Skip to main content
rmon
New Member
June 29, 2016
Question

Trying to identify Policy IDs with a zero counter or less than a particular value

  • June 29, 2016
  • 1 reply
  • 2807 views

Hi all,

 

I am trying to see if there is a way to run a report on policy ids that have a counter value of either zero or less than a particular value, for example less than 500k.  I am trying to perform some policy clean up and want to get rid of rules that have not gotten any hits for the past quarter (3 months).  If i can help it, I dont want to generate a report on all rules and weed out the ones that have zero.  Any thoughts are appreciated.  

 

Thanks!

    1 reply

    CrisP
    New Member
    June 29, 2016

    Hello

    There is a dataset called "bandwidth-app-Top-Policies-By-Bandwidth-Sessions", you could modify order by bandwidth descending to order by bandwidth ascending, then you get a list starting with useless or less used policies. But less used doesn't usually mean useless... That's why, in order to rid your list from ancient policies which had traffic some time ago but are now bypassed, I think you should find a way to reset the counters in CLI before running the dataset, then run it at least for a week or a month (maybe you have some guys that place bets or an app that updates a database; let's forget the rest, they'll call you when in distress).

    Happy garbage collect!

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!