<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unused rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76241#M42226</link>
    <description>&lt;P&gt;No unused rules are rules that have not matched since reboot of the firewall.&lt;/P&gt;
&lt;P&gt;To be more specific from reboot of the dataplane.&lt;/P&gt;
&lt;P&gt;If something is blocked then you see in traffic log what rule it matched against to figure out what rule blocked traffic.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Apr 2016 12:56:17 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2016-04-12T12:56:17Z</dc:date>
    <item>
      <title>Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76238#M42223</link>
      <description>&lt;P&gt;Is it possible for a rule to show unused and be passing traffic? I disabled an unused rule and it seemed to affect traffic. I usually check it and it now show in the traffice monitor and it highlighted as unused. I also rebooted the firewall about a month ago.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 12:49:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76238#M42223</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-12T12:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76241#M42226</link>
      <description>&lt;P&gt;No unused rules are rules that have not matched since reboot of the firewall.&lt;/P&gt;
&lt;P&gt;To be more specific from reboot of the dataplane.&lt;/P&gt;
&lt;P&gt;If something is blocked then you see in traffic log what rule it matched against to figure out what rule blocked traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 12:56:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76241#M42226</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-12T12:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76256#M42238</link>
      <description>&lt;P&gt;I don't see anything in the traffic monitor for the rule I disabled, I was wondering if there is anywhere else to double check&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 14:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76256#M42238</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-12T14:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76262#M42240</link>
      <description>&lt;P&gt;I have also found some rules that show used but I cannot find them in the traffic monitor at all. Anyone know of anywhere else to confirm whether rule is being used or not&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 16:49:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76262#M42240</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-12T16:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76283#M42243</link>
      <description>&lt;P&gt;How can a ruled show used and not be in the traffic monitor?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 19:31:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76283#M42243</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-12T19:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76284#M42244</link>
      <description>&lt;P&gt;Question:&lt;/P&gt;
&lt;P&gt;You can have used rules that do not log, and will never show up in the Traffic Monitor logs. Please ensure that this is not the case first.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next, you can use a filter like "( rule eq 'rulename' )" &amp;nbsp;without the quotes to search for traffic just for that rule name. &amp;nbsp;OR it can work in reverse if you want to show ALL but a certain rule name with "( rule neq 'rulename' )" where "neq" is NOT equal to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also go into "&lt;STRONG&gt;Monitor &amp;gt; Manage Custom reports&lt;/STRONG&gt; and then create a new report, use the traffic summary, and then use the same filter as above in the &lt;STRONG&gt;Query Builder&lt;/STRONG&gt; area.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope either of these help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 20:03:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76284#M42244</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2016-04-12T20:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76285#M42245</link>
      <description>&lt;P&gt;Good suggestions but I already checked to make sure it was set to log - specifically log at sessions end. I have used this filter rule eq rulename&amp;nbsp; and neq filter and it found nothing.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 20:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76285#M42245</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-12T20:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76287#M42247</link>
      <description>&lt;P&gt;I also tried the custom report and tried several different time frames and found nothing for the used rule that is shadowed by another and looks is showing as used but there is no evidence of it being used or having been used&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 20:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76287#M42247</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-12T20:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76299#M42252</link>
      <description>&lt;P&gt;From cli command below will show you what is your current retention period for traffic log (how many days worth of log fits into the traffic log database).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; show system logdb-quota&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With "show system info" you can see uptime of your firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If uptime is longer then retention period then some logs might be overwritten already and that can be reason why rule is used but you don't see it in the log.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 03:44:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76299#M42252</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-13T03:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76324#M42264</link>
      <description>&lt;P&gt;Thanks I will take a look at that, so that would be why an unused rule would be showing as used but have no instances in the traffic monitor&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 12:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76324#M42264</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-13T12:48:08Z</dc:date>
    </item>
  </channel>
</rss>

