Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
Under the Monitor Traffic Logs, is there a way to filter by mul... - Knowledge Base - Palo Alto Networks

Under the Monitor Traffic Logs, is there a way to filter by multiple address objects or address group?

0
Created On 02/16/19 03:14 AM - Last Modified 07/19/22 23:12 PM


Question


The following IP addresses 172.20.118.11; 172.20.118.12; 172.20.118.13 make up an Address Group called Trusted_Clients.
To search the Traffic logs for the associated traffic would require searching individual IP addresses or creating a query with all the addresses. This can present an issue if the Address Group is quite large.

Query Logs

Query


Environment


  • PAN-OS 9.0


Answer


Starting in 9.0, the option to query the Monitor logs by Address Group name is supported
Query Address Group Logs

Address Group Object


Note: A shortcut to add a query for an Address Group object can be done by using the drop down where the Address Group resides
On the GUI, navigate to Objects > Address Groups 
Drop down edited


Click on the drop down and select "Query Traffic Log"
Query Traffic Log
 


Additional Information


Limitation:
  • The address expansion of objects ONLY APPLIES to static address objects
  • DOES NOT apply for Dynamic Address Objects, Dynamic Address Groups (Groups with Dynamic Address Objects), and FQDN address objects

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmrSCAS&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail