<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to parse and filter proofpoint list in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-parse-and-filter-proofpoint-list/m-p/387185#M95439</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Since the default proofpoint miner is not working 'im trying to find a workaround to be able to download and filter the lists.&lt;/P&gt;&lt;P&gt;I have tried to use the generic json or csv miner but i'm having issues with both:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the json miner I receive 0 values from the lists, I guess is not able to parse it.&lt;/P&gt;&lt;P&gt;This is an example from the proofpoint list:&lt;/P&gt;&lt;P&gt;{&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "&lt;A href="http://webmail.bokep-indo.grup-whatsapp.xyz" target="_blank"&gt;webmail.bokep-indo.grup-whatsapp.xyz&lt;/A&gt;" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "Drop" : "72"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; },&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "&lt;A href="http://beaconsupport.com" target="_blank"&gt;beaconsupport.com&lt;/A&gt;" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "RemoteAccessService" : "51"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; },&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "&lt;A href="http://fbgaragedoors.com" target="_blank"&gt;fbgaragedoors.com&lt;/A&gt;" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "Drop" : "37"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; },&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "webmail.marelanhostlivev2.event-op.cf" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "AbusedTLD" : "98"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the&amp;nbsp;&lt;SPAN&gt;minemeld.ft.csv.CSVFT miner I have partial success, all the fields are parsed but filtering on "score" is not working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is a log example&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{&lt;BR /&gt;"category": "1",&lt;BR /&gt;"_age_out": 1616595084032,&lt;BR /&gt;"confidence": 80,&lt;BR /&gt;"share_level": "red",&lt;BR /&gt;"_last_run": 1614010284043,&lt;BR /&gt;"sources": [&lt;BR /&gt;"ProofpointET"&lt;BR /&gt;],&lt;BR /&gt;"score": "117",&lt;BR /&gt;"first_seen": 1614003084032,&lt;BR /&gt;"type": "IPv4",&lt;BR /&gt;"last_seen": 1614003084032&lt;BR /&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If in output condition I add "score &amp;gt; 99" this is ignored or not matched&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any suggestion on how to manage a custom list?&lt;/P&gt;&lt;P&gt;The originali list is a simple csv/json/txt with indicator,category,score.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Feb 2021 16:13:30 GMT</pubDate>
    <dc:creator>MMeld_Testing</dc:creator>
    <dc:date>2021-02-22T16:13:30Z</dc:date>
    <item>
      <title>How to parse and filter proofpoint list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-parse-and-filter-proofpoint-list/m-p/387185#M95439</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Since the default proofpoint miner is not working 'im trying to find a workaround to be able to download and filter the lists.&lt;/P&gt;&lt;P&gt;I have tried to use the generic json or csv miner but i'm having issues with both:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the json miner I receive 0 values from the lists, I guess is not able to parse it.&lt;/P&gt;&lt;P&gt;This is an example from the proofpoint list:&lt;/P&gt;&lt;P&gt;{&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "&lt;A href="http://webmail.bokep-indo.grup-whatsapp.xyz" target="_blank"&gt;webmail.bokep-indo.grup-whatsapp.xyz&lt;/A&gt;" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "Drop" : "72"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; },&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "&lt;A href="http://beaconsupport.com" target="_blank"&gt;beaconsupport.com&lt;/A&gt;" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "RemoteAccessService" : "51"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; },&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "&lt;A href="http://fbgaragedoors.com" target="_blank"&gt;fbgaragedoors.com&lt;/A&gt;" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "Drop" : "37"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; },&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "webmail.marelanhostlivev2.event-op.cf" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "AbusedTLD" : "98"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the&amp;nbsp;&lt;SPAN&gt;minemeld.ft.csv.CSVFT miner I have partial success, all the fields are parsed but filtering on "score" is not working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is a log example&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{&lt;BR /&gt;"category": "1",&lt;BR /&gt;"_age_out": 1616595084032,&lt;BR /&gt;"confidence": 80,&lt;BR /&gt;"share_level": "red",&lt;BR /&gt;"_last_run": 1614010284043,&lt;BR /&gt;"sources": [&lt;BR /&gt;"ProofpointET"&lt;BR /&gt;],&lt;BR /&gt;"score": "117",&lt;BR /&gt;"first_seen": 1614003084032,&lt;BR /&gt;"type": "IPv4",&lt;BR /&gt;"last_seen": 1614003084032&lt;BR /&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If in output condition I add "score &amp;gt; 99" this is ignored or not matched&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any suggestion on how to manage a custom list?&lt;/P&gt;&lt;P&gt;The originali list is a simple csv/json/txt with indicator,category,score.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 16:13:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-parse-and-filter-proofpoint-list/m-p/387185#M95439</guid>
      <dc:creator>MMeld_Testing</dc:creator>
      <dc:date>2021-02-22T16:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse and filter proofpoint list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-parse-and-filter-proofpoint-list/m-p/387316#M95440</link>
      <description>&lt;P&gt;For that JSON structure you cannot use the JSON parser, as the indicators are the keys of the feed and this is not supported. The JSON Miners expects a list of objects/indicators. Also if the feed is large JSON does not scale too well, as the full file should be loaded and parsed to extract indicators. I would suggest to use CSV Miner instead.&lt;/P&gt;
&lt;P&gt;The problem with the filter on the score is that the &lt;EM&gt;score&lt;/EM&gt; attribute is a string and not a number, the filter &lt;EM&gt;score &amp;gt; 99 &lt;/EM&gt;could not work then. You should convert &lt;EM&gt;score&lt;/EM&gt; to number before filtering, basically yous should try: &lt;EM&gt;to_number(score) &amp;gt; 99&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 08:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-parse-and-filter-proofpoint-list/m-p/387316#M95440</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2021-02-23T08:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse and filter proofpoint list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-parse-and-filter-proofpoint-list/m-p/387755#M95441</link>
      <description>&lt;P&gt;It worked, thank you for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a list of functions that can be used as filter in the output node?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 08:52:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-parse-and-filter-proofpoint-list/m-p/387755#M95441</guid>
      <dc:creator>MMeld_Testing</dc:creator>
      <dc:date>2021-02-25T08:52:52Z</dc:date>
    </item>
  </channel>
</rss>

