<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Highlight Unused Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31124#M22765</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Marcel. I'm running Panorama to manage the PA4050s - when you say system restart what exactly do you mean. Eg. I have Panorama receiving logs - I have 3 months worth of logs - the policy config is saved, committed on Panorama and pushed to the PA4050s every week for rule changes. Neither the PAs or the Panorama server or software has been rebooted during that time. When clicking the "Highlight Unused Rules" on Panorama - would I get a full view of what rules didn't see traffic during that 3 month period?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If Panorama was rebooted for some reason - but I still had the logs on Panorama - what would happen if I selected the "Highlight Unused Rules" option then on Panorama?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Apr 2011 09:59:35 GMT</pubDate>
    <dc:creator>fmd</dc:creator>
    <dc:date>2011-04-06T09:59:35Z</dc:date>
    <item>
      <title>Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31122#M22763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're running 4.0.1 in a test environment. We have a large Checkpoint rulebase that we will export. It ideally needs a rule tidy up to remove unused rules and objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone describe how the "Highlight Unused Rules" tick box option on the policy page works. Yep, I know it sounds obvious!! But what is it based on - the logs? If so how far back in the logs will it go? Is there then a way of quickly removing unused objects that aren't in rule? etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Apr 2011 21:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31122#M22763</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-04-05T21:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31123#M22764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The options shows you the unused since the last restart of the system. So you need to have it pass traffic and execute rules before you can see which rules are used or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 06:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31123#M22764</guid>
      <dc:creator>mderksen</dc:creator>
      <dc:date>2011-04-06T06:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31124#M22765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Marcel. I'm running Panorama to manage the PA4050s - when you say system restart what exactly do you mean. Eg. I have Panorama receiving logs - I have 3 months worth of logs - the policy config is saved, committed on Panorama and pushed to the PA4050s every week for rule changes. Neither the PAs or the Panorama server or software has been rebooted during that time. When clicking the "Highlight Unused Rules" on Panorama - would I get a full view of what rules didn't see traffic during that 3 month period?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If Panorama was rebooted for some reason - but I still had the logs on Panorama - what would happen if I selected the "Highlight Unused Rules" option then on Panorama?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 09:59:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31124#M22765</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-04-06T09:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31125#M22766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you select the context of the unit in Panorama and click on the unused rule you will see which have not been hit since the moment you rebooted the unit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 15:05:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/31125#M22766</guid>
      <dc:creator>mderksen</dc:creator>
      <dc:date>2011-04-06T15:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/72523#M41115</link>
      <description>&lt;P&gt;hi is there a way to possibly export the unused policies on an excel?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2016 08:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/72523#M41115</guid>
      <dc:creator>n.barria</dc:creator>
      <dc:date>2016-02-10T08:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Highlight Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/72526#M41116</link>
      <description>&lt;P&gt;you can spawn a simple list using the CLI command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;show running rule-use vsys &amp;lt;value&amp;gt; rule-base &amp;lt;security|nat|qos|pbf|decryption|app-override|cp|dos&amp;gt; type &amp;lt;used|unused&amp;gt; &lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eg:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; show running rule-use vsys vsys1 rule-base security type unused 

rule1
unusedrule1
unusedrule2&lt;/PRE&gt;</description>
      <pubDate>Wed, 10 Feb 2016 08:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/highlight-unused-rules/m-p/72526#M41116</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-02-10T08:48:37Z</dc:date>
    </item>
  </channel>
</rss>

