<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Minemeld Syslog Miner Not parsing Messages in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/minemeld-syslog-miner-not-parsing-messages/m-p/325189#M801</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi, I am working with a new installation of Minemeld running on ubuntu 16.04. if I do a TCP dump I can see the Syslog but minemeld is not parsing them. I check the /var/log/Syslog and found this.&lt;BR /&gt;&lt;BR /&gt;It seems that some modules are missing and that gives an error. please let me know how can I install the missing Modules or how to fix this.&lt;BR /&gt;&lt;BR /&gt;Thanks &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Starting Process Monitoring and Control Daemon...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd: [origin software="rsyslogd" swVersion="8.16.0" x-pid="26659" x-info="&lt;A href="http://www.rsyslog.com" target="_blank" rel="noopener"&gt;http://www.rsyslog.com&lt;/A&gt;"] exiting on signal 15.&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd: [origin software="rsyslogd" swVersion="8.16.0" x-pid="20727" x-info="&lt;A href="http://www.rsyslog.com" target="_blank" rel="noopener"&gt;http://www.rsyslog.com&lt;/A&gt;"] start&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2222: command 'KLogPermitNonKernelFacility' is currently not permitted - did you already set it via a RainerScript command (v6+ config)? [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2222" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2222&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2066: &lt;STRONG&gt;could not load module '/usr/lib/rsyslog/pmpanngfw.so&lt;/STRONG&gt;', dlopen: /usr/lib/rsyslog/pmpanngfw.so: cannot open shared object file: No such file or directory [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2066" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2066&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01&lt;STRONG&gt; rsyslogd-2066: could not load module '/usr/lib/rsyslog/mmnormalize.so'&lt;/STRONG&gt;, dlopen: /usr/lib/rsyslog/mmnormalize.so: cannot open shared object file: No such file or directory [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2066" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2066&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2066:&lt;STRONG&gt; could not load module '/usr/lib/rsyslog/omrabbitmq.so'&lt;/STRONG&gt;, dlopen: /usr/lib/rsyslog/omrabbitmq.so: cannot open shared object file: No such file or directory [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2066" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2066&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2209: module name 'mmnormalize' is unknown [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2209" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2209&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2207: error during parsing file /etc/rsyslog.d/60-syslog-minemeld.conf, on or before line 9: errors occured in file '/etc/rsyslog.d/60-syslog-minemeld.conf' around line 9 [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2207" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2207&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2209: module name 'omrabbitmq' is unknown [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2209" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2209&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2207: error during parsing file /etc/rsyslog.d/60-syslog-minemeld.conf, on or before line 22: errors occured in file '/etc/rsyslog.d/60-syslog-minemeld.conf' around line 22 [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2207" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2207&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2159: error: parser 'rsyslog.panngfw' unknown at this time (maybe defined too late in rsyslog.conf?) [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2159" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2159&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd: rsyslogd's groupid changed to 108&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd: rsyslogd's userid changed to 104&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2039: Could not open output pipe '/dev/xconsole':: No such file or directory [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2039" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2039&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2007: action 'action 10' suspended, next retry is Tue Apr 28 11:29:53 2020 [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2007" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2007&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Stopping System Logging Service...&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Stopped System Logging Service.&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Starting System Logging Service...&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 mkdir[20706]: /bin/mkdir: cannot create directory ‘/var/run/minemeld’: File exists&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Started System Logging Service.&lt;BR /&gt;Apr 28 11:29:24 Minemeld-01 supervisord[20735]: /opt/minemeld/engine/0.9.68/local/lib/python2.7/site-packages/supervisor/options.py:383: PkgResourcesDeprecationWarning: Parameters to load are deprecated. Call .resolve and .require separately.&lt;BR /&gt;Apr 28 11:29:24 Minemeld-01 supervisord[20735]: return pkg_resources.EntryPoint.parse("x="+spec).load(False)&lt;BR /&gt;Apr 28 11:29:24 Minemeld-01 systemd[1]: minemeld.service: Can't open PID file /var/run/minemeld/minemeld.pid (yet?) after start: No such file or directory&lt;BR /&gt;Apr 28 11:29:24 Minemeld-01 systemd[1]: Started Process Monitoring and Control Daemon.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 17:03:11 GMT</pubDate>
    <dc:creator>mmatos</dc:creator>
    <dc:date>2020-04-28T17:03:11Z</dc:date>
    <item>
