<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article How to Deploy MineMeld within Azure in Featured Articles</title>
    <link>https://live.paloaltonetworks.com/t5/featured-articles/how-to-deploy-minemeld-within-azure/ta-p/235380</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;&lt;H1&gt;&lt;A name="_Toc527131088"&gt;&lt;/A&gt;Introduction&lt;/H1&gt;
&lt;P&gt;MineMeld is an open-source tool from Palo Alto Networks to assist in threat feed aggregation and consumption. MineMeld’s “miners” are responsible for retrieving feed data on a defined basis and importing the data into MineMeld. Once imported, feeds are deduplicated and aggregated into one or more lists. After aggregation, the lists are published and ready for consumption by&amp;nbsp;Palo Alto Networks firewalls. MineMeld may be run on-premise or in a public cloud. This article shows the step-by-step process for deploying MineMeld within the Azure public cloud.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;A name="_Toc527131089"&gt;&lt;/A&gt;Deploy MineMeld to Azure&lt;/H1&gt;
&lt;H2&gt;&lt;A name="_Toc527131090"&gt;&lt;/A&gt;Deploy Template&lt;/H2&gt;
&lt;P&gt;Use the MineMeld ARM Template to deploy the required Ubuntu server into Azure.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Running-MineMeld-on-Microsoft-Azure/ta-p/78730"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Running-MineMeld-on-Microsoft-Azure/ta-p/78730&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click “Deploy To Azure” to get started.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17151iE5CDC9BC4FEFFD98/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture1.png" alt="Picture1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After filling in the required information, select purchase to continue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture2.png" style="width: 416px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17150i334D68395E426EC2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture2.png" alt="Picture2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wait until the deployment is complete.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture3.png" style="width: 533px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17148i1E105C046AA4B219/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture3.png" alt="Picture3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go to the Resource Group where the server was just created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture4.png" style="width: 539px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17149i8A31A6EA0EB964A2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture4.png" alt="Picture4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click on the virtual machine just created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture5.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17152iA6A1078C59AB6BBD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture5.png" alt="Picture5.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Copy the DNS name so you can SSH to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture6.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17153i1FF4D0EE9645B820/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture6.png" alt="Picture6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Open a terminal window and SSH into the instance to finish the MineMeld installation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture7.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17154i2AB568D5EF7AC438/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture7.png" alt="Picture7.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;A name="_Toc527131091"&gt;&lt;/A&gt;Begin Manual Process&lt;/H2&gt;
&lt;P&gt;Deploy IP Tables by copy and pasting the following commands. Answer “yes” to save IPv4/IPv6 tables.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;sudo apt-get update &amp;amp;&amp;amp; sudo apt-get install -y iptables-persistent&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -i lo -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -p tcp -m tcp --dport 13514 -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -p icmp -m icmp --icmp-type 0 -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -p icmp -m icmp --icmp-type 3 -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -A INPUT -p icmp -m icmp --icmp-type 11 -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -P INPUT DROP&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo iptables -P FORWARD DROP&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo bash -c "iptables-save &amp;gt; /etc/iptables/rules.v4"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo ip6tables -A INPUT -i lo -j ACCEPT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo ip6tables -P INPUT DROP&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo ip6tables -P FORWARD DROP&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt; sudo bash -c "ip6tables-save &amp;gt; /etc/iptables/rules.v6"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may notice the following error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;GPG error: &lt;A href="http://minemeld-updates.panw.io" target="_blank"&gt;http://minemeld-updates.panw.io&lt;/A&gt; trusty-minemeld InRelease: The following signatures were invalid: KEYEXPIRED&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will be addressed in a step below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add the MineMeld rep GPG key to the APT trusted keyring:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;wget -qO - &lt;A href="https://minemeld-updates.panw.io/gpg.key" target="_blank"&gt;https://minemeld-updates.panw.io/gpg.key&lt;/A&gt; | sudo apt-key add -&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Double check the GPG key fingerprint (should match characters in bold):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;apt-key adv --fingerprint DD0DA1F9&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt; &lt;EM&gt;Executing: gpg --ignore-time-conflict --no-options --no-default-keyring --homedir /tmp/tmp.W74MaAG3pI --no-auto-check-trustdb --trust-model always --keyring /etc/apt/trusted.gpg --primary-keyring /etc/apt/trusted.gpg --fingerprint DD0DA1F9&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; pub 4096R/DD0DA1F9 2016-07-15&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; &amp;nbsp;Key fingerprint = &lt;STRONG&gt;E558 CE6E 3968 0F31 8F6C BFAC B401 E02E DD0D A1F9&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; uid Palo Alto Networks, MineMeld Team &amp;lt;minemeld@paloaltonetworks.com&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After verifying the key, add MineMeld to the APT repository:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;sudo add-apt-repository "deb &lt;A href="http://minemeld-updates.panw.io/ubuntu" target="_blank"&gt;http://minemeld-updates.panw.io/ubuntu&lt;/A&gt; trusty-minemeld main"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perform another update.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;sudo apt-get update&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Install PIP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;sudo apt-get install python-pip&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Install MineMeld:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;sudo apt-get update &amp;amp;&amp;amp; sudo apt-get install -y minemeld rsyslog-minemeld rsyslog-mmnormalize&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;A name="_Toc527131092"&gt;&lt;/A&gt;Downgrade PIP&lt;/H2&gt;
&lt;P&gt;Follow these steps to downgrade PIP to version 9.0.3. If PIP is not downgraded, you may not be able to log into the MineMeld WEB GUI after completion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Stop the MineMeld service:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;sudo service minemeld stop&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Downgrade PIP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;sudo -H -u minemeld /opt/minemeld/engine/current/bin/pip install pip==9.0.3&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Start the MineMeld service:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" color="#99CC00"&gt;sudo service minemeld start&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;A name="_Toc527131093"&gt;&lt;/A&gt;Access MineMeld&lt;/H2&gt;
&lt;P&gt;Using the Azure DNS name, browse to the MineMeld instance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture8.png" style="width: 516px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17155iE0AD18366572C8F4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture8.png" alt="Picture8.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Login with the default credentials: admin / paloalto&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;A name="_Toc527131094"&gt;&lt;/A&gt;References&lt;/H1&gt;
&lt;P&gt;Deploy Azure Template&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Running-MineMeld-on-Microsoft-Azure/ta-p/78730"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Running-MineMeld-on-Microsoft-Azure/ta-p/78730&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Manually Deploy MineMeld&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-install-MineMeld-on-Ubuntu-Server-14-04/ta-p/98454"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-install-MineMeld-on-Ubuntu-Server-14-04/ta-p/98454&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 15 Oct 2018 15:04:00 GMT</pubDate>
    <dc:creator>kwall00</dc:creator>
    <dc:date>2018-10-15T15:04:00Z</dc:date>
    <item>
      <title>How to Deploy MineMeld within Azure</title>
      <link>https://live.paloaltonetworks.com/t5/featured-articles/how-to-deploy-minemeld-within-azure/ta-p/235380</link>
      <description>&lt;P&gt;Having trouble deploying MineMeld within Azure? Even with the helpful articles existing on this subject, you may still have trouble getting it to work. This article combines all of the required steps into one place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:04:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/featured-articles/how-to-deploy-minemeld-within-azure/ta-p/235380</guid>
      <dc:creator>kwall00</dc:creator>
      <dc:date>2018-10-15T15:04:00Z</dc:date>
    </item>
  </channel>
</rss>

