<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Viewing Unused Address Objects in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185674#M56777</link>
    <description>&lt;P&gt;The Migration Tool could be helpful. (I'm not sure if you've used it for migrations before, but it needs a bit of work to be useful). I'll look into that as an option.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2017 00:34:32 GMT</pubDate>
    <dc:creator>evan.wathington</dc:creator>
    <dc:date>2017-11-07T00:34:32Z</dc:date>
    <item>
      <title>Viewing Unused Address Objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185260#M56701</link>
      <description>&lt;P&gt;Hello fellow engineers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm in the process of a firewall audit in my environment and I've got a lot of address objects configured. I'd like to trim the list down and get rid of addresses that are no longer valid (as in haven't been used in over a year). Is something like this possible?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I saw this &lt;A href="https://live.paloaltonetworks.com/t5/API-Articles/Unused-and-Duplicate-Address-Object-Script/ta-p/62377" target="_self"&gt;link&lt;/A&gt; about a Perl Script, but it doesn't seem promising.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any other methods where I could get an accurate view of object usage?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this has been addressed in a previous thread, please direct me there. I couldn't find anything in my initial search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;—E&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 23:02:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185260#M56701</guid>
      <dc:creator>evan.wathington</dc:creator>
      <dc:date>2017-11-02T23:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing Unused Address Objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185483#M56738</link>
      <description>PanOS 7.0 Global Find helps a little &lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/management-features/global-find.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/management-features/global-find.html&lt;/A&gt; I'm guessing you have too many to do that manually. The Firewall Migration Tool has some clean-up functionality &lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool" target="_blank"&gt;https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool&lt;/A&gt; I haven't tried yet whether it can also detect junk in a PA policy.</description>
      <pubDate>Sat, 04 Nov 2017 15:56:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185483#M56738</guid>
      <dc:creator>BenLassila</dc:creator>
      <dc:date>2017-11-04T15:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing Unused Address Objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185631#M56768</link>
      <description>You can always simply attempt to delete the objects in question. If they are in use the PA will generate an alerts about it being utilized, and tell you where exactly the object is being used. When I do an object cleanup I usually just delete everything that isn't actively being used, way easier to have to create a few address objects when they are needed again then spending the time to verify they won't be needed going forward.</description>
      <pubDate>Mon, 06 Nov 2017 17:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185631#M56768</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-06T17:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing Unused Address Objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185674#M56777</link>
      <description>&lt;P&gt;The Migration Tool could be helpful. (I'm not sure if you've used it for migrations before, but it needs a bit of work to be useful). I'll look into that as an option.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 00:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185674#M56777</guid>
      <dc:creator>evan.wathington</dc:creator>
      <dc:date>2017-11-07T00:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing Unused Address Objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185675#M56778</link>
      <description>&lt;P&gt;There are two types of objects that I want to clean up - objects that are not in a policy and objects that are in a policy and are not being utilized over a certain amount of time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's tough to gather this data from the Palos because the address objects only exists as objects in the Objects tab. Once they're a part of a session the Palo can't record them as individual objects, but as just a part of a session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm reaching total object limitations and looking to sift through the data to remove as much as possible that's no longer being used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all of the suggestions. I appreciate. it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;—E&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 00:39:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/185675#M56778</guid>
      <dc:creator>evan.wathington</dc:creator>
      <dc:date>2017-11-07T00:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing Unused Address Objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/423898#M94215</link>
      <description>&lt;P&gt;Did you find the solution ?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 14:46:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-unused-address-objects/m-p/423898#M94215</guid>
      <dc:creator>Ayesha</dc:creator>
      <dc:date>2021-08-02T14:46:06Z</dc:date>
    </item>
  </channel>
</rss>

