<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MineMeld into Proofpoint TRAP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-into-proofpoint-trap/m-p/292632#M96462</link>
    <description>&lt;P&gt;For what it is worth, it can be made to work.&amp;nbsp; ProofPoint TRAP has a few issues.&amp;nbsp; &amp;nbsp;You will need to build trust on TRAP of the MineMeld root CA (trust the certificate), set TRAP to poll at 1 hour, not 1 minute, or you will periodically consume all RAM within TRAP and then TRAP will fail.&amp;nbsp; &amp;nbsp;TRAP will stop polling with no indication that it has failed.&amp;nbsp; &amp;nbsp;The feeds will have green icons indicating feeds are updating, though the logs clearly show no activity.&amp;nbsp; &amp;nbsp;This requires watching and rebooting TRAP.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don 't currently have access to the TRAP box.&amp;nbsp; If I did, I'd share the config.&amp;nbsp; &amp;nbsp;One thing that was more stable was to create an output feed in MineMeld that was a simple HTTP plain text output feed.&amp;nbsp; &amp;nbsp;TRAP appeared to handle that type of a feed with less issues.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Oct 2019 16:42:18 GMT</pubDate>
    <dc:creator>ACMENEWS</dc:creator>
    <dc:date>2019-10-11T16:42:18Z</dc:date>
    <item>
      <title>MineMeld into Proofpoint TRAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-into-proofpoint-trap/m-p/285876#M96461</link>
      <description>&lt;TABLE class="detailList" border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD colspan="3" class="last data2Col"&gt;
&lt;P&gt;I am trying to integrate MineMeld and Proofpoint TRAP. It should be relatively simple and feel I am overlooking something.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;The first step was easy. Create an output using stdlib.taxiiDataFeed.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Because this is the community edition auth is turned off by default. (Leaving this off until things are working)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;In TRAP you have the following fields:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;URL:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://url.to.minemeld.com/taxii-discovery-service" target="_blank" rel="noopener"&gt;https://url.to.minemeld.com/taxii-discovery-service&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Feed:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;Unique_IP_taxiiDataFeed&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;TAXII version:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;TAXII 1.x&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Confidence:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;USE STIX&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Poll Interval:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;Interval Here&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Require Auth:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;Not Checked (For Now)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Select SSL Client Cert:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;None (For Now)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Error: Invalid username or password&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Postman works great after turning off SSL verification.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I even change the URL to &lt;A href="https://url.to.minemeld.com/taxii-poll-service" target="_blank"&gt;https://url.to.minemeld.com/taxii-poll-service&lt;/A&gt; to no avail.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 29 Aug 2019 21:10:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-into-proofpoint-trap/m-p/285876#M96461</guid>
      <dc:creator>Romans6</dc:creator>
      <dc:date>2019-08-29T21:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld into Proofpoint TRAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-into-proofpoint-trap/m-p/292632#M96462</link>
      <description>&lt;P&gt;For what it is worth, it can be made to work.&amp;nbsp; ProofPoint TRAP has a few issues.&amp;nbsp; &amp;nbsp;You will need to build trust on TRAP of the MineMeld root CA (trust the certificate), set TRAP to poll at 1 hour, not 1 minute, or you will periodically consume all RAM within TRAP and then TRAP will fail.&amp;nbsp; &amp;nbsp;TRAP will stop polling with no indication that it has failed.&amp;nbsp; &amp;nbsp;The feeds will have green icons indicating feeds are updating, though the logs clearly show no activity.&amp;nbsp; &amp;nbsp;This requires watching and rebooting TRAP.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don 't currently have access to the TRAP box.&amp;nbsp; If I did, I'd share the config.&amp;nbsp; &amp;nbsp;One thing that was more stable was to create an output feed in MineMeld that was a simple HTTP plain text output feed.&amp;nbsp; &amp;nbsp;TRAP appeared to handle that type of a feed with less issues.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 16:42:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-into-proofpoint-trap/m-p/292632#M96462</guid>
      <dc:creator>ACMENEWS</dc:creator>
      <dc:date>2019-10-11T16:42:18Z</dc:date>
    </item>
  </channel>
</rss>

