- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-23-2018 07:15 AM
I assume there is no report to list address objects that have not been used
Ones that may or may not be in rules, relate to long dead or incorrectly entered endpoints, that have not generated any traffic.
I have seen the "Shared_dup_and_unused... script, but don't think that gives me the desired result.
Unless someone has something already, I think it's a new script to parse the traffic logs.
Cheers
Rob
02-24-2018 10:59 AM
Correct, no current feature. Do contact your sales engineer and vote for FR 3159.
PAN maintains an internal database of customer "Feature Requests" and each is assigned an ID number.
Companies can add the "vote" for specific requests via your sales engineer.
Highlight Unused Objects
FR 3159
02-25-2018 05:55 PM
You can use the PANW Migration Tool;
Load a runnign config of your firewall(s) into that, and it has a section down the bottom of the 'Objects' tab to show/remove unused address objects
02-26-2018 01:16 AM
It's a while sice I have used the PAN migration tool, but I don't think it will do what I want.
The need is to find objects that may or may not be in a rule (not just ones that are not used in any rule) which have had no traffic logged from them.
As for logging it with our sales, I doubt they would ever pass it on and I doubt we will use them again!
Rob
03-03-2018 12:47 AM
As for a lot of topics without solution, the solution is the XML API.
If you really need something like that to check for used objects, you can write a script for doing exactly that:
Obviously depending on the size of the ruleset and the amount of objects this script can easily run for hours, but at the end you could have your custom object usage report.
Or use something like Tufin, to do this job. But even if you are not familiar with scripting, doing it by yourself is probably less expensive (unless you have other things wher Tufin would help you that are also time consuming)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!