<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MineMeld Engine Stuck in Restart Loop in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/314887#M96219</link>
    <description>&lt;P&gt;hi Luigi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thx for your answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;im using the VERSION: 0.9.66.&lt;/P&gt;
&lt;P&gt;i have found a way to filter using the syntax: contains(xxxxx_list, 'yyyyyyy') == true&lt;/P&gt;</description>
    <pubDate>Fri, 06 Mar 2020 10:49:17 GMT</pubDate>
    <dc:creator>Farouk.Kahoul</dc:creator>
    <dc:date>2020-03-06T10:49:17Z</dc:date>
    <item>
      <title>MineMeld Engine Stuck in Restart Loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/298195#M96214</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I face an issue where my MineMeld server keeps on restarting continuously. Initially, it showed an error about low disk space, which got fixed by purging logs, however, the engine keeps restarting. Below is the sample log which I keep seeing repeatedly in engine logs. Attached the complete file. Any help is appreciated. Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2019-11-13T02:44:00 (37331)launcher.main ERROR: Exception initializing graph&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/minemeld-ansible/minemeld/engine/core/minemeld/run/launcher.py", line 288, in main&lt;BR /&gt;mbusmaster.wait_for_chassis(timeout=10)&lt;BR /&gt;File "/minemeld-ansible/minemeld/engine/core/minemeld/mgmtbus.py", line 140, in wait_for_chassis&lt;BR /&gt;raise RuntimeError('Timeout waiting for chassis')&lt;BR /&gt;RuntimeError: Timeout waiting for chassis&lt;BR /&gt;2019-11-13T02:44:00 (37331)mgmtbus.checkpoint_graph INFO: checkpoint_graph called, checking current state&lt;BR /&gt;2019-11-13T02:44:00 (37331)mgmtbus.checkpoint_graph INFO: graph status None, checkpoint_graph ignored&lt;BR /&gt;2019-11-13T02:44:00 (37636)chassis.stop INFO: chassis stop called&lt;BR /&gt;2019-11-13T02:44:00 (37638)chassis.stop INFO: chassis stop called&lt;BR /&gt;2019-11-13T02:44:00 (37636)base.stop ERROR: stop on not IDLE or STARTED FT&lt;BR /&gt;2019-11-13T02:44:00 (37638)base.stop ERROR: stop on not IDLE or STARTED FT&lt;BR /&gt;2019-11-13T02:44:00 (37638)chassis.stop ERROR: Error stopping Test-Vendor-IP&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/minemeld-ansible/minemeld/engine/core/minemeld/chassis.py", line 210, in stop&lt;BR /&gt;ft.stop()&lt;BR /&gt;File "/minemeld-ansible/minemeld/engine/core/minemeld/ft/actorbase.py", line 69, in stop&lt;BR /&gt;super(ActorBaseFT, self).stop()&lt;BR /&gt;File "/minemeld-ansible/minemeld/engine/core/minemeld/ft/base.py", line 763, in stop&lt;BR /&gt;raise AssertionError("stop on not IDLE or STARTED FT")&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 07:57:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/298195#M96214</guid>
      <dc:creator>shanu2405</dc:creator>
      <dc:date>2019-11-13T07:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Engine Stuck in Restart Loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/298257#M96215</link>
      <description>&lt;P&gt;The problem is in the custom prototype of&amp;nbsp;Azure-AD_Test node. infilters should be an array. If you paste the custom prototype conig here I can help.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 14:16:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/298257#M96215</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2019-11-13T14:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Engine Stuck in Restart Loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/298287#M96216</link>
      <description>&lt;P&gt;Thanks Luigi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That was the issue. Commit fixed it.&lt;/P&gt;&lt;P&gt;Coming to the Custom Prototype: I am trying to split the JSON &lt;A href="https://www.microsoft.com/en-us/download/confirmation.aspx?id=56519" target="_blank"&gt;feed&lt;/A&gt; of Azure IPs based on services/region/both.&lt;/P&gt;&lt;P&gt;Here is what I tried which failed. I can’t remember exactly, but I think it was created from aws.AMAZON&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; minemeldlocal_ms_AzurePublicIP_JSON-AD:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; class: minemeld.ft.json.SimpleJSON&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age_out:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default: null&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interval: 257&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sudden_death: true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; attributes:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; confidence: 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; share_level: green&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type: IPv4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; extractor: values[].properties.addressPrefixes[].{indicator:@}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; infilters:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; actions: accept&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; conditions: __method == 'withdraw' name_azure == 'AzureActiveDirectory'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name: accept withdraws&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; prefix: azure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source_name: azure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; url: &lt;A href="https://www.microsoft.com/en-us/download/details.aspx?id=56519" target="_blank"&gt;https://www.microsoft.com/en-us/download/details.aspx?id=56519&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; description: all Azure ranges&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; development_status: STABLE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; indicator_types:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - IPv4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; node_type: miner&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tags:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - ConfidenceHigh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - ShareLevelGreen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;--------------------------------------&lt;/P&gt;&lt;P&gt;I found it worked for region in another &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Filtering-Azure-IP-ranges-based-on-a-subset-of-regions/td-p/193368" target="_blank"&gt;post&lt;/A&gt; and tried similar conditions to accept indicators. It does work for region+service, but not for services alone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what I have created&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Miner uses prototype: azure.cloudIPsWithServiceTags&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Processor uses:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;------------&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;infilters:&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp; actions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - accept&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conditions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - __method == 'withdraw'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; name: accept withdraws&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp; actions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - accept&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conditions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - type == 'IPv4'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - &lt;STRONG&gt;azure_id == 'AzureCloud.uksouth2'&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; name: accept IPv4&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp; actions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - drop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; name: drop all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to be working in most of the cases unless I filter services which have their names matching with other IDs (region based) – example:&lt;/P&gt;&lt;P&gt;"id": "AzureActiveDirectory",&amp;nbsp; - 95 indicators&lt;/P&gt;&lt;P&gt;"id": "AzureActiveDirectoryDomainServices", - 73 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When such is the case, it keeps only unique values (22 indicators) and removes both values in case of a duplicate.&lt;/P&gt;&lt;P&gt;I’m not really good with scripting. Is there a way we can make the condition attribute as exact match?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 15:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/298287#M96216</guid>
      <dc:creator>shanu2405</dc:creator>
      <dc:date>2019-11-13T15:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Engine Stuck in Restart Loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/313535#M96217</link>
      <description>&lt;P&gt;hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you resolved your problem of filtering by service name?&lt;/P&gt;
&lt;P&gt;i have the same problem.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 14:48:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/313535#M96217</guid>
      <dc:creator>Farouk.Kahoul</dc:creator>
      <dc:date>2020-02-28T14:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Engine Stuck in Restart Loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/314885#M96218</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134388"&gt;@Farouk.Kahoul&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;which MineMeld version are you using? the most recent version (0.9.68) has several improvements in how the Azure feeds are handled and you can adopt a solution similar to the one used for regions also for services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luigi&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 10:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/314885#M96218</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2020-03-06T10:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Engine Stuck in Restart Loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/314887#M96219</link>
      <description>&lt;P&gt;hi Luigi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thx for your answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;im using the VERSION: 0.9.66.&lt;/P&gt;
&lt;P&gt;i have found a way to filter using the syntax: contains(xxxxx_list, 'yyyyyyy') == true&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 10:49:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-stuck-in-restart-loop/m-p/314887#M96219</guid>
      <dc:creator>Farouk.Kahoul</dc:creator>
      <dc:date>2020-03-06T10:49:17Z</dc:date>
    </item>
  </channel>
</rss>

