Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
Hello NQE Enthusiasts, Several Months ago we posted a challenge to use NQE to solve the FizzBuzz challenge . We had so much fun we thought we would make it a reoccurring exercise to demonstrate the power of NQE and and have some more fun with it. You might be asking “What are koans”?"koans" refer to a series of small coding challenges designed to teach programming concepts, often in a particular language. The term originates from Zen Buddhism, where a "koan" is a paradoxical question or statement used to provoke deep thought and insight.We are looking forward to see how everyone solves these challenges so tune in and give it a try, there are no wrong answers :).ChallengeYour task is to calculate the age of a list of people not in human years but in “dog years”. Assuming that one human year is equivalent to seven dog years. Calculate for the following input.Input people = [ { Name: "Tom", Age: 25 }, { Name: "Jerry", Age: 30 }, { Name: "Spike", Age: 15 } ];Expected Output: [ {
I was helping some folks in getting familiar with Forward Networks, we were having trouble in adding in new devices (that already exist in the parent network) in to the already created workspace. The existing options to add devices in the workspace looks to only include ways to create new connections to those devices. But I did not see any way for me to pull in existing devices from the parent network, after the workspace was already created. Does anyone have any insight into this?
I was asked by a customer to write an NQE check that would trigger a violation if there was not an explicit deny rule at the end of an ACL list. This query breaks down the acl list by acl name leveraging the group-by qualifier. We are also leveraging the `maxBy` function to find the last entry by leveraging the lineNumber property. // /**// * @intent Find acls by name, count and last entry// * @description test if there is an explicity deny rule at end of acl list// */acl_pattern_1 = `access-list {aclName:string} {!"remark"} {action:string} {rest:(string*)}`;maxLine(l) = l.line.lineNumber;foreach device in network.deviceswhere device.platform.vendor == Vendor.CISCOlet acls = patternMatches(device.files.config, acl_pattern_1)let acl_groups = (foreach acl in acls group acl as group_acls_by_name by { deviceName: device.name, aclName: acl.data.aclName } as v select { device
Hi Team , How can i get F5 VIP Ip and Pool address details by NQE. ThanksRohit
OverviewThis solution for renumbering line number defaults in NQEs addresses the issue of zero-based indexing by adding one to the line number output, aligning it with user expectations and conventional numbering in configuration files. This adjustment enhances usability and accuracy in network management by ensuring that outputs from NQEs are more intuitive and consistent with other data sources. Additionally, the logic can be applied to child line numbers, further improving the flexibility of the solution. Benefits Improved Usability: The adjustment aligns line numbers with user expectations, making outputs more intuitive and reducing confusion during configuration management and troubleshooting. Enhanced Accuracy: By providing one-indexed line numbers, the solution minimizes errors that could arise from mismatches between displayed and expected line numbers in configurations. Flexible Application: The logic used for renumbering can be extended to child line numbers, allowing for
Under the command type F5_LTM_POOL_STATE for F5 devices, the pool and pool members are in the following format:---------------------------------------------------------------------------------------Ltm::Pool: XXX ---------------------------------------------------------------------------------------Status Availability : XXX State : XXX ... -------------------------------------------------------------- | Ltm::Pool Member: XXX -------------------------------------------------------------- | Status | Availability : XXX | State : XXX ... -------------------------------------------------------------- | Ltm::Pool Member: XXX -------------------------------------------------------------- | Status
Hi Team,Can you please help me with a NQE Query to get SNMP configured IPs on Fortinet Devices.
I have a custom source that is appending zeros to the end of the microseconds which may be the cause of FN seeing it as a Float. Would it be possible in future versions to force a string data type so it might be manipulated or is there any other way I can manage this from the FN side? Excited to begin using the date and timestamp functions. Do you think they will become data types that could be used in the extractJson strings eventually? Custom source value: extractJson code: If i change the value to Number or String the query errors because it sees that value as a Floatselect code: Result:
parserecords(ep) = foreach x in [0] let recordid = extractJson[{ kind: String, selfLink: String, items: List<{ subList:List List<{ kind: String, selfLink: String, name: String }> }> }]foreach hs in network.externalSources.httpSourcesforeach ep in hs.endpointswhere ep.name == "endpointname" && ep.statusCode == 200let recordItems = (min(parserecords(ep))).itemsforeach i in recordItemsselect { SrcName: hs.name, subListName: i.subList.name}///////////////////////// Oops! The query doesn't work ///////////////Address the following issues: - Line xx, character xx: Can't access field 'name' from 'i.subList', because that is a List<{kind: String, selfLink: String, name:String}>.
A custom source API call returns a date field in microseconds format. Does NQE have a built in function to convert? For example, 1725899407, to Sept. 9, 2024. Currently I don’t need the hours and minutes but in the future it may be necessary. I’ve searched “date” and “microseconds” in the documentation and online without success.
Borrowing a capture of the Results window from another post on this site for reference, is it possible to filter for values that are not present?For example, instead of “cisco” could I return records that are !=cisco. I understand I have the options to write it in the NQE or export into Excel and filter as a spreadsheet but it would be useful to have the ability to filter other comparison operators on the fly in the Results window.
Is there a command equivalent to str(X) in Forward Networks?
