Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
is it possible to run NQEs immediately after a snapshot completes? If Forward can baseline what NQEs are always run after a snapshot completes (possibly this data baseline is based upon a period of time such as 30 days or some admin defined time period). Administrators can use this baseline data to flag those NQEs of priority to run immediately after the snapshot completes. in this way, results from priority NQEs are immediately available (from cached results) for applications to use with minimal delay.
how can i get the Egress and Ingress IP Details by NQE
Need one NQE Queries for Public IPs only from where outside traffic is coming to my internal network. Also want to get the output of below command on Fortinet Firewall through NQE Queries. “ local route prefix list ”I used one NQE Query that already on Forward Library - “Interfaces Using Public IPv4 Addresses” but this is not fulfilling my requirement. Tried Forward AI Assist also but not useful in this scenario.Can you please help me on this ?
This article explores NQE's robust pattern matching for extracting and parsing data, simplifying complex tasks with high-level, well-defined types for reporting and evaluation.Table of ContentsApproach 1: Leveraging the “or” pattern as described here Approach 1 Test Approach 2 : Unifying multiple patterns Approach 2 Test Approach 3: Evaluation via token count Approach 3 Test Approach 1: Leveraging the “or” pattern as described here Using the following pattern`ntp server {"vrf" vrf:string server:string | server:string}`; We can accommodate various patterns for this command syntax by which the literal “vrf” and the VRF name maybe elided from the command. Instead of needing to create two separate patterns we can combine them into one expression.Looking closer at how we then extract the properties out of the data for vrf and server. The expression will append all properties to the left of the ‘|’ pipe operator to the data.left property and will append all properties to the right of the
Is there a way to get the pair of switches for the VRRP protocol using NQE?
I am trying to get the output from commandType NHRP_STATE so I can then pull out the tunnel peer IPs with a patternmatch. When the NHRP table was a custom command the command.commandText was able to get this information, now how to do so that NHRP is part of the data model?
foreach device in network.devicesselect { deviceName: device.name}For the above NQE, if I get the device names in the format “aaa_bbb_ccc”, is there a way to split the output based on the string “_” and have three different fields?
OverviewIn my recent work with Palo Alto firewalls, I noticed that keeping configurations compliant can get complex, especially when administrators need to modify default settings for certain applications. Small changes to session handling or TCP timeouts, while necessary for specific use cases, can introduce inconsistencies and potential compliance issues. I developed straightforward NQEs to create compliance checks that help us monitor and manage these configurations effectively. Key Benefits:Improved Visibility: The compliance checks I set up give us a clear view into any configuration deviations across firewalls, making it easy to spot unauthorized changes. Targeted Control: By creating separate compliance checks for different parameters, like session setup and timeouts, we can focus on what matters most in our environment. Unified Compliance Management: Even though Panorama handles many configurations, Forward Networks fills in the gaps by providing custom compliance checks, givin
Hey, Forward Community Members!We're thrilled to invite you to submit your ideas for network configurations you’d like to see analyzed within our Net3 lab network. Whether it's testing new scenarios, troubleshooting common issues, or exploring unique configurations, we want to know what network setups you’re interested in. Example lab scenarios include:Layer 2 Host-to-Host communication in VXLAN EVPN fabric based on Arista STP/RSTP Layer2 pods built with Cisco or Arista switches Layer 3 MPBGP with VXLAN EVPN forwarding (Arista vEOS) IPv6/IPv4 Dual stack forwarding using routers/switches by Cisco and Arista, as well as Palo Alto firewalls SD-WAN Viptela/Catalyst SD-WAN As well as other configurations including Network Services - Load-balancer single-arm (SNAT/DNAT): A10 And many others! What network configuration would you like to see? Our Net3 lab network is constantly expanding with a diverse set of devices, offering a robust environment for analysis and experimentation. H
how can i merger 2 or 3 NQE Query into 1 , so that i can get output in single file.
Hi Team, Can you help to get all the details verifying NTP/DNS and Fortiguard configuratioins ?
I am trying to get an NQE scheduled to run every 5 mins. and fetch if an interface has any errors and/or if the interface utilization is high ( >90%).With the below NQE i get an error as below - Any fields with bytes is not recognized..ERROR: Record does not have field: "bytesOut". interfaceUtilization(iface) = 100 * (sum(iface.bytesOut) - sum(iface.bytesIn)) / (sum(iface.bytesOut) + sum(iface.bytesIn));foreach device in network.devicesforeach interface in device.interfaceswhere interface.adminStatus == AdminStatus.UPselect { deviceName: device.name, interfaceName: interface.name, utilization: interfaceUtilization(interface)} Not sure why “bytes” is not recognized by the NQE How to have this scheduled to run every 5 mins ?
The below are two lines that we are trying to pull data out of, but it appears utilizing device.file.config from the data model wont return the information because they are comments? Thoughts? !! Last configuration change at 13:58:30 ZULU Fri Oct 25 2024 by personx! NVRAM config last updated at 14:01:13 ZULU Thu Aug 22 2024 by persony!
Team, i am using below query to get the virtual server name and dst ip from below query , but somehow i am getting 0 result , can anyone please help . -=-------------------- pattern01 = ```Ltm::Virtual Server: {VirtualServer: string} | Availability : {Availability: string} | State : {State: string} | IP Address : {Destination: ipv4Address} | Reason : {Reason: string}```; foreach device in network.deviceswhere device.platform.vendor == Vendor.F5where device.snapshotInfo.result == DeviceSnapshotResult.completedforeach command in device.outputs.commandswhere command.commandType == CommandType.F5_VIRTUAL_SERVER_STATElet text = command.responselet text = replaceMatches(text, "\n", "\n ")let text = replaceMatches(text, " Ltm::Virtual Server: ", "Ltm::VirtualServer: ")let parsedCommand = parseConfigBlocks(OS.F5, text)foreach match in blockMatches(parsedCommand, pattern01)select { device: device.name, VirtualServer: match.
