<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New stix/taxii miner using cabby in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/278897#M95414</link>
    <description>&lt;P&gt;Awesome! Are you planning to add UI to it?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2019 13:31:02 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2019-07-25T13:31:02Z</dc:date>
    <item>
      <title>New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/278343#M95413</link>
      <description>&lt;P&gt;I created a new stix/taxii miner for MineMeld, it can be found on github: &lt;A href="https://github.com/mr-torgue/mmcabby" target="_blank"&gt;https://github.com/mr-torgue/mmcabby&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;It was created because I encountered severel problems with the default taxii miner and the ng miner. In general mmcabby is more stable because it uses cabby (from eclecticIQ developers of stix/taxii). It also contains support for certificate based authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Improvements/remarks/bug notifications are appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 13:02:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/278343#M95413</guid>
      <dc:creator>folmer</dc:creator>
      <dc:date>2019-07-23T13:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/278897#M95414</link>
      <description>&lt;P&gt;Awesome! Are you planning to add UI to it?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 13:31:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/278897#M95414</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2019-07-25T13:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/278909#M95415</link>
      <description>&lt;P&gt;Yes, that is one of the things I want to add in a future version. For now everything seems to be working well, so I don't know when I will work on it.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 14:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/278909#M95415</guid>
      <dc:creator>folmer</dc:creator>
      <dc:date>2019-07-25T14:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/294491#M95416</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112876"&gt;@folmer&lt;/a&gt;&amp;nbsp;i tried to get this going as according to your github instructions and doesn't work, i get a lot of errors. For example:&lt;/P&gt;
&lt;P&gt;oader._initialize_entry_point_group ERROR: minemeld.ft.local.YamlURLFT not loadable: pytz==2019.3 not compatible with pytz==2015.4, libtaxii==1.1.114 not compatible with libtaxii==1.1.107&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also the engine now is FATAL and doesnt load properly and i do not see this as an available prototype.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 19:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/294491#M95416</guid>
      <dc:creator>Carlos_Gomes</dc:creator>
      <dc:date>2019-10-25T19:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/295128#M95417</link>
      <description>&lt;P&gt;Hello Carlos, did you change the entries for pytz and libtaxii in requirements.txt? Usually requirements.txt&amp;nbsp;contains "pytz==2015.4" and libtaxii"=="1.1.107". However for cabby to work these need to be newer versions. So the requirements have to be changed to "pytz&amp;gt;=2015.4" and libtaxii&amp;gt;="1.1.107".&amp;nbsp;You can probably just restart the service and it should work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 08:00:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/295128#M95417</guid>
      <dc:creator>folmer</dc:creator>
      <dc:date>2019-10-30T08:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/295174#M95418</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112876"&gt;@folmer&lt;/a&gt;&amp;nbsp;Correct. i actually didnt have the folder core under &lt;SPAN&gt;opt/minemeld/engine/ so i created to match your instructions. I created the requirements.txt as per minemeld file in their github and changed the requirements for&amp;nbsp;pytz to pytz==2019.3 and libtaxii to&amp;nbsp;libtaxii==1.1.114, i think below its what you meant to write.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The errors in minemeld.engine log below as example i get that for every prototype.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(26093)loader._initialize_entry_point_group ERROR: minemeld.ft.taxii.TaxiiClient not loadable: pytz==2019.3 not compatible with pytz==2015.4, libtaxii==1.1.114 not compatible with libtaxii==1.1.107&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can try this again but havent had much luck leveraging cabby, i was try to do that as with AlienVault OTX i am getting sslv3 handshake failures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(26093)config._load_and_validate_config_from_file ERROR: Invalid config /opt/minemeld/local/config/committed-config.yml: Class minemeld.ft.taxii.TaxiiClient in Cyrebro10_OTX_Pulses not safe to load&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 12:26:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/295174#M95418</guid>
      <dc:creator>Carlos_Gomes</dc:creator>
      <dc:date>2019-10-30T12:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/295494#M95419</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112876"&gt;@folmer&lt;/a&gt;&amp;nbsp;i ended up uninstalling minemeld, upgraded to Ubuntu 18.04 and then deployed minemeld-ansible instead or minemeld-core&lt;/P&gt;
&lt;P&gt;now working a treat with cabby needed. sslv3 handshake errors gone.&lt;/P&gt;
&lt;P&gt;i cannot start minemeld-web service but that is a different issue altogether for another post.&lt;/P&gt;
&lt;P&gt;thank you for your reply and help.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 16:03:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/295494#M95419</guid>
      <dc:creator>Carlos_Gomes</dc:creator>
      <dc:date>2019-10-31T16:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/383543#M95420</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112876"&gt;@folmer&lt;/a&gt;. Have you had any success getting this extension to work with docker MineMeld distribution?&lt;/P&gt;&lt;P&gt;The engine/core directory didn't exist here.&lt;/P&gt;&lt;P&gt;I tried downloading the core git repo to engine/core, modifying the requirements.txt as recommended, but get errors when running "/opt/minemeld/engine/current/bin/python setup.py install".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;creating build/temp.linux-x86_64-2.7/minemeld/packages/gdns&lt;BR /&gt;x86_64-linux-gnu-gcc -pthread -DNDEBUG -g -fwrapv -O2 -Wall -Wstrict-prototypes -fno-strict-aliasing -Wdate-time -D_FORTIFY_SOURCE=2 -g -fstack-protector-strong -Wformat -Werror=format-security -fPIC -DHAVE_NETDB_H= -I/usr/include/python2.7 -c minemeld/packages/gdns/_ares.c -o build/temp.linux-x86_64-2.7/minemeld/packages/gdns/_ares.o&lt;BR /&gt;unable to execute 'x86_64-linux-gnu-gcc': No such file or directory&lt;BR /&gt;error: command 'x86_64-linux-gnu-gcc' failed with exit status 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice would be greatly appreciated. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 00:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/383543#M95420</guid>
      <dc:creator>Dave_W</dc:creator>
      <dc:date>2021-02-03T00:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: New stix/taxii miner using cabby</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/383816#M95421</link>
      <description>&lt;P&gt;I solved the dependency issues with an ugly fix. It will work however.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont know if the developer of minemeld is reading this, but why are minemeld python requirements version specific? For example pytz needs to be version 2015.4, which is pretty old. Also requests needs to be version 2.20 and libtaxii needs to be 1.107. If == could be replaced by &amp;gt;= there would be less dependency issues.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 12:53:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-stix-taxii-miner-using-cabby/m-p/383816#M95421</guid>
      <dc:creator>folmer</dc:creator>
      <dc:date>2021-02-04T12:53:26Z</dc:date>
    </item>
  </channel>
</rss>

