All templates
For network security engineers, security operations teams & IT infrastructure teams

Catch firewalls running old threat content

Every night, WebRun signs in to your Palo Alto Networks management console, reads the content update and software version on every firewall and device group, compares each against the newest version available, checks subscription status, posts the devices that are behind to Slack, and cards the laggards in Trello.

  • No credit card
  • Under $0.01 per run
  • Cancel anytime
14,115 templates Safe automation No code
Every night at 11:00 PM WebRun
1 Palo Alto Networks read versions per device
2 Slack post the devices behind
3 Trello card each laggard device
Run a sample
In short

How do I check which firewalls are behind on threat content updates?

WebRun signs in to your Palo Alto Networks console every night and reads the content update and software version on each managed firewall, along with its subscription status. It posts the devices sitting behind the newest version to Slack and cards each laggard in Trello for the network team.

  • Devices behind on threat content surface the same night
  • Lapsed subscriptions are called out separately, not buried
  • The run is read-only: no update is installed without a human

Built for network security engineers · security operations teams · IT infrastructure teams · managed service providers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.paloaltonetworks.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Palo Alto Networks - read versions per device
    paloaltonetworks.com
    WebRun in Palo Alto Networks: read versions per device
    WebRun opens Palo Alto Networks to read versions per device.
    • Sign in to your Palo Alto Networks management console and list the managed firewalls
    • For each device, read the installed content update version and the software version
    • Read the newest content version available and work out how far behind each device sits
    • Check the subscription and licence status on each device and flag anything lapsed or close to lapsing
    • Group results by device group so the pattern is easy to see

    Done when Every firewall has its content version, software version, and subscription status recorded.

  3. 2
    Slack - post the devices behind
    slack.com How to Automate Slack
    WebRun in Slack: post the devices behind
    WebRun opens Slack to post the devices behind.
    • Post tonight's coverage summary to your network security channel in Slack
    • List only the devices behind the newest content version, with how far behind each is
    • Call out any lapsed subscription separately, since that stops updates entirely
    • Say plainly when the whole estate is current so the team knows the check ran

    Done when The security channel knows which firewalls are behind tonight.

  4. 3
    Trello - card each laggard device
    trello.com How to Automate Trello
    WebRun in Trello: card each laggard device
    WebRun opens Trello to card each laggard device.
    • Open your network operations board in Trello
    • Add a card per device that is behind, naming the device group and the version gap
    • Put devices with a lapsed subscription at the top since they receive nothing new
    • Close cards for devices brought current since the last run

    Done when Every device needing an update has a card on the board.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.paloaltonetworks.com
ScheduleRuns automatically on this cadence
Every night at 11:00 PM
DeliveryHow each run's result reaches you
Update coverage report · Slack
OutputWhat each run produces - A nightly device by device list of content and software versions, how far behind each firewall is, and any lapsed subscription.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it install an update or reboot a firewall?

No. WebRun reads versions and reports the gaps. Installing content, upgrading software, or rebooting a device stays a change-controlled human action.

Does it change any firewall policy?

No. This run is read-only. WebRun does not create, edit, or push a policy rule, and it does not commit any configuration change.

What about devices that are already current?

They are left out of the Slack post and the board. WebRun confirms in one line that the estate is current so silence never means the check failed.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.