<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Messed up IPv4 ranges in output in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/messed-up-ipv4-ranges-in-output/m-p/314862#M96126</link>
    <description>&lt;P&gt;We are on MineMeld version 0.9.52. We had an incident with MineMeld on the 4th of March that caused a major outage for many of our users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have four miners feeding in IP addresses for our block list (let's call them bl-1, bl-2, bl-3 and wl-1). The first is for addresses we want to block, the next two use external threat feeds (one of them is itcertpa.IP), and the last is a white list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All four feed into a processor (let's call it p2, with prototype stdlib.aggregatorIPv4Generic) which in turn feeds into an output node (let's call it o2). In addition, for historical reasons bl-1 feeds into p1 which feeds into o1. I don't think p1 had any other inputs (although I could be wrong).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Last Wednesday something went wrong and both output nodes contained a number of address ranges that were not in any of the feeds. These ranges appeared to represent the addresses between address entries in the feeds. For example, bl1 contained the IP addresses 200.127.121.99 and 200.194.26.234. bl-2 contained the IP address 201.14.193.151. Instead of the output of o2 containing just these three addresses, it contained:&lt;/P&gt;
&lt;P&gt;200.127.121.99-200.127.121.99&lt;BR /&gt;200.127.121.100-200.194.26.233&lt;BR /&gt;200.194.26.234-200.194.26.234&lt;BR /&gt;200.194.26.235-201.14.193.150&lt;BR /&gt;201.14.193.151-201.14.193.151&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Obviously those second and fourth lines should not have been there (there were substantially more entries like this). The very first entry in the logs for 200.194.26.235-201.14.193.150 is a TRACE &lt;SPAN&gt;/ EMIT_UPDATE&lt;/SPAN&gt; for source p1 and is below:&lt;/P&gt;
&lt;P&gt;{&lt;BR /&gt;"comment": "user1 - 18-02-2020",&lt;BR /&gt;"_updated": 1583328197470,&lt;BR /&gt;"confidence": 100,&lt;BR /&gt;"_added": 1583328197470,&lt;BR /&gt;"share_level": "red",&lt;BR /&gt;"sources": [&lt;BR /&gt;"bl-1"&lt;BR /&gt;],&lt;BR /&gt;"first_seen": 1583328194879,&lt;BR /&gt;"_id": "50d9e67e-dd7c-4437-9809-5108a352c7c8",&lt;BR /&gt;"type": "IPv4",&lt;BR /&gt;"last_seen": 1583328194879&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The comment appears to be taken from entries added on the 18th of Feb. These entries were not related to 200.194.26.234. All the incorrect entries in the log appear to contain this same comment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I removed bl-2 and bl-3 from p-2 which seemed to also remove the wrong entries. I remove bl-1 from p-1 which basically made o-1 empty. I don't recall if there were any other feeds into p-1, but if there were I would have removed them at the same time. I later put bl-1 back into p-1 and it appeared normal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have any idea what might have caused this issue, or how I can find the root cause?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Mar 2020 08:23:54 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2020-03-06T08:23:54Z</dc:date>
    <item>
      <title>Messed up IPv4 ranges in output</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/messed-up-ipv4-ranges-in-output/m-p/314862#M96126</link>
      <description>&lt;P&gt;We are on MineMeld version 0.9.52. We had an incident with MineMeld on the 4th of March that caused a major outage for many of our users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have four miners feeding in IP addresses for our block list (let's call them bl-1, bl-2, bl-3 and wl-1). The first is for addresses we want to block, the next two use external threat feeds (one of them is itcertpa.IP), and the last is a white list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All four feed into a processor (let's call it p2, with prototype stdlib.aggregatorIPv4Generic) which in turn feeds into an output node (let's call it o2). In addition, for historical reasons bl-1 feeds into p1 which feeds into o1. I don't think p1 had any other inputs (although I could be wrong).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Last Wednesday something went wrong and both output nodes contained a number of address ranges that were not in any of the feeds. These ranges appeared to represent the addresses between address entries in the feeds. For example, bl1 contained the IP addresses 200.127.121.99 and 200.194.26.234. bl-2 contained the IP address 201.14.193.151. Instead of the output of o2 containing just these three addresses, it contained:&lt;/P&gt;
&lt;P&gt;200.127.121.99-200.127.121.99&lt;BR /&gt;200.127.121.100-200.194.26.233&lt;BR /&gt;200.194.26.234-200.194.26.234&lt;BR /&gt;200.194.26.235-201.14.193.150&lt;BR /&gt;201.14.193.151-201.14.193.151&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Obviously those second and fourth lines should not have been there (there were substantially more entries like this). The very first entry in the logs for 200.194.26.235-201.14.193.150 is a TRACE &lt;SPAN&gt;/ EMIT_UPDATE&lt;/SPAN&gt; for source p1 and is below:&lt;/P&gt;
