<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I get a report of what threat prevention rules are enabled? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30937#M22647</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Bart!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried that, and am working through some problems I am having (suspect I have a mistake in my API query due to running 4.1.1) but I am headed in the right direction now.&amp;nbsp; Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jan 2012 15:45:57 GMT</pubDate>
    <dc:creator>cwilliams</dc:creator>
    <dc:date>2012-01-06T15:45:57Z</dc:date>
    <item>
      <title>How do I get a report of what threat prevention rules are enabled?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30933#M22643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a customer that has asked me to match up an ISS proventia IPS rule to put a PAN Threat Prevention rule.&amp;nbsp;&amp;nbsp; I have created a enabled about 1009 rules on a custom ruleset to do so.&amp;nbsp;&amp;nbsp;&amp;nbsp; The customer has asked that I "print off" in CSV or other format the " rules, showing which ones are enabled, what action is configured, against what is available..."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The GUI shows this very nicely in 138 pages, but I can not find a good way to pump that out into a presentable format.&amp;nbsp;&amp;nbsp;&amp;nbsp; The only other method I have found is to export the config via .xml, but that only has the signature number, not description.... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 18:29:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30933#M22643</guid>
      <dc:creator>cwilliams</dc:creator>
      <dc:date>2012-01-04T18:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a report of what threat prevention rules are enabled?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30934#M22644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;I have not tried this myself, but I think you import the xml part of the threat prevention config into excel, similar to importing the ruleset into excel, as described in &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1617"&gt;https://live.paloaltonetworks.com/docs/DOC-1617&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 08:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30934#M22644</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2012-01-05T08:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a report of what threat prevention rules are enabled?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30935#M22645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info, Bart!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That link gave me an error, can you please repost?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 15:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30935#M22645</guid>
      <dc:creator>cwilliams</dc:creator>
      <dc:date>2012-01-05T15:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a report of what threat prevention rules are enabled?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30936#M22646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I corrected the link in my first post.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 15:13:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30936#M22646</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2012-01-05T15:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a report of what threat prevention rules are enabled?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30937#M22647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Bart!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried that, and am working through some problems I am having (suspect I have a mistake in my API query due to running 4.1.1) but I am headed in the right direction now.&amp;nbsp; Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 15:45:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30937#M22647</guid>
      <dc:creator>cwilliams</dc:creator>
      <dc:date>2012-01-06T15:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a report of what threat prevention rules are enabled?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30938#M22648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SO I have had some success.... and still have some problems....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been working with the REST API, and am able to pull the rules with the threat ID, but I do not get the threat name, criticality, default action, etc.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using this xpath:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/config/devices/entry[@name='localhost.localdomain']/device-group/entry[@name='FW1']/profiles/vulnerability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I import that into excel, I get the columns for threat-name, category, default, etc.&amp;nbsp; but no data in the fields...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only data fields populated are the ID field, and the name of the profile, which is a start, but I need the other fields as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cam &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2012 18:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30938#M22648</guid>
      <dc:creator>cwilliams</dc:creator>
      <dc:date>2012-01-19T18:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a report of what threat prevention rules are enabled?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30939#M22649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;The threat names are not part of the configuration.&amp;nbsp; This is why you are not able to see that information. We have a threat database on the device from which you could pull that information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;For example – if you want to pull&amp;nbsp; the threat name for threat id 30003, this is how you do&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;&lt;A href="https://10.2.133.10/api/?type=config&amp;amp;key=hu6jy9KNvrN7oXLsRQMNZpd6JHdyawpcJU727bW0Z7o=&amp;amp;action=get&amp;amp;xpath=/config/predefined/threats/vulnerability/entry%5b@name=%2730003%27%5d/threatname"&gt;&lt;SPAN style="color:#00B050"&gt;https://x.x.x.10/api/?type=config&amp;amp;key=hu6jy9KNvrN7oXLsRQMNZpd6JHdyawpcJU727bW0Z7o=&amp;amp;&lt;/SPAN&gt;&lt;SPAN style="color:#0070C0"&gt;action=get&amp;amp;xpath=/config/predefined/threats/vulnerability/entry[@name='30003']/threatname&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;your action will be "get" and xpath="/config/predefined/threats/vulnerability" . However that xpath will display all the threat objects in the device. So make the xpath more fine grained by&amp;nbsp; providing the threat id.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;&lt;A href="https://10.2.133.10/api/?type=config&amp;amp;key=hu6jy9KNvrN7oXLsRQMNZpd6JHdyawpcJU727bW0Z7o=&amp;amp;action=get&amp;amp;xpath=/config/predefined/threats/vulnerability/entry%5b@name=%2730003"&gt;https://x.x.x.10/api/?type=config&amp;amp;key=hu6jy9KNvrN7oXLsRQMNZpd6JHdyawpcJU727bW0Z7o=&amp;amp;action=get&amp;amp;xpath=/config/predefined/threats/vulnerability/entry[@name='30003&lt;/A&gt;']&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;here is the xpath to get the name of the threat with threat id 30003.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;IMG border="0" height="484" src="file:/C:/Users/KSOMU%7E1.PAL/AppData/Local/Temp/msohtmlclip1/01/clip_image002.jpg" width="1116" /&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;&lt;A href="https://10.2.133.10/api/?type=config&amp;amp;key=hu6jy9KNvrN7oXLsRQMNZpd6JHdyawpcJU727bW0Z7o=&amp;amp;action=get&amp;amp;xpath=/config/predefined/threats/vulnerability/entry%5b@name=%2730003%27%5d/threatname"&gt;https://x.x.x.10/api/?type=config&amp;amp;key=hu6jy9KNvrN7oXLsRQMNZpd6JHdyawpcJU727bW0Z7o=&amp;amp;action=get&amp;amp;xpath=/config/predefined/threats/vulnerability/entry[@name='30003']/threatname&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt; So its&amp;nbsp; two-step process. you might want to import all the vulnerabilities in to an excel and then merge those vulnerabilities that you are looking for in to your original excel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color:#1F497D"&gt;krishna&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2012 22:04:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-get-a-report-of-what-threat-prevention-rules-are/m-p/30939#M22649</guid>
      <dc:creator>ksomu</dc:creator>
      <dc:date>2012-01-19T22:04:29Z</dc:date>
    </item>
  </channel>
</rss>

