← Files CrowdStrike Falcon FusionARCHIVED FILE
skills/authoring/examples/response-actions/pan-ngfw-get-all-edls.yaml
1.89 KB · Oct 2, 2026 · 00:31 UTC
# Example: PAN NGFW - Get All EDLs
# Category: response-actions
# Source: CrowdStrike Content Library
name: PAN NGFW - Get All EDLs
description: Retrieves all External Dynamic List (EDL) objects configured on a PAN NGFW firewall for a given XPath scope (per-vsys or shared). Use this to audit available EDLs or identify the correct EDL name before performing blocklist or allowlist operations.
trigger:
next:
- GetAllEDLs
name: On demand
type: On demand
parameters:
properties:
FirewallIP:
type: string
description: IP address or hostname of the PAN NGFW management interface
XPath:
enum:
- /config/devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']/external-list
- /config/shared/external-list
type: string
description: 'XPath scope to query: use vsys path for per-vsys EDLs, or shared path for EDLs shared across all vsys'
required:
- XPath
- FirewallIP
type: object
actions:
GetAllEDLs:
id: 50b8a7cc77ea4ebb9d0bbe96d8def095
class: Inline.HTTPRequest
name: Get All EDLs
version_constraint: ~1
properties:
authentication_option: UseExisting
definition_id: 31fd9a5893df4127b93f9d27e80a1ea9
deployment_model: on_prem
host_group_id: 4775ad67cafd4edb90aa9d250678c871
http_transaction:
request_content_type: NONE
request_headers: {}
request_http_method: GET
request_query:
1e79e667-45ce-4bb6-90c0-3d8082954b35:
name: type
value: config
893e0c8b-a8bb-42c2-bd60-2413e99ef28d:
name: action
value: show
a186c680-5ddb-4643-84b0-c844e2cc0899:
name: xpath
value: ${data['XPath']}
request_url: https://${data['FirewallIP']}/api
response_body: ''
response_status_code: 200
insecure_skip_verify: true
SHA-256: d2ea74db1a29d7c2556633a796e6d950ace053143f5ea990c438fb3abd7a85ef