For reference - we recently were able to get Cisco Firepower ASA operating as FTD and FPRs on IOS FXOS, for the first time. With that…. Since none of the default commands produce any data in the state files, we are trying to use custom commands. Right now, when performing a show run, it comes back with 25 lines of configs, but then stops at --More--, which is when a user via cli would would push a button. We have lots of other devices running custom commands that do not do this, so why is it happening with FXOS and how can we work around it? Also, the FTD devices reporting all state files properly, its just the FPRs that are having issues.
Suppose you are using NQE queries to validate that your networking devices follow certain configuration benchmarks. You have an individual query for each benchmark, but you would also like a summary query that shows how each device in the network performs against every check. Here is how you can combine them.Below are two separate NQE queries that validate that the password policies on Cisco ASA devices require a minimum number of numbers and a minimum number of special characters, respectively.In each query, we define a function using the export command that takes in a Device as a parameter. export minNumber(device: Device) Then we call that function later in the same query with minNumber(device). This allows the query to be run on its own or part of another query.We save each file as min-numeric and min-special.pattern = ```password-policy minimum-numeric {minNum:number}```;checkPattern(config) = (max(blockMatches(config, pattern)))?.data?.minNum >= 1;export minNumber(device: Devi
how can i get the F5 POOL Member name ip and state and availability ?
What command can be ran from the CLI to find the postgres version?
I recently have done alot of work on building Golden Config and using NQE queries to find Actual Config on devices and compare to Golden Config and then building the remediation config so actual config will match Golden Config. I did this so Operations engineers can utilize the remediation config to implement on device either manually or through an Ansible playbook that utilizes the NQE Query and then build a workspace on devices being worked on to verify that Golden Config was implemented correctly on device(s). Below is a sample Query for a small section of config to ensure NTP configuration is correct on a Juniper device: goldenConfig_ntp_list = ["set system ntp server 10.10.10.10", "set system time-zone UTC" ];foreach device in network.deviceswhere device.platform.os == OS.JUNOSlet outputs = device.outputsforeach command in outputs.commands where command.commandText == "show configuration | display set" let text = parseConfigBlocks(OS.JUNOS, command.response)let configList =
i am using below query to get the F5 Partition details.======================== foreach device in network.deviceswhere device.platform.vendor == Vendor.F5let outputs = device.outputsforeach c in outputs.commandswhere c.commandType == CommandType.PARTITION_CONFIGselect { Device: device.name, Location: device.locationName, "Partition Name": c.response}===================================== but the output is not looks good , i am also getting the Partition description in Output , i just need only Partition name only , Please help
extractJson obtains a signatureId value that is a 9 digit Number. When viewing the results in the FN Results window the number appears with commas every three digits. *When exporting the results to Excel the command is not included in the output.
For any users that may be looking to leverage a query to gather information on devices to compare with an existing CMDB inventory, or looking to import data into their existing CMDB to update inventory. Please checkout this NQE: /** * @intent Basic information about Network Devices for CMDB import/compare */formatStatus(deviceSnapshotResult) = when deviceSnapshotResult is collectionFailed(collectionError) -> "Collecting - " + replace(toString(collectionError), "DeviceCollectionError.", ""); completed -> "Completed"; processingFailed(processingError) -> "Processing - " + replace(toString(processingError), "DeviceProcessingError.", "");foreach device in network.deviceslet platform = device.platformlet snapshotInfo = device.snapshotInfoforeach component in platform.componentsselect { Name: device.name, Location: device.locationName, Tags: device.tagNames, Vendor: platform.vendor, Model: platform.model, "Part Serial Number": component.serialNumb
I have several questions around the NQE api endpoint for running a queries. This endpoint has parameters for limit and offset for the number of records to skip and how many records to request.(example from the documentation){ "query": "foreach d in network.devices select { Name: d.name }", "queryId": "FQ_ac651cb2901b067fe7dbfb511613ab44776d8029", "commitId": "84f84b0c0a0a1805ddff0ca5451c2c55c58605e5", "queryOptions": { "offset": 20, "limit": 100, "sortBy": { "columnName": "Name", "order": "ASC" }, "columnFilters": [ { "columnName": "Name", "value": "MyDeviceName" } ] }, "parameters": { "mtuThreshold": 123, "ntpServers": [ "10.22.2.3", "192.33.4.1" ] }} I have a few questions, and would appreciate any guidance the community can providehow do i know the total number of records that is available ? do i just ask for the next number of records and if none are returned then i have the full set ? if i run the api fo
Introduction Hello Community! I wanted to share something I’ve been working on that may be helpful to you. It's a query designed to manipulate list arrays by transforming list elements into fixed-length strings, which then lets us easily join, split, or pop elements. NQE built-in functions provide list iteration and for the most part, this satisfies data model iteration for our queries. The approach presented here extends NQE list operation abilities to manipulate lists or extract specific values when required.To accomplish this we can apply a well known process called fixed-length string encoding which involves standardizing the length of each item in a list. By transforming variable-length strings into uniform sizes, we can “index” each item making if possible to perform operations like joining, splitting, and extracting elements. It opens up new possibilities for customizing functions beyond the basics of list iteration and hopefully, it will serve as a helpful tool when you nee
[Resolved]Hi team,when I am trying to use one NQE query for public IPs from Forward Network NQE Library to use it further more on my query, I am getting error while using this. Its showing me module error.
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.