<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Impossible?  List unused Addres Objects? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202011#M59642</link>
    <description>&lt;P&gt;I assume there is no report to list address objects that have not been used&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ones that may or may not be in rules, relate to long dead or incorrectly entered endpoints,&amp;nbsp;that have not generated any traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen the "Shared_dup_and_unused... script, but don't think that gives me the desired result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless someone has something already, I think it's a new script to parse the traffic logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2018 15:15:51 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2018-02-23T15:15:51Z</dc:date>
    <item>
      <title>Impossible?  List unused Addres Objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202011#M59642</link>
      <description>&lt;P&gt;I assume there is no report to list address objects that have not been used&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ones that may or may not be in rules, relate to long dead or incorrectly entered endpoints,&amp;nbsp;that have not generated any traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen the "Shared_dup_and_unused... script, but don't think that gives me the desired result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless someone has something already, I think it's a new script to parse the traffic logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 15:15:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202011#M59642</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-02-23T15:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Impossible?  List unused Addres Objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202151#M59667</link>
      <description>&lt;P&gt;Correct, no current feature.&amp;nbsp; Do contact your sales engineer and vote for FR 3159.&lt;/P&gt;&lt;P&gt;PAN maintains an internal database of customer "Feature Requests" and each is assigned an ID number.&lt;/P&gt;&lt;P&gt;Companies can add the "vote" for specific requests via your sales engineer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Highlight Unused Objects&lt;/P&gt;&lt;P&gt;FR&amp;nbsp; 3159&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 18:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202151#M59667</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-02-24T18:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Impossible?  List unused Addres Objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202180#M59670</link>
      <description>&lt;P&gt;You can use the PANW Migration Tool;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Migration-Tool-Articles/MigrationTool-3-3-Info-and-Guide/ta-p/72559" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Migration-Tool-Articles/MigrationTool-3-3-Info-and-Guide/ta-p/72559&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Load a runnign config of your firewall(s) into that, and it has a section down the bottom of the 'Objects' tab to&amp;nbsp;show/remove unused address objects&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 01:55:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202180#M59670</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-02-26T01:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Impossible?  List unused Addres Objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202227#M59675</link>
      <description>&lt;P&gt;It's a while sice I have used the PAN migration tool, but I don't think it will do what I want.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The need is to find objects that may or may not be in a rule (not just ones that are not used in any rule) which have had no traffic logged from them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for logging it with our sales, I doubt they would ever pass it on and&amp;nbsp;I doubt we will use them again!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 09:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/202227#M59675</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-02-26T09:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Impossible?  List unused Addres Objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/203387#M59923</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for a lot of topics without solution, the solution is the XML API.&lt;/P&gt;&lt;P&gt;If you really need something like that to check for used objects, you can write a script for doing exactly that:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Parse the ruleset for all the objects used&lt;/LI&gt;&lt;LI&gt;Lookup these objects in the configuration to get the ip address/subnet/IP range&lt;/LI&gt;&lt;LI&gt;Use the information from point 2 to query the logs for each object/address one by one and exclude the drop all policy in your query&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Obviously depending on the size of the ruleset and the amount of objects this script can easily run for hours, but at the end you could have your custom object usage report.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or use something like Tufin, to do this job. But even if you are not familiar with scripting, doing it by yourself is probably less expensive (unless you have other things wher Tufin would help you that are also time consuming)&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 08:47:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/impossible-list-unused-addres-objects/m-p/203387#M59923</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-03T08:47:26Z</dc:date>
    </item>
  </channel>
</rss>

