<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom report analyse trafic on object in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432577#M95771</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rapport_palo_.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36249iD931FBDEB3FAE278/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rapport_palo_.PNG" alt="rapport_palo_.PNG" /&gt;&lt;/span&gt;Thank you for your answer&lt;BR /&gt;I want to see the unused objects&lt;BR /&gt;in my object groups&lt;BR /&gt;the policy optimizer does not allow me that.&lt;BR /&gt;I changed the database to "traffic log".&lt;BR /&gt;(see picture)&lt;BR /&gt;I have a lot of subnet I have to filter by subnet and match "(pkts_received neq 0)&lt;BR /&gt;"?&lt;/P&gt;</description>
    <pubDate>Wed, 08 Sep 2021 14:31:05 GMT</pubDate>
    <dc:creator>navaro06</dc:creator>
    <dc:date>2021-09-08T14:31:05Z</dc:date>
    <item>
      <title>Custom report analyse trafic on object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432272#M95193</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I want to check all my object addresses with zero traffic to clean up my flow rules. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can I replace my sources and destination IP with an "all IP" setting ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you help me ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;section "Query Builder" does not work (see image)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 14:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432272#M95193</guid>
      <dc:creator>navaro06</dc:creator>
      <dc:date>2021-09-07T14:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Custom report analyse trafic on objet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432276#M95194</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="analyse_objet.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36213iC20DE50A5935D98E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="analyse_objet.PNG" alt="analyse_objet.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 14:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432276#M95194</guid>
      <dc:creator>navaro06</dc:creator>
      <dc:date>2021-09-07T14:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Custom report analyse trafic on object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432295#M95403</link>
      <description>&lt;P&gt;To filter for any IP on the custom report, remove the src and dst filters. That report is a traffic report and is only going to report traffic over the last calendar month, it will not show unhit objects.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're looking at cleaning up rules, why not use the policy optimizer and look at unused rules?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 14:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432295#M95403</guid>
      <dc:creator>bafergel</dc:creator>
      <dc:date>2021-09-07T14:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Custom report analyse trafic on object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432577#M95771</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rapport_palo_.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36249iD931FBDEB3FAE278/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rapport_palo_.PNG" alt="rapport_palo_.PNG" /&gt;&lt;/span&gt;Thank you for your answer&lt;BR /&gt;I want to see the unused objects&lt;BR /&gt;in my object groups&lt;BR /&gt;the policy optimizer does not allow me that.&lt;BR /&gt;I changed the database to "traffic log".&lt;BR /&gt;(see picture)&lt;BR /&gt;I have a lot of subnet I have to filter by subnet and match "(pkts_received neq 0)&lt;BR /&gt;"?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 14:31:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/432577#M95771</guid>
      <dc:creator>navaro06</dc:creator>
      <dc:date>2021-09-08T14:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom report analyse trafic on object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/433195#M95835</link>
      <description>&lt;P&gt;I believe you may be able to use the Expedition tool to achieve what you're looking for. I have only briefly used the tool so someone else may be better at answering this but it looks like there is another thread discussing this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347" target="_self"&gt;TomYoung&lt;/A&gt;&amp;nbsp;said in regards to this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Expedition can make changes directly on the firewall.&amp;nbsp; It has been a while since I have done it, but I believe you add the device under Devices and make the changes under your project &amp;gt; Export &amp;gt; API Output Manager.&amp;nbsp; You should know the difference between Atomic and SubAtomic changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could also use "show | match &amp;lt;object-name&amp;gt;" in configuration mode (set format) and see where it is used in the configuration.&amp;nbsp; If the only line is the address object, it is not used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could also delete the object.&amp;nbsp; If it is used, you will get an error right away.&amp;nbsp; If not, the delete will be accepted in the candidate configuration.&amp;nbsp; UPDATE:&amp;nbsp; I saw this on Reddit, and it works.&amp;nbsp; Select all the objects.&amp;nbsp; (This may not be quick depending upon the number of objects.)&amp;nbsp; Select Delete and Yes.&amp;nbsp; All unused objects are deleted.&amp;nbsp; All used objects produce an error and are kept.&amp;nbsp; Use Device &amp;gt; Config Audit to see which objects were deleted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once Expedition is setup, that is the quickest and easiest."&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 19:07:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/433195#M95835</guid>
      <dc:creator>bafergel</dc:creator>
      <dc:date>2021-09-10T19:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom report analyse trafic on object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/433196#M95836</link>
      <description>&lt;P&gt;Here is the link to the thread and expedition tool.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool" target="_blank"&gt;https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/td-p/230055" target="_blank"&gt;https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-quickly-find-and-remove-unused-objects-in-policy/td-p/230055&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 19:08:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/433196#M95836</guid>
      <dc:creator>bafergel</dc:creator>
      <dc:date>2021-09-10T19:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom report analyse trafic on object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/433731#M95910</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your answer.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have already installed and used a palo expedtion virtual machine. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Palo expedition does not allow me to check objects traffic, it only shows unused objects.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I need to know if there is any traffic on the objects ( pkts_received neq 0 ) because some objects are seen as used because they are in object groups.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can I use a palo alto script to check that or report ? &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 09:34:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/433731#M95910</guid>
      <dc:creator>navaro06</dc:creator>
      <dc:date>2021-09-14T09:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Custom report analyse trafic on object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/433745#M95912</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192923"&gt;@navaro06&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;- First you have syntactical error in your query. You need to put the or in additional brakets, without them you query is searching for "dst network in 10.69.17.0/24 and zero received bytes" OR "any log where src network is 10.69.17.0/24. In addition you can use "addr" to search for given prefix in source and destination, so it should look like this:&lt;/P&gt;&lt;P&gt;(addr in 10.69.17.0/24) and ( pkts_received eq 0)&lt;/P&gt;&lt;P&gt;it is the same as ((addr.src in 10.69.17.0/24) or (addr.dst in 10.69.17.0/24)) and ( pkts_received eq 0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Even tho the above query is correct it still wouldn't provide the result you need. Think for a moment - the reports are generated by quering the traffic logs and aggregating the result in table. If there is object/network, that has never generated traffic, nor it was received traffic (aka unused), you will never see traffic logs for it, right? So searching traffic logs for traffic that never happend is pointless.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I personally also doesn't have much of experiance with Expedition, but as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176243"&gt;@bafergel&lt;/a&gt; suggested it may be your solution. In the latest version of Expedition tool, you have option to forward the traffic logs the tool, that way the analytic engine will be able to gather information which rule, which object and which group have been used (because it now have the actual rulebase and the traffic log, so it can map which object have been seen in the logs and which not). But for that purpose you will need bigger storage for the Expedition - in order to store longer period of logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your other option would be to invest in 3rd party tools like FireMon and Tufin. Couple years ago I was using FireMon and I remember it was very powerfull it can give you very detailed report. Unfortunately I don't believe you can achive the same result with firewall buil-in reporting.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 11:10:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-analyse-trafic-on-object/m-p/433745#M95912</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-09-14T11:10:44Z</dc:date>
    </item>
  </channel>
</rss>

