-hit/m-p/598660#M119068</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2024-09-24T15:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: looking for efficient way to clear specific security rule hit counts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-efficient-way-to-clear-specific-security-rule-hit/m-p/598862#M119108</link>
      <description>&lt;P&gt;Luckily, I have a small deployment and so I will just run the clear command on each active firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 14:32:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-efficient-way-to-clear-specific-security-rule-hit/m-p/598862#M119108</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2024-09-26T14:32:48Z</dc:date>
    </item>
  </channel>
</rss>

