<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TAXII feed for SIEM in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/173371#M95321</link>
    <description>&lt;P&gt;I'm trying to ingest a TAXII feed from MineMeld into STAXX. After following the guidance found in multiple posts across the community, I'm still unable to get the feed to work. I've tried various tags (anonymous, any, custom) and I've tried both a "feed" user and an admin user for authentication purposes in STAXX. The errors I keep receiving are below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[2017-08-28 07:52:33,742] [ERROR] STAXX: Failed to get_feeds for site https://&lt;FONT color="#FF0000"&gt;[REMOVED]&lt;/FONT&gt;.paloaltonetworks-app.com/taxii-discovery-service, response: None&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[2017-08-28 07:52:33,742] [ERROR] HTTP/1.1 500 INTERNAL SERVER ERROR&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Traceback (most recent call last):&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;File "taxii_stix.py", line 789, in get_feeds&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;File "taxii_stix.py", line 708, in get_version_url&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;File "taxii_stix.py", line 745, in discover_version&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;File "taxii_stix.py", line 733, in discovery_generic&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;File "taxii_stix.py", line 509, in make_request&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Exception: HTTP/1.1 500 INTERNAL SERVER ERROR&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[2017-08-28 07:52:33,742] [ERROR] Discovery failed.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Aug 2017 08:02:26 GMT</pubDate>
    <dc:creator>jhopple</dc:creator>
    <dc:date>2017-08-28T08:02:26Z</dc:date>
    <item>
      <title>TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103578#M95291</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried minemeld with few miners and output to the inbounfeedhc i.e. PAN EBL/DBL. It is worked as expected. I would like to push the data to SIEM so that i can perform log analysis based on the indicators. How can i use taxii? I have configured ET.compromisedIP and Dshield miners to send data to new aggregator with output to stllib.feedHCGreen and stdlib.taxiiDataFeed based nodes. I can get data in PAN DBL using stdlib.feedHCGreen output node. What configuration will be needed so that I can configure our SIEM to use taxii based feed? For the taxii based node, I can see current indicators as 1080.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 19:58:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103578#M95291</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-08-16T19:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103596#M95292</link>
      <description>&lt;P&gt;Hi Sly_Cooper,&lt;/P&gt;
&lt;P&gt;what SIEM are you working with ?&lt;/P&gt;
&lt;P&gt;Can your SIEM retrieve (pull) indicators from MineMeld via TAXII ? Or should MineMeld push indicators to the SIEM using TAXII ?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 20:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103596#M95292</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-16T20:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103628#M95293</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori﻿&lt;/a&gt;&amp;nbsp;we use McAfee ESM. We already have one thread feed configured for hailataxii feed (&lt;A href="http://hailataxii.com/taxii-discovery-service" target="_blank"&gt;http://hailataxii.com/taxii-discovery-service&lt;/A&gt;). The current feed is configured as POST (and Collection Name). I dont see any URL to pull the data the way it is for DBL based output nodes.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 21:18:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103628#M95293</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-08-16T21:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103629#M95294</link>
      <description>&lt;P&gt;Hi Sly_Cooper,&lt;/P&gt;
&lt;P&gt;default output nodes do not support TAXII. But you can create new output nodes based on stdlib.taxiiDataFeed and attach them to your aggregators to support TAXII.&lt;/P&gt;
&lt;P&gt;Then you can query the MineMeld TAXII Discover Service at https://&amp;lt;minemeld&amp;gt;/taxii-discovery-service to retrieve the list of currently configured TAXII feeds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am working on the documentation for the TAXII output nodes, stay tuned &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 21:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103629#M95294</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-16T21:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103636#M95295</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori﻿&lt;/a&gt;&amp;nbsp;Thank you.&lt;/P&gt;
&lt;P&gt;I have configured custom aggregator node based on stlib.aggregatorIPv4Generic and custom output node based on stdlib.taxiiDataFeed. I am using DShild block list as miner. The SIEM just says Error and hostname while adding feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am also suspecting issue with self signed ssl cert.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 22:03:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/103636#M95295</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-08-16T22:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/104084#M95296</link>
      <description>&lt;P&gt;Please, could you post the full error message you get back from the SIEM ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 21:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/104084#M95296</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-17T21:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/104385#M95297</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The web ui just shows "Error and hostname on next line" when we try "Test Connection". I will see if there is way to get raw log from the system.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2016 16:50:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/104385#M95297</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-08-18T16:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/104658#M95298</link>
      <description>&lt;P&gt;Hi Sly_Cooper,&lt;/P&gt;
&lt;P&gt;I don't have access to a McAfee SIEM but this config should work:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Type:&lt;/STRONG&gt; TAXII&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;URL:&lt;/STRONG&gt; https://&amp;lt;minemeldip&amp;gt;/taxii-discovery-service&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Authentication:&lt;/STRONG&gt; None&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method:&lt;/STRONG&gt; POST&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ignore Invalid Certificate:&lt;/STRONG&gt; Checked (if you have changed the cet with a valid one you should uncheck this)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Collection Name:&lt;/STRONG&gt; &amp;lt;name of the TAXII output node&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2016 12:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/104658#M95298</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-19T12:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/105703#M95299</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori﻿&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured the required settings. Here is the new error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#999999"&gt;&lt;STRONG&gt;&lt;EM&gt;ERROR&lt;/EM&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;&lt;STRONG&gt;&lt;EM&gt;Error issuing TAXII request, HTTP response code: 400: Missing X-Server header&lt;/EM&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2016 22:31:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/105703#M95299</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-08-22T22:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108187#M95300</link>
      <description>&lt;P&gt;Hi Sly_Cooper,&lt;/P&gt;
&lt;P&gt;thanks for the additional log. I have found the issue, it's an oversight in the nginx config. It will be fixed in the next release.&lt;/P&gt;
&lt;P&gt;Meanwhile as a workaround you can edit the file /opt/minemeld/local/config/wsgi.yml and add the TAXII_HOST variable. The value should be the IP address of your MineMeld instance. Example if your MineMeld instance has IP 192.168.55.172:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;# this should be commented in production !
DEBUG: true

