Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
Advisor
Jump to solution

Rules report with 0 Hits.

Hello, everybody.

Is it possible to have a report of all FW rules that have 0 Hits since about 90 days without use?

I have a MDS and VSX environment.

Many domains inside my MDS, and several FW Clusters in VSLS mode.

I want a “report” on one of the domains.

Is this possible?

Greetings.

0 Kudos
36 Replies
the_rock
Legend
Legend

O yea, that was my post back in the day, totally forgot about it 😃

Andy

genisis__
Mentor Mentor
Mentor

Do you think it will work on R81.10+?

Ideally it would be great if we could have a script that generates a list of rules with there UIDs with zero hit counts, ideal html format.  We could then present that a client which would form the basis of a change to remove these.

Next - and I think more challenging,  review the existing rule to determine if all object in a rule are actually being used, so that a further cleanup could be done by removing unused objects within a rule that has hits against it.

I know this is all possible, but just needs a good scripter who know checkpoint.  It would be an invaluable tool for us all.

Food for thought Checkpoint - Perhaps this could be a function built into SmartEvent, after all all the information is potentially there (R83+)

the_rock
Legend
Legend

Yes, it does work, I tested in R81.20 and R82. Script that does clean up of those rules would be excellent.

Andy

0 Kudos
genisis__
Mentor Mentor
Mentor

Will give it a go, may have to stump up a lab with some data though.

 

the_rock
Legend
Legend

Let me know if you need me to test anything.

Andy

0 Kudos
genisis__
Mentor Mentor
Mentor

thanks,  I've generated some code in chatGPT, so will be interesting to see if that actually works.  Will pass it over soon.

 

0 Kudos
the_rock
Legend
Legend

Sounds good @genisis__ 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events