<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Automate Minemeld .lst entries in Integration Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/integration-discussions/automate-minemeld-lst-entries/m-p/295575#M48</link>
    <description>&lt;P&gt;Needing Automation.&amp;nbsp; Our Security analysts often send an email with URL(s), IP(s) that need to be Allowed/Blocked.&amp;nbsp; We have experimented with EDL and Minemeld and are successfully using each.&amp;nbsp; We are going to consolidate to using only Minemeld for these requests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to automate it, so that the initial request can easily be approved and implemented without our (Implementation) team's involvement.&lt;BR /&gt;&lt;BR /&gt;Is anyone already using a simple system to accept URL/IP entries that runs the python script (minemeld-sync.py)?&amp;nbsp; We could tie it into Servicenow or maybe use a simple webpage?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any thoughts!&lt;/P&gt;</description>
    <pubDate>Thu, 31 Oct 2019 21:37:31 GMT</pubDate>
    <dc:creator>Timotheous</dc:creator>
    <dc:date>2019-10-31T21:37:31Z</dc:date>
    <item>
      <title>Automate Minemeld .lst entries</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/automate-minemeld-lst-entries/m-p/295575#M48</link>
      <description>&lt;P&gt;Needing Automation.&amp;nbsp; Our Security analysts often send an email with URL(s), IP(s) that need to be Allowed/Blocked.&amp;nbsp; We have experimented with EDL and Minemeld and are successfully using each.&amp;nbsp; We are going to consolidate to using only Minemeld for these requests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to automate it, so that the initial request can easily be approved and implemented without our (Implementation) team's involvement.&lt;BR /&gt;&lt;BR /&gt;Is anyone already using a simple system to accept URL/IP entries that runs the python script (minemeld-sync.py)?&amp;nbsp; We could tie it into Servicenow or maybe use a simple webpage?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any thoughts!&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 21:37:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/automate-minemeld-lst-entries/m-p/295575#M48</guid>
      <dc:creator>Timotheous</dc:creator>
      <dc:date>2019-10-31T21:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Automate Minemeld .lst entries</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/automate-minemeld-lst-entries/m-p/299615#M49</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85364"&gt;@Timotheous&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your question!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I'm sure you're aware, Minemeld is an open-source solution that is available to anyone who wants to run it. Due to it's open-source nature, there is no official support for it. I think it's best to look at your requirement(s) and determine whether it makes sense to build something on your own, or look at other methods/solutions to achieve the desired outcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, there are a couple of things that I'd recommend you take a look at:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Demisto - Palo Alto Networks acquired Demisto earlier this year and the product is a comprehensive Security Orchestration, Automation, and Response (SOAR) solution. Demisto has an incredibly vast ecosystem of products that it integrates with including Palo Alto Networks Next-Generation Firewall, Minemeld, and ServiceNow. You can create "playbooks" to automate SOC processes and standardize workflows. There's a "community edition" as well as an "enterprise edition". The community edition is supported through the Demisto community - the enterprise edition:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This link will allow you to view the Demisto Data Sheet:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://go.demisto.com/hubfs/Resources/Datasheets/data_sheet_final.pdf" target="_blank" rel="noopener"&gt;Demisto Data Sheet&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Palo Alto Networks AutoFocus is an officially supported threat intelligence platform that provides access to Palo Alto Networks' massive repository of threat intelligence and is consumable as a feed very similar in nature to Minemeld. There's an option for an AutoFocus-hosted version of Minemeld that removes the need for you to operate and maintain a locally hosted version of Minemeld.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This link will allow you to access the AutoFocus Data Sheet:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/resources/datasheets/autofocus-threat-intelligence" target="_blank" rel="noopener"&gt;AutoFocus Data Sheet&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally, this is a link to information on the AutoFocus-hosted version of Minemeld - a chapter within the AutoFocus Administrators Guide:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/autofocus/autofocus-admin/autofocus-apps/minemeld" target="_blank" rel="noopener"&gt;AutoFocus Hosted Minemeld&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ServiceNow offers an integration with AutoFocus:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://store.servicenow.com/sn_appstore_store.do#!/store/application/1061c8919f33120034c6b6a0942e702a/8.0.8?referer=sn_appstore_store.do%23!%2Fstore%2Fsearch%3Fq%3Dpalo%2520alto%2520networks" target="_blank" rel="noopener"&gt;ServiceNow Store: Palo Alto Networks AutoFocus for Security Operations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.servicenow.com/bundle/jakarta-security-management/page/product/secops-integration-palo-alto/concept/palo-alto-autofocus.html" target="_blank" rel="noopener"&gt;ServiceNow: Palo Alto Networks - AutoFocus Integration Overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And here are details on how to configure the ServiceNow integration with AutoFocus:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.servicenow.com/bundle/istanbul-security-management/page/product/palo-alto-autofocus/task/set-up-autofocus.html" target="_blank" rel="noopener"&gt;ServiceNow: Activate and Configure Palo Alto Networks AutoFocus Integration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me know if you have any additional questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your interest in Palo Alto Networks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-JeffH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Jeff Hochberg | Senior Solutions Engineer - Product Partnerships&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Palo Alto Networks&amp;nbsp;|&amp;nbsp;Atlanta, GA&amp;nbsp;|&amp;nbsp;&amp;nbsp;USA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The content of this message is the proprietary and confidential property of Palo Alto Networks and should be treated as such. If you are not the intended recipient and have received this message in error, please delete this message from your computer system and notify me immediately by reply e-mail. Any unauthorized use or distribution of the content of this message is prohibited.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 00:13:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/automate-minemeld-lst-entries/m-p/299615#M49</guid>
      <dc:creator>jhochberg</dc:creator>
      <dc:date>2019-11-20T00:13:52Z</dc:date>
    </item>
  </channel>
</rss>

