edl_lookup
Checks if an IP, domain, or URL appears in a firewall's External Dynamic Lists, including exception lists, across Panorama device groups. Verifies EDL membership for security policy analysis.
Instructions
[READ-ONLY] Checks whether an IP, domain or URL is present in the External Dynamic Lists applying to a firewall (config from Panorama, current content from the firewall), including EDL exception lists.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Only this EDL | |
| value | Yes | IP, domain or URL to look for | |
| device | No | Specific firewall (hostname or serial). Usually omit it: the firewall is chosen from device_group, or from the user's/IP's recent traffic. | |
| firewall | No | Panorama entry from firewalls.json. Optional when a single Panorama is configured. | |
| device_group | No | Device group name (includes what it inherits from shared and parent groups), or 'shared'. When omitted, every location is searched. |