For a user defined function as follows, can it be used to return a number or does it only return a Bool value? threshold : Number = 100;hasManySubInterfaces(iface) : Bool = length(iface.subinterfaces) > threshold; Say something like the following, is that possible? threshold : Number = 100;hasManySubInterfaces(iface) : Number= length(iface.subinterfaces) + threshold;
Is there any way to order the results in the NQE output ? E.g. order by field A then field B This would be within the query rather than once the results are shown in the table below the query itself.
We were finally able to configure and get SSO online and operational this past week in our Dev environment, and pushed it in to the production world yesterday. After running fine for about 10-12 hours, we came in this morning to the following error: SAML validation failed. Invalid assertion [insert a bunch of random letters and numbers] for SAML response [insert more random letters and numbers]: Assertion IssueInstant was invalid, expiredContact your Org Admin to resolve the issue. I check with the in group that manages SSO and they claim nothing has changed on their end, so now I must ask: How do we get past this so I can turn SSO back on? P.S. we are on base 11 app version 24.8 (rolling to 24.9 in a couple hours)
Scenario: Disabled all classic and all but one custom source in order to speed up and test an NQE with extractJson on an endpoint for a specific device. Observation: Unable to take a snapshot without at least one Classic source enabled.
The ability to include/exclude custom sources in bulk in the same way as classic sources would be useful if capability is possible. Secondary to an ability to bulk include/exclude custom sources would be the ability to bulk edit custom source profiles, basic authentication, SSL validation, and location. I also noticed when editing custom source that I had to update in phases. I imported csv of devices. I then attempted to update the profile and auth and location but it stated the source already existed and when I exited it only saved one of the settings. I then edited the src again and updated the location. If I recall it was unable to edit the tags at the same time as other config fields as well. No big deal for the few devices in my workspace and I have finished update but wanted to bring to your attention.
We are thrilled to announce the release of AI Assist for NQE! Whether you're new to the platform or a seasoned NQE expert, AI Assist allows you to skip complex syntax and describe what you need in plain English, making it easier than ever to create NQE queries. Generating an NQE query using AI AssistWhat is AI Assist?AI Assist enables you to write NQE queries using everyday language. Instead of manually writing complex queries, you can simply describe what you're looking for, and AI Assist will generate the appropriate NQE query for you. For example, to create a query that lists all CVEs currently impacting devices within a network, you can type, “List CVEs impacting each device,” and NQE AI Assist will instantly translate that into a valid query. How to Use AI AssistUsing AI Assist is easy. Just follow these steps:Log in to Forward Enterprise. Navigate to the NQE Library. Open the query editor by adding a new query. Click the AI Assist button. In the Generate tab, type your natural la
Hi All, Can you please help me to write a NQE query for all ip details where BGP Admin status id is showing down.
Custom source profile with Endpoint that is using “url/path?_return_type=json-pretty” but responseBody is one long line.I attempt to use splitJsonObjects; however, it isn’t returning in a structured layout for me to pattern match.
File this under “ya I’ll never do that again”. We’ve all had at least one “oops” that sticks with us.How does one find Cisco Switches or Routers that just happen to have the same Hostname or the same Management IP Address reported in LLDP and / or CDP? What if those alleged Cisco device just happen to have the same configuration except for the out of band management address? Accidentally of course. Well, this happened during a rapid stand up of two new Cisco routers. (Not me, of course. I learned this lesson many moons ago). To speed up the deployment, a copy / paste of config from one Router to two others occurred. Oh, yes, some nasty stuff happened after this. But that’s not pertinent to the resolution.NQE to the rescue. Since the Management IP addresses were “forgotten” or unknown to those troubleshooting the issue, how does one find these near identical twins? Remember that CDP announces Serial Numbers. LLDP typically does not advertise the device’s Serial Number. Thu
In Part 1 of Best way to start writing a Parser I described how you can start writing a parser without running it against a snapshot, which can save a lot of time.I ended it with parsing the interface out of a device output blob.This Article will extend the same NQE, but I will extend the content of the information that we will be parsing for.As a reminder, here the final NQE from Part 1:test_string ="""GigabitEthernet0/0 is up, line protocol is up (connected) MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, media type is RJ45 output flow-control is XON, input flow-control is XON ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters 25w3d Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: Class-based queueing Output queue: 0/1
Are you new to NQE?Do you need to write a pattern match parser but don't know where to start?Do you want to test your pattern match without running it against your snapshot, because it takes too long for each iteration?Well, I have been there and here's what I've learned.If you start writing a parser, you'll most likely run into multiple iterations that won't give you the desired results. If you're as impatient as me, you'd like to get your test results quickly back so you can adjust the parser.To do this, you can:Take a sample of the config or device output and store it in a variable. Write the parser to run against this sample. Check if the result is what you expect. Modify the parser and run step 3 until you get your expected results.Well, that sounds easy enough! But how do you actually do each of these steps?Here's an example.For example, lets assume you have to lookup information from the "show interfaces" command on Cisco devices, something like this:GigabitEthernet0/0 is up, li
what is format to pass the the path parameter in Path Mtu consistency check ?is it a list of devices ? is it a traceroute ?or source or destination ip ?
How would one replicate the OneIP table with NQE, including info such as IP address, MAC address, vendor, switch name and switch port?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.