      <title>Minemeld Syslog Miner Not parsing Messages</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/minemeld-syslog-miner-not-parsing-messages/m-p/325189#M801</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, I am working with a new installation of Minemeld running on ubuntu 16.04. if I do a TCP dump I can see the Syslog but minemeld is not parsing them. I check the /var/log/Syslog and found this.&lt;BR /&gt;&lt;BR /&gt;It seems that some modules are missing and that gives an error. please let me know how can I install the missing Modules or how to fix this.&lt;BR /&gt;&lt;BR /&gt;Thanks &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Starting Process Monitoring and Control Daemon...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd: [origin software="rsyslogd" swVersion="8.16.0" x-pid="26659" x-info="&lt;A href="http://www.rsyslog.com" target="_blank" rel="noopener"&gt;http://www.rsyslog.com&lt;/A&gt;"] exiting on signal 15.&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd: [origin software="rsyslogd" swVersion="8.16.0" x-pid="20727" x-info="&lt;A href="http://www.rsyslog.com" target="_blank" rel="noopener"&gt;http://www.rsyslog.com&lt;/A&gt;"] start&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2222: command 'KLogPermitNonKernelFacility' is currently not permitted - did you already set it via a RainerScript command (v6+ config)? [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2222" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2222&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2066: &lt;STRONG&gt;could not load module '/usr/lib/rsyslog/pmpanngfw.so&lt;/STRONG&gt;', dlopen: /usr/lib/rsyslog/pmpanngfw.so: cannot open shared object file: No such file or directory [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2066" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2066&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01&lt;STRONG&gt; rsyslogd-2066: could not load module '/usr/lib/rsyslog/mmnormalize.so'&lt;/STRONG&gt;, dlopen: /usr/lib/rsyslog/mmnormalize.so: cannot open shared object file: No such file or directory [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2066" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2066&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2066:&lt;STRONG&gt; could not load module '/usr/lib/rsyslog/omrabbitmq.so'&lt;/STRONG&gt;, dlopen: /usr/lib/rsyslog/omrabbitmq.so: cannot open shared object file: No such file or directory [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2066" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2066&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2209: module name 'mmnormalize' is unknown [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2209" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2209&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2207: error during parsing file /etc/rsyslog.d/60-syslog-minemeld.conf, on or before line 9: errors occured in file '/etc/rsyslog.d/60-syslog-minemeld.conf' around line 9 [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2207" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2207&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2209: module name 'omrabbitmq' is unknown [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2209" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2209&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2207: error during parsing file /etc/rsyslog.d/60-syslog-minemeld.conf, on or before line 22: errors occured in file '/etc/rsyslog.d/60-syslog-minemeld.conf' around line 22 [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2207" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2207&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2159: error: parser 'rsyslog.panngfw' unknown at this time (maybe defined too late in rsyslog.conf?) [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2159" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2159&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd: rsyslogd's groupid changed to 108&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd: rsyslogd's userid changed to 104&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2039: Could not open output pipe '/dev/xconsole':: No such file or directory [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2039" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2039&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 rsyslogd-2007: action 'action 10' suspended, next retry is Tue Apr 28 11:29:53 2020 [v8.16.0 try &lt;A href="http://www.rsyslog.com/e/2007" target="_blank" rel="noopener"&gt;http://www.rsyslog.com/e/2007&lt;/A&gt; ]&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Stopping System Logging Service...&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Stopped System Logging Service.&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Starting System Logging Service...&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 mkdir[20706]: /bin/mkdir: cannot create directory ‘/var/run/minemeld’: File exists&lt;BR /&gt;Apr 28 11:29:23 Minemeld-01 systemd[1]: Started System Logging Service.&lt;BR /&gt;Apr 28 11:29:24 Minemeld-01 supervisord[20735]: /opt/minemeld/engine/0.9.68/local/lib/python2.7/site-packages/supervisor/options.py:383: PkgResourcesDeprecationWarning: Parameters to load are deprecated. Call .resolve and .require separately.&lt;BR /&gt;Apr 28 11:29:24 Minemeld-01 supervisord[20735]: return pkg_resources.EntryPoint.parse("x="+spec).load(False)&lt;BR /&gt;Apr 28 11:29:24 Minemeld-01 systemd[1]: minemeld.service: Can't open PID file /var/run/minemeld/minemeld.pid (yet?) after start: No such file or directory&lt;BR /&gt;Apr 28 11:29:24 Minemeld-01 systemd[1]: Started Process Monitoring and Control Daemon.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 17:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/minemeld-syslog-miner-not-parsing-messages/m-p/325189#M801</guid>
      <dc:creator>mmatos</dc:creator>
      <dc:date>2020-04-28T17:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld Syslog Miner Not parsing Messages</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/minemeld-syslog-miner-not-parsing-messages/m-p/326552#M806</link>
      <description>&lt;P&gt;Please post this question in the MineMeld Discussions forum&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Discussions/bd-p/MineMeldDiscussions" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Discussions/bd-p/MineMeldDiscussions&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 23:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/minemeld-syslog-miner-not-parsing-messages/m-p/326552#M806</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-05-06T23:17:12Z</dc:date>
    </item>
  </channel>
</rss>