API_AUTH_ENABLED: true
USERS_DB: wsgi.htpasswd

SUPERVISOR_URL: "unix:///opt/minemeld/local/supervisor/run/minemeld.sock"

&lt;STRONG&gt;TAXII_HOST: 192.168.55.172&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After changing the file you should reload MineMeld Web API using the command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;sudo -u minemeld /opt/minemeld/engine/current/bin/supervisorctl -c /opt/minemeld/local/supervisor/config/supervisord.conf restart minemeld-web&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 08:34:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108187#M95300</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-29T08:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108368#M95301</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori﻿&lt;/a&gt;&amp;nbsp;I have got required configuration updated in the config file. Please note that the command to reload minemeld api worked fine in cli however there was warning in GUI "Error loading config" and indicators to "0". I restarted the VM and the gui loaded fine with all required nodes with indicator data. Now the error has changed on SIEM. I am not sure if the MineMeld configuration needs further tweaking.&lt;/P&gt;
&lt;PRE&gt;ERROR
Error issuing TAXII request, HTTP response code: 400: Invalid message&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 15:46:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108368#M95301</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-08-29T15:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108377#M95302</link>
      <description>Would you be available for a webmeeting? We could speed up the integration tests this way.&lt;BR /&gt;Just send me an email at lmori@paloaltonetworks.com &lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Luigi</description>
      <pubDate>Mon, 29 Aug 2016 15:55:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108377#M95302</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-29T15:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108417#M95303</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30703"&gt;@Sly_Cooper﻿&lt;/a&gt;&amp;nbsp;that error message typically happens when you try to access a TAXII feed that does not exist. Could you post the screenshot of your MM config and the config of McAfee SIEM ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 17:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108417#M95303</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-29T17:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108468#M95304</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 513px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5375i8E11A9E14E0F2012/image-dimensions/513x550/is-moderation-mode/true?v=v2" width="513" height="550" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 611px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5376iD295F966D027B918/image-dimensions/611x274/is-moderation-mode/true?v=v2" width="611" height="274" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Clipboard01.jpg" style="width: 570px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5377i719F744CEED197C2/image-dimensions/570x397/is-moderation-mode/true?v=v2" width="570" height="397" role="button" title="Clipboard01.jpg" alt="Clipboard01.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 19:49:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108468#M95304</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-08-29T19:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108470#M95305</link>
      <description>&lt;P&gt;McAfee SIEM Config and error&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_3.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5379i329B13502DA50CB6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot_3.png" alt="Screenshot_3.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 19:51:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108470#M95305</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-08-29T19:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108489#M95306</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30703"&gt;@Sly_Cooper﻿&lt;/a&gt;&amp;nbsp;could you post or send me the log /opt/minemeld/log/minemeld-web.log ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 21:03:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/108489#M95306</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-29T21:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/109891#M95307</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori﻿&lt;/a&gt;&amp;nbsp;Logs attached.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2016 15:16:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/109891#M95307</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-09-01T15:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/110613#M95308</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30703"&gt;@Sly_Cooper﻿&lt;/a&gt;&amp;nbsp;thanks !&lt;/P&gt;
&lt;P&gt;I have checked and you should change the config this way (note the URL now set to https://&amp;lt;minemeld&amp;gt;/taxii-poll-service):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1473090019878screensave.png" style="width: 622px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5458i6FE44C975EF8BB5F/image-dimensions/622x478/is-moderation-mode/true?v=v2" width="622" height="478" role="button" title="1473090019878screensave.png" alt="1473090019878screensave.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically you have to specify&amp;nbsp;URL of the TAXII poll service, not the URL of the discovery service.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After that indicators can be sucessfully downloaded:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-09-05 at 17.42.17.png" style="width: 629px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5459i84B8FCD7E01AAFCE/image-dimensions/629x268/is-moderation-mode/true?v=v2" width="629" height="268" role="button" title="Screen Shot 2016-09-05 at 17.42.17.png" alt="Screen Shot 2016-09-05 at 17.42.17.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 15:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/110613#M95308</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-05T15:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/110893#M95309</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori﻿&lt;/a&gt; Thank you. It worked! I could see the indicators in the watchlist. I will continue to work with minemeld and SIEM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI - The Minemeld instance failed automatically with error reading config message. All indicators went to zero. It started back automatically when checked after two days.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2016 14:55:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/110893#M95309</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-09-06T14:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII feed for SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/110894#M95310</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30703"&gt;@Sly_Cooper﻿&lt;/a&gt;&amp;nbsp;could you send me the file /opt/minemeld/log/minemeld-engine.log to check the error in reading the config ?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2016 14:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-feed-for-siem/m-p/110894#M95310</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-06T14:58:18Z</dc:date>
    </item>
  </channel>
</rss>

