Skip to main content

Network Object Groups

A network object group is a named collection of network objects — hosts, ranges, subnets — that a rule can reference as a single unit instead of listing every member. This page counts how many exist, how that count has moved, and how many are no longer referenced or used. Policy data defines objects, and the three questions Insights asks about them.

Insights counts the groups and does not hold their contents. Groups are consolidated or removed in Security Manager, and the page links through to the list there for the selected device group.

Scope and range

The selected device group and date range apply to everything on the page. The range also sets the interval the figures are grouped into. Ranges longer than your history are unavailable. Device groups covers where groups come from and what else they scope.

Group counts and hygiene

The page reports the total group count across the range, with each interval's change from the one before.

Hygiene is three counts, each collected as its own metric, each with low as the ideal:

CategoryWhat it counts
UnreferencedThe group exists but no rule mentions it
UnusedNothing has been recorded as matching it — SIP holds no last-used date for it at all
DuplicatedAnother group holds identical contents under a different name

The combined hygiene figure adds the three together. They are counted separately, and one group can fall into more than one: an unreferenced group with no last-used date is counted once as unreferenced and again as unused. So that figure counts findings, not distinct groups.

The distinction matters for what you do next. No rule points at an unreferenced group at all. An unused group is referenced by a rule that has not matched, which makes it a question about the rule as much as the group.

By device

The three categories are also broken out per device, each reporting the device's value, its share of the device group's total for that category, and the change across the range. That reports whether a category is concentrated on a few devices or spread across many.

Devices are separately ranked by total group count rather than by hygiene, so a device can rank high with no hygiene findings against it.

The generated insight

A model writes the insight from your figures: the current and starting totals, each hygiene category's count and its share of the total, and which category is largest. It is also given the median rate for each category across FireMon customers and may quote it, so the insight can carry a comparison the page does not otherwise report. Benchmarking covers who is included.

Insights writes it once and keeps it for the day, so the same device group and range return the same wording. Where no total group count was collected for the range, there is no insight.