<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need stdlib.aggregatorIPv4Generic to provide single IPs instead of IP r in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-stdlib-aggregatoripv4generic-to-provide-single-ips-instead/m-p/339673#M95617</link>
    <description>&lt;P&gt;Hi, just curious if you found any resolution of that issue ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Get the same issue in Log analytics. All my Ipv4 indicators are in CIDR too in Azure Log Anytic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found a workaround with KQL&amp;nbsp;ipv4_is_match() function&amp;nbsp;but didn't try it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/data-explorer/kusto/query/ipv4-is-matchfunction" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/data-explorer/kusto/query/ipv4-is-matchfunction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 18:23:38 GMT</pubDate>
    <dc:creator>papham</dc:creator>
    <dc:date>2020-07-20T18:23:38Z</dc:date>
    <item>
      <title>Need stdlib.aggregatorIPv4Generic to provide single IPs instead of IP ranges</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-stdlib-aggregatoripv4generic-to-provide-single-ips-instead/m-p/322120#M95615</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to use Minemeld in a setup with Microsoft Sentinel (Microsoft Graph).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am encountering an issue with entities of type IP, as they are getting&amp;nbsp; in my log analytics space as IP ranges, mentioned in the "ExternalIndicatorID" along with the word IPv4. I cannot process that and I need single IP alone in another column, like NetworkIP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to change the processor to provide single IPs instead of ranges?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 12:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-stdlib-aggregatoripv4generic-to-provide-single-ips-instead/m-p/322120#M95615</guid>
      <dc:creator>GabrielNBJJ</dc:creator>
      <dc:date>2020-04-10T12:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need stdlib.aggregatorIPv4Generic to provide single IPs instead of IP ranges</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-stdlib-aggregatoripv4generic-to-provide-single-ips-instead/m-p/322128#M95616</link>
      <description>&lt;P&gt;I found some info about modifying the FEED URL, however I have no such URL in my Microsoft output node.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any workarounds to that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 13:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-stdlib-aggregatoripv4generic-to-provide-single-ips-instead/m-p/322128#M95616</guid>
      <dc:creator>GabrielNBJJ</dc:creator>
      <dc:date>2020-04-10T13:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Need stdlib.aggregatorIPv4Generic to provide single IPs instead of IP r</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-stdlib-aggregatoripv4generic-to-provide-single-ips-instead/m-p/339673#M95617</link>
      <description>&lt;P&gt;Hi, just curious if you found any resolution of that issue ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Get the same issue in Log analytics. All my Ipv4 indicators are in CIDR too in Azure Log Anytic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found a workaround with KQL&amp;nbsp;ipv4_is_match() function&amp;nbsp;but didn't try it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/data-explorer/kusto/query/ipv4-is-matchfunction" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/data-explorer/kusto/query/ipv4-is-matchfunction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 18:23:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-stdlib-aggregatoripv4generic-to-provide-single-ips-instead/m-p/339673#M95617</guid>
      <dc:creator>papham</dc:creator>
      <dc:date>2020-07-20T18:23:38Z</dc:date>
    </item>
  </channel>
</rss>

