<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Minemeld Ageout Policys and Withdraw in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/304588#M96360</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;There are still unanswered questions regarding aging of indicators, as well as minemeld working output configuration.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Can Minemeld function with “first_seen+2d” even if the indicator is still present in the feed?&lt;/LI&gt;&lt;LI&gt;If “first_seen+2d” is accepted, and the miner pulls the feed again with the indicator still present what happens to the indicator?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We are also trying to understand behaviors showing in our Minemeld instance such as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Miner node #1 has 7413 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Miner node #2 has 783 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Processor, with Miner node #1 and Miner node #2 as input, has 8196 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Output (minemeld.ft.redis.RedisSet) has 7413 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Same processor with different Output (minemeld.ft.taxii.DataFeed) and it currently has 587479 indicators – this number keeps on growing as indicators just keep getting added on until the next service restart.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any advice, guides or hints are much appreciated and thank you very much for your time and assistance.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Dec 2019 21:27:15 GMT</pubDate>
    <dc:creator>Vorskla</dc:creator>
    <dc:date>2019-12-20T21:27:15Z</dc:date>
    <item>
      <title>Minemeld Ageout Policys and Withdraw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/280602#M96357</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im having several issues and questions about what the best practices would be for surronding ageout policys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is it better to add an ageout policy to the Miners, Aggregators, or Outputs?&lt;/LI&gt;&lt;LI&gt;If I use the following Ageout policy, if a feed sends an IP right after the age-out occurs, will the first_seen time start over?&amp;nbsp;&amp;nbsp;&lt;UL&gt;&lt;LI&gt;age_out:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; default: first_seen+20d&lt;BR /&gt;&amp;nbsp; &amp;nbsp; interval: 600&lt;BR /&gt;&amp;nbsp; &amp;nbsp; sudden_death: true&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;I have a TAXII feed that is currently ignoring all withdrawal requests, but I cannot figure out why it is doing so.&amp;nbsp; Its using the base minemeld.ft.taxii.Datafeed class, and all the miners prior to it have the same ageout policy as the one above.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 01 Aug 2019 18:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/280602#M96357</guid>
      <dc:creator>DSHDAlex</dc:creator>
      <dc:date>2019-08-01T18:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld Ageout Policys and Withdraw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/299753#M96358</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having issues with age-out policy on miners.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any answers for the questions above? Anything new?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please, advise and thank you very much for your time!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 17:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/299753#M96358</guid>
      <dc:creator>Vorskla</dc:creator>
      <dc:date>2019-11-20T17:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld Ageout Policys and Withdraw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/301096#M96359</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still going through configurations via trial-and-error approach as the indicator numbers are not looking correct at all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reviewing configuration for Output of class&amp;nbsp;minemeld.ft.taxii.DataFeed&lt;/P&gt;&lt;P&gt;Added the following config:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;infilters:
- actions:
- accept
conditions:
- __method == 'withdraw'
name: accept withdraws
- actions:
- accept
conditions:
- type == 'IPv4'
name: accept IPv4
- actions:
- drop
name: drop all&lt;/LI-CODE&gt;&lt;P&gt;Would it be helpful to add "store_value: true" and how?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything that may be helpful to add to an OUTPUT configuration to make sure the node (somehow) does not keep accumulating indicators after every update and ignores indicators that have already been seen/aged-out ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any and all assistance or feedback is very much appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 19:05:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/301096#M96359</guid>
      <dc:creator>Vorskla</dc:creator>
      <dc:date>2019-11-27T19:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld Ageout Policys and Withdraw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/304588#M96360</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;There are still unanswered questions regarding aging of indicators, as well as minemeld working output configuration.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Can Minemeld function with “first_seen+2d” even if the indicator is still present in the feed?&lt;/LI&gt;&lt;LI&gt;If “first_seen+2d” is accepted, and the miner pulls the feed again with the indicator still present what happens to the indicator?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We are also trying to understand behaviors showing in our Minemeld instance such as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Miner node #1 has 7413 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Miner node #2 has 783 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Processor, with Miner node #1 and Miner node #2 as input, has 8196 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Output (minemeld.ft.redis.RedisSet) has 7413 indicators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Same processor with different Output (minemeld.ft.taxii.DataFeed) and it currently has 587479 indicators – this number keeps on growing as indicators just keep getting added on until the next service restart.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any advice, guides or hints are much appreciated and thank you very much for your time and assistance.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 21:27:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ageout-policys-and-withdraw/m-p/304588#M96360</guid>
      <dc:creator>Vorskla</dc:creator>
      <dc:date>2019-12-20T21:27:15Z</dc:date>
    </item>
  </channel>
</rss>

