← Files CrowdStrike Falcon FusionARCHIVED FILE
skills/authoring/examples/response-actions/pan-ngfw-monitor-dag-members.yaml
1.57 KB · Oct 2, 2026 · 00:31 UTC
# Example: PAN NGFW - Monitor Dynamic Address Group Members
# Category: response-actions
# Source: CrowdStrike Content Library
name: PAN NGFW - Monitor Dynamic Address Group Members
description: Retrieves all currently registered IP-to-tag mappings from a PAN NGFW firewall. Use this to monitor which IPs are active members of Dynamic Address Groups (DAGs) and what tags they carry, providing visibility into runtime DAG membership.
trigger:
next:
- MonitorDAGMembers
name: On demand
type: On demand
parameters:
properties:
FirewallIP:
type: string
description: IP address or hostname of the PAN NGFW management interface
required:
- FirewallIP
type: object
actions:
MonitorDAGMembers:
id: 50b8a7cc77ea4ebb9d0bbe96d8def095
class: Inline.HTTPRequest
name: Monitor DAG Members
version_constraint: ~1
properties:
authentication_option: UseExisting
definition_id: 31fd9a5893df4127b93f9d27e80a1ea9
deployment_model: on_prem
host_group_id: 4775ad67cafd4edb90aa9d250678c871
http_transaction:
request_content_type: NONE
request_headers: {}
request_http_method: GET
request_query:
1e79e667-45ce-4bb6-90c0-3d8082954b35:
name: type
value: op
893e0c8b-a8bb-42c2-bd60-2413e99ef28d:
name: cmd
value: <show><object><registered-ip><all/></registered-ip></object></show>
request_url: https://${data['FirewallIP']}/api
response_body: ''
response_status_code: 200
insecure_skip_verify: true
SHA-256: f4f0ae91684982e7990ef7e77271908fc501b6547c45d3e5c9a95262c3f2d250