&lt;P&gt;{&lt;BR /&gt;"comment": "user1 - 18-02-2020",&lt;BR /&gt;"_updated": 1583328197470,&lt;BR /&gt;"confidence": 100,&lt;BR /&gt;"_added": 1583328197470,&lt;BR /&gt;"share_level": "red",&lt;BR /&gt;"sources": [&lt;BR /&gt;"bl-1"&lt;BR /&gt;],&lt;BR /&gt;"first_seen": 1583328194879,&lt;BR /&gt;"_id": "50d9e67e-dd7c-4437-9809-5108a352c7c8",&lt;BR /&gt;"type": "IPv4",&lt;BR /&gt;"last_seen": 1583328194879&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The comment appears to be taken from entries added on the 18th of Feb. These entries were not related to 200.194.26.234. All the incorrect entries in the log appear to contain this same comment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I removed bl-2 and bl-3 from p-2 which seemed to also remove the wrong entries. I remove bl-1 from p-1 which basically made o-1 empty. I don't recall if there were any other feeds into p-1, but if there were I would have removed them at the same time. I later put bl-1 back into p-1 and it appeared normal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have any idea what might have caused this issue, or how I can find the root cause?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 08:23:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/messed-up-ipv4-ranges-in-output/m-p/314862#M96126</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-03-06T08:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Messed up IPv4 ranges in output</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/messed-up-ipv4-ranges-in-output/m-p/314882#M96127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@Retired Member,&lt;/P&gt;
&lt;P&gt;this is weird and I guess it could have been generated by an old Miner as bl-1. Could you share more about the config? what type of Miners are you using for bl-1, bl-2 and bl-3? How do you feed bl-1?&lt;/P&gt;
&lt;P&gt;Could you also search the logs for the string "&lt;SPAN&gt;200.194" ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Luigi&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 10:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/messed-up-ipv4-ranges-in-output/m-p/314882#M96127</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2020-03-06T10:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Messed up IPv4 ranges in output</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/messed-up-ipv4-ranges-in-output/m-p/315971#M96128</link>
      <description>&lt;P&gt;bl-1 uses the class "minemeld.ft.local.YamlIPv4FT". It's basically where we manually add addresses to block. It has the following config:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;age_out default: null&lt;BR /&gt;interval: 67&lt;BR /&gt;sudden_death: true&lt;BR /&gt;attributes confidence: 100&lt;BR /&gt;share_level: red&lt;BR /&gt;interval 3600&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bl-2 uses the class "minemeld.ft.http.HttpFT". It has the following config (with obfuscation of the URL as we pay for it):&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;attributes confidence: 100&lt;BR /&gt;share_level: red&lt;BR /&gt;type: IPv4&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;ignore_regex ^#&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;source_name ET.block_ips&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;url &lt;A href="https://a.domain.com/ti/v1/db-token/blackList?type=ip&amp;amp;listId=0&amp;amp;format=pan&amp;amp;token=12345" target="_blank"&gt;https://a.domain.com/ti/v1/db-token/blackList?type=ip&amp;amp;listId=0&amp;amp;format=pan&amp;amp;token=12345&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bl-3 uses the included itcertpa.IP prototype. Class is "minemeld.ft.http.HttpFT" and config is:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;age_out default: null&lt;BR /&gt;interval: 600&lt;BR /&gt;sudden_death: true&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;attributes confidence: 80&lt;BR /&gt;direction: inbound&lt;BR /&gt;share_level: green&lt;BR /&gt;type: IPv4&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;ignore_regex ^#.*&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;indicator regex: ^[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}$&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;source_name itcertpa.IP&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;url &lt;A href="https://infosec.cert-pa.it/analyze/listip.txt" target="_blank"&gt;https://infosec.cert-pa.it/analyze/listip.txt&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The logs in MimeMeld now appear to not be going back earlier than the 11th of March. However, I do have backups of the server (one week of dailies plus the first of each month). So, is there a way to extract the information from the logs using the CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 08:23:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/messed-up-ipv4-ranges-in-output/m-p/315971#M96128</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-03-12T08:23:18Z</dc:date>
    </item>
  </channel>
</rss>

