<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Show hit count in CLI in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68530#M39949</link>
    <description>&lt;P&gt;I was searching this forum and official documentation, but I can't find the following:&lt;/P&gt;
&lt;P&gt;Is there equivalent to Cisco ASA "show access-list acl_name" command in the PAN-OS CLI. I am looking for the command that will show hit count for every configured security rule. Also if the object groups are used either in source or destination address it would be great if this command would show exact IP address that have hit count. Some thing like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list outside_in line 1 extended permit tcp any host 192.168.1.1 eq www (hitcnt=2176) 0x9e62d266 &lt;BR /&gt;access-list outside_in line 2 extended permit tcp object-group PUBLIC_IPs host 192.168.1.2 eq smtp 0xd1a0241c &lt;BR /&gt; access-list outside_in line 2 extended permit tcp 1.2.3.0 255.255.255.192 host &lt;SPAN&gt;192.168.1.2&lt;/SPAN&gt; eq smtp (hitcnt=5421) 0x13f4d6dc &lt;BR /&gt; access-list outside_in line 2 extended permit tcp 2.3.4.0 255.255.255.224 host &lt;SPAN&gt;192.168.1.2&lt;/SPAN&gt; eq smtp (hitcnt=0) 0x9366dd12 &lt;BR /&gt;access-list outside_in line 3 extended permit tcp any host 192.168.1.3 eq https (hitcnt=8957) 0x83457acc&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;All that I have found is this command that can show unused rules:&lt;BR /&gt;show running rule-use rule-base security type unused vsys vsys1&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2015 13:26:52 GMT</pubDate>
    <dc:creator>hrvoje_samec</dc:creator>
    <dc:date>2015-11-24T13:26:52Z</dc:date>
    <item>
      <title>Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68530#M39949</link>
      <description>&lt;P&gt;I was searching this forum and official documentation, but I can't find the following:&lt;/P&gt;
&lt;P&gt;Is there equivalent to Cisco ASA "show access-list acl_name" command in the PAN-OS CLI. I am looking for the command that will show hit count for every configured security rule. Also if the object groups are used either in source or destination address it would be great if this command would show exact IP address that have hit count. Some thing like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list outside_in line 1 extended permit tcp any host 192.168.1.1 eq www (hitcnt=2176) 0x9e62d266 &lt;BR /&gt;access-list outside_in line 2 extended permit tcp object-group PUBLIC_IPs host 192.168.1.2 eq smtp 0xd1a0241c &lt;BR /&gt; access-list outside_in line 2 extended permit tcp 1.2.3.0 255.255.255.192 host &lt;SPAN&gt;192.168.1.2&lt;/SPAN&gt; eq smtp (hitcnt=5421) 0x13f4d6dc &lt;BR /&gt; access-list outside_in line 2 extended permit tcp 2.3.4.0 255.255.255.224 host &lt;SPAN&gt;192.168.1.2&lt;/SPAN&gt; eq smtp (hitcnt=0) 0x9366dd12 &lt;BR /&gt;access-list outside_in line 3 extended permit tcp any host 192.168.1.3 eq https (hitcnt=8957) 0x83457acc&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;All that I have found is this command that can show unused rules:&lt;BR /&gt;show running rule-use rule-base security type unused vsys vsys1&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 13:26:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68530#M39949</guid>
      <dc:creator>hrvoje_samec</dc:creator>
      <dc:date>2015-11-24T13:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68588#M39980</link>
      <description>&lt;P&gt;You cannot find this because the feature does not exist. &amp;nbsp;PAN does not at this time track hit count at all. &amp;nbsp;The unused rule feature is not hit count but simply a flag that is triggered when a rule is first used after reboot. &amp;nbsp;As long as the rule was used at least once the rule will be removed from the unused rule list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am pretty sure hit counters are an existing feature request in the PAN database. &amp;nbsp;If you contact your sales engineer you can get your companies vote for the feature request recorded.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 23:29:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68588#M39980</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-11-24T23:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68606#M39992</link>
      <description>&lt;P&gt;Hi there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is doable with custom reports, and has been for a long time. If you want to specify one specific source IP, you can do this with the query builder. See pictures. With 7.0 this is actually now visible in the ACC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1330iF83A8A371649933D/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="Custom report" title="Custom report" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1331i84EB93BB5367117E/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="Custom report output" title="Custom report output" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1333i00C70E2ABF845A73/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="Custom report with source IP" title="Custom report with source IP" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1334iEBF493270D6DC970/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="Custom report with source IP output" title="Custom report with source IP output" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1332iEA0668657F5F4B4E/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="ACC Rule Usage" title="ACC Rule Usage" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 06:39:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68606#M39992</guid>
      <dc:creator>gtomte</dc:creator>
      <dc:date>2015-11-25T06:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68626#M39999</link>
