Rule Usage Filtering

Filter rule usage to identify unused rules for deletion in order to improve your security posture.
Over-provisioned access on the firewall can be exploited by attacks, and administrators need to periodically check for outdated and unused rules. View the policy rule usage to simplify your rule lifecycle management to find unused rules and delete them to maintain an up to date rulebase and improve your security posture. In PAN-OS 9.0, Rule Usage Filtering enables you to quickly filter the selected rulebase based on the rule usage data, as well as additional rule data such as the Created and Modified dates, within a customizable timeframe.
Additionally, use the Rule Usage Filter to Migrate Port-Based to App-ID Based Security Policy Rules. By migrating to app-based rules, administrators can reduce the attack surface and gain visibility into, inspect, and safely enable applications on your network.
  1. Log in to the firewall web interface.
  2. Select DeviceSetup Management, and navigate to the Policy Rulebase Settings to verify that Policy Rule Hit Count is enabled.
  3. Select Policies and then select the policy rulebase to filter.
  4. In the Policy Optimizer window, click Rule Usage to view the rule usage filter.
  5. Filter rules in the selected rulebase.
    1. Select the Timeframe you want to filter from the drop-down, or specify a Custom timeframe.
    2. Select the rule Usage to filter.
    3. (Optional) If you have reset the rule usage data for any rules, check the Exclude rules reset during the last _ days, and within how many days the rules were reset in order to be excluded. Rules that were reset before the specified number of days are included in the filtered results.
    4. (Optional) Specify search filters based on additional rule data, other than the rule usage.
      1. Hover your mouse over the column header, and from the drop-down select Columns.
      2. Add any additional columns to want to filter with or to display.
      3. Hover your mouse over the column data that you would like to filter, and select Filter from the drop-down. For data that contain dates, select whether to filter using This date, This date or earlier, or This date or later.
      4. Click Apply Filter.

Related Documentation