<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filter Output By Category in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/filter-output-by-category/m-p/379227#M95531</link>
    <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;I'm working with the Proofpoint EThreat,&lt;BR /&gt;I'm trying to filter the output feed based on ET category.&lt;BR /&gt;&lt;BR /&gt;to archieve this, i'm editing the Output Node stlib with this condition:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#808080"&gt;- actions:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;- accept&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;conditions:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;- confidence &amp;gt; 75&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;- share_level == 'red'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;- proofpoint_etintelligence_categories == 'VPN'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;name: category CnC&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it doesn't work, probably because proofpoint_etintelligence_categories it's an Array&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#808080"&gt;"proofpoint_etintelligence_categories": [&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;"Drop",&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;"VPN"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;],&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4" color="#000000"&gt;&lt;FONT size="3"&gt;How can I filter with a condition&lt;/FONT&gt; (&lt;FONT size="2" color="#808080"&gt;proofpoint_etintelligence_categories CONTAIN "category_name"&lt;/FONT&gt;)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4" color="#000000"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jan 2021 09:48:14 GMT</pubDate>
    <dc:creator>bereon</dc:creator>
    <dc:date>2021-01-12T09:48:14Z</dc:date>
    <item>
      <title>Filter Output By Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filter-output-by-category/m-p/379227#M95531</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;I'm working with the Proofpoint EThreat,&lt;BR /&gt;I'm trying to filter the output feed based on ET category.&lt;BR /&gt;&lt;BR /&gt;to archieve this, i'm editing the Output Node stlib with this condition:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#808080"&gt;- actions:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;- accept&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;conditions:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;- confidence &amp;gt; 75&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;- share_level == 'red'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;- proofpoint_etintelligence_categories == 'VPN'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;name: category CnC&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it doesn't work, probably because proofpoint_etintelligence_categories it's an Array&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" color="#808080"&gt;"proofpoint_etintelligence_categories": [&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;"Drop",&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;"VPN"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" color="#808080"&gt;],&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4" color="#000000"&gt;&lt;FONT size="3"&gt;How can I filter with a condition&lt;/FONT&gt; (&lt;FONT size="2" color="#808080"&gt;proofpoint_etintelligence_categories CONTAIN "category_name"&lt;/FONT&gt;)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4" color="#000000"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 09:48:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filter-output-by-category/m-p/379227#M95531</guid>
      <dc:creator>bereon</dc:creator>
      <dc:date>2021-01-12T09:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Output By Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filter-output-by-category/m-p/379271#M95532</link>
      <description>&lt;P&gt;Found the solution:&lt;/P&gt;&lt;DIV&gt;contains(proofpoint_etintelligence_categories, 'category') == true&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Jan 2021 13:12:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filter-output-by-category/m-p/379271#M95532</guid>
      <dc:creator>bereon</dc:creator>
      <dc:date>2021-01-12T13:12:53Z</dc:date>
    </item>
  </channel>
</rss>