      <description>&lt;P&gt;This is a nice work around but this is not a hit counter and not a CLI option as requested.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This custom report is looking a logged sessions over the report time period and further reporting by your filter choices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The desired function is a BY RULE hit counter. &amp;nbsp;Traffic hits the rule a counter is incremented and this continues until the cournter is reset manually or the firewall rebooted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We typically use this during active live troubleshooting sessions to reset the counter and confirm traffic generated is live hitting the expected rule. &amp;nbsp;Or to reset the counters after we think no more traffic should hit a rule and turn at a later time and confirm there is no increment of the counter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The function is not yet implemented in PAN.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 13:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68626#M39999</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-11-25T13:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68635#M40002</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If you require a by-rule hit counter, please contact your Palo Alto Networks SE and vote for that feature request. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aside from the custom report suggestion, I have one from the CLI as well. &amp;nbsp;This doesn't necessarily "count" the rules, but it&amp;nbsp;may be enough to confirm if traffic is hitting the expected rule or answer the question "when was the last time this rule was hit". &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: small; line-height: normal;"&gt;admin@pa0(active)&amp;gt; show log traffic direction equal backward rule equal 'deny any to dbl'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Time App From Src Port Source&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Rule Action To Dst Port Destination&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; Src User Dst User End Reason&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;====================================================================================================&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;2015/11/25 07:31:24 not-applicable trust 58750 10.1.1.10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;deny any to dbl deny untrust 80 46.21.151.38&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; policy-deny&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;2015/11/25 07:31:23 not-applicable trust 58749 10.1.1.10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;deny any to dbl deny untrust 80 46.21.151.38&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; policy-deny&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;2015/11/25 07:31:21 not-applicable trust 58748 10.1.1.10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;deny any to dbl deny untrust 80 46.21.151.38&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 14:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68635#M40002</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2015-11-25T14:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68642#M40006</link>
      <description>&lt;P&gt;thanks for answer. We will certainly send our vote for this feature&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 16:18:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68642#M40006</guid>
      <dc:creator>hrvoje_samec</dc:creator>
      <dc:date>2015-11-25T16:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68800#M40061</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;you could also run this for live sessions on a per-policy basis:&lt;BR /&gt;&amp;gt;show session all filter rule &amp;nbsp;Rule_Name count yes (state active)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 16:18:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/68800#M40061</guid>
      <dc:creator>seleftherakis</dc:creator>
      <dc:date>2015-11-30T16:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/314142#M81054</link>
      <description>&lt;P&gt;For PAN-OS version 9.x, the hit counter is available via CLI using ---&lt;/P&gt;&lt;P&gt;show rule-hit-count vsys vsys-name vsys1 rule-base security rules all | match " 0 "&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 14:31:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/314142#M81054</guid>
      <dc:creator>ChrisHuang</dc:creator>
      <dc:date>2020-03-03T14:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/314161#M81060</link>
      <description>&lt;P&gt;Gosh darnit Chris...What are you doing browsing 5 year old threads?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 14:58:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/314161#M81060</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-03-03T14:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Show hit count in CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/576072#M115641</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87299"&gt;@ChrisHuang&lt;/a&gt;&amp;nbsp; Yes this command works on PAN OS 10.1 and above also&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show rule-hit-count vsys vsys-name vsys1 rule-base security rules all | match " 0 "&lt;BR /&gt;NetGear_Adobe 0 - - - Fri Jul 28 23:20:20 2023 Fri Sep 29 18:21:48 2023&lt;BR /&gt;NetGear_Goto_Meeting 0 - - - Fri Jul 28 23:20:20 2023 Fri Sep 29 18:21:48 2023&lt;BR /&gt;TPLink_Zoom 0 - - - Thu Dec 7 10:04:11 2023 Thu Dec 7 10:04:11 2023&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 16:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-hit-count-in-cli/m-p/576072#M115641</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2024-02-05T16:25:08Z</dc:date>
    </item>
  </channel>
</rss>

