Has anyone seen the following issue?
Panorama manages a security policy for a remote PA, if you try clear the app seen counter on the remote PA using this KB https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/security-policy-rule-optimization/p... you get a server error: fail to clear usage data error.
If I clear the apps seen usage on the Panorama cli for the rule in question, I see the value back to 0, but on the remote PA it still shows the old usage count. Any reason why?
If you have a large number of rules, and want to save a lot of time over copying them individually in the GUI, it can be useful to export the list of rules from Panorma as a CSV and include the rule UUID column. You can then use a text editor like Notepad++ to prepend clear policy-app-usage-data ruleuuid to each entry, and paste the whole thing into your firewall's CLI. You'll want to run this command before pasting:
set cli scripting-mode on
Thanks, that is what the OP tried. It only works when using Panorama. I want to clear the counter for apps seen on the local FW. Reaper's reply was to clear counters, that is what I'm looking for. You would think the command should work on the local FW, but it doesn't. 😕
admin@palo220> clear policy-app-usage-data ruleuuid 66d7cf61-465c-4b47-bcc4-19b302919827
Server error : Failed to clear usage data
In my experience, policy optimizer is incredibly buggy, and the data isn't completely trustworthy. This seems to be one of those bugs. I was looking back on some internal notes from when I ran into this a few months ago. I found something else that makes this even more odd. When you run the clear policy-app-usage-data ruleuuid command in the firewall CLI, you get the error message, and the total apps displayed in the Apps Seen column doesn't change. However, the detailed list of apps does seem to get flushed. It's deceiving, but if you're trying to see which apps have hit the rule since it was last cleared, it still might be somewhat useful. It's frustrating though.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!