- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-15-2026 06:36 AM
hello , i need to extract security policies from palo alto appliance
Model (PA-460)
is there a way to schedule the report or grant read only access to audit function ?
06-15-2026 07:36 AM
Hi @mostafa.abdelhakem ,
To accomplish this on a PA-460, you have two distinct approaches depending on whether you want a push method (scheduling automated email reports) or a pull method (granting direct, read-only access to an external auditor).
Because "Security Policies" are part of the firewall's XML configuration file rather than dynamic traffic data, standard PDF custom reports won't show the exact rule geometry. However, for auditing Palo Alto policies you can configure notifications for configuration changes under Device > Log Settings > Configurations.
As for granting Read-Only Access to an Auditor, you can create a customized Admin Role Profile:
Navigate to Device > Admin Role and click Add.
Name the profile something clear (e.g., Auditor-Read-Only).
Under the Web UI tab, set the rules for the tabs you want them to see.
Then you can create the actual auditor account. Go to Device > Administrators and click create a role based admin using the profile you just created earlier.
Hope this helps,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

