<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MineMeld - need help importing and processing syslog data in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/272150#M96690</link>
    <description>&lt;P&gt;Did you have any progress here? I'm at the same point wondering if I need to create own .rb file and place it before or after the 60-... rb file. How does it decide which template to use?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2019 13:25:22 GMT</pubDate>
    <dc:creator>DaniBCS</dc:creator>
    <dc:date>2019-06-21T13:25:22Z</dc:date>
    <item>
      <title>MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/101312#M96682</link>
      <description>&lt;P&gt;I installed the MineMeld VM on my ESXi box yesterday and it came up just fine, I can login to it from the VM Console, the web console, and over SSH.&amp;nbsp; I've edited the /etc/rsyslog.conf file and /etc/iptables/rules.v4 so that syslog data is coming in from the firewall to the /var/log/syslog file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question: How do I get MineMeld to process the syslog data? I looked at the "Using the sysloig Miner"&amp;nbsp; article and have created a miner (stdlib.syslogMiner) and linked it to the inboundaggregator but, it isn't processing anything.&amp;nbsp; I'm sure I'm missing something rather simple - can somebody point me in the right direction?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 15:42:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/101312#M96682</guid>
      <dc:creator>jerryshenk</dc:creator>
      <dc:date>2016-08-05T15:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/103594#M96683</link>
      <description>&lt;P&gt;Hi jerryshenk,&lt;/P&gt;
&lt;P&gt;do you have a file named&amp;nbsp;/etc/rsyslog.d/60-syslog-minemeld.conf in your instance ?&lt;/P&gt;
&lt;P&gt;This should instruct rsyslog to parse syslog messages on port 13514/tcp into JSON using PAN-OS rulebase and push them to RabbitMQ on a queue MineMeld should listen to.&lt;/P&gt;
&lt;P&gt;This seems complex, but it is just a short config file. Could you check ?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 20:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/103594#M96683</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-16T20:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181548#M96684</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;
&lt;P&gt;I've got pretty much the same "problem" as jerryshenk.&lt;/P&gt;
&lt;P&gt;I checked for the file mentioned (60-syslog-minemeld.conf). But it does not exist in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;/etc/rsyslog.d/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can i get the file/settings from somewhere?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks alot&lt;/P&gt;
&lt;P&gt;Andreas&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 17:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181548#M96684</guid>
      <dc:creator>AndreasTrautmann</dc:creator>
      <dc:date>2017-10-12T17:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181776#M96685</link>
      <description>&lt;P&gt;Update: &lt;BR /&gt;OK, I found the file in the apt package, extracted it and put it to /etc/rsyslog.d/ together with &amp;nbsp;palo_alto_networks.rb.&lt;/P&gt;
&lt;P&gt;But still no Indicators in my syslog-miner.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Syslog is arriving at the minemeld server, ufw is opened.&lt;/P&gt;
&lt;P&gt;Do I need a "syslog miner rule" for it to start collecting indicators?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any Ideas how I can further troubleshoot this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Context Infos:&lt;BR /&gt;Installation on Ubuntu 16.04&lt;/P&gt;
&lt;P&gt;Installed via ansible playbook&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks, best Regards&lt;/P&gt;
&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 15:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181776#M96685</guid>
      <dc:creator>AndreasTrautmann</dc:creator>
      <dc:date>2017-10-13T15:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181801#M96686</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/696"&gt;@AndreasTrautmann&lt;/a&gt;: I'm quite new at this myself but yes, after you have syslog showing up in statistics &amp;gt;&amp;nbsp;&lt;EM&gt;SYSLOG.PROCESSED&lt;/EM&gt;, the next step is to&amp;nbsp;create some rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this thread helpful:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 17:11:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181801#M96686</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-10-13T17:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181803#M96687</link>
      <description>&lt;P&gt;Hi Luca&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the hint.&lt;/P&gt;
&lt;P&gt;Unfortunately my miner does not yet receive anything (SYSLOG.PROCESSED is 0).&lt;/P&gt;
&lt;P&gt;So my problem is further "up" somewhere in the "link" between rsyslogd and the miner.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;BR /&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 17:15:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181803#M96687</guid>
      <dc:creator>AndreasTrautmann</dc:creator>
      <dc:date>2017-10-13T17:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181814#M96688</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/696"&gt;@AndreasTrautmann&lt;/a&gt;:&amp;nbsp; Got you. Definitely the SYSLOG.PROCESSED counter starts moving even with zero rules present on the node itself, so that's what needs fixing first (as you already pointed out).&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 18:12:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/181814#M96688</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-10-13T18:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/207145#M96689</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;Hi jerryshenk,&lt;/P&gt;&lt;P&gt;do you have a file named&amp;nbsp;/etc/rsyslog.d/60-syslog-minemeld.conf in your instance ?&lt;/P&gt;&lt;P&gt;This should instruct rsyslog to parse syslog messages on port 13514/tcp into JSON using PAN-OS rulebase and push them to RabbitMQ on a queue MineMeld should listen to.&lt;/P&gt;&lt;P&gt;This seems complex, but it is just a short config file. Could you check ?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Is&amp;nbsp; "/etc/rsyslog.d/palo_alto_networks.rb" the only rulebase file? Can I modify another rulebase that can make the minemeld to integrate with any other products syslogs such as any AV, FW or IPS? Do you have any instruction for creating a "rb" file? Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 15:00:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/207145#M96689</guid>
      <dc:creator>HAO.BAN</dc:creator>
      <dc:date>2018-03-23T15:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/272150#M96690</link>
      <description>&lt;P&gt;Did you have any progress here? I'm at the same point wondering if I need to create own .rb file and place it before or after the 60-... rb file. How does it decide which template to use?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 13:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/272150#M96690</guid>
      <dc:creator>DaniBCS</dc:creator>
      <dc:date>2019-06-21T13:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/285069#M96691</link>
      <description>&lt;P&gt;What version of PanOS are you using? I've been troubleshooting the same issue. We turned on debugging for rsyslogd and it's logging error messages while parsing the palo's syslog. It looks like the threat log format changed between 8.0.X and 8.1.X. I'm thinking that the config given to rsyslogd doesn't know how to handle the 8.1.X format?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can see the format differences between these two links:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/threat-log-fields.html" target="_self"&gt;8.0.x Format&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/threat-log-fields.html" target="_self"&gt;8.1.x Format&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 15:44:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/285069#M96691</guid>
      <dc:creator>mboehlke</dc:creator>
      <dc:date>2019-08-26T15:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld - need help importing and processing syslog data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/285220#M96692</link>
      <description>&lt;P&gt;Well , I'm up to making it ingest non-PA syslog. The end goal is to have it ingest all sorts of logs and make aggregators which do conclusions based on multiple sources and prep inputs for others in the network.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 08:02:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-need-help-importing-and-processing-syslog-data/m-p/285220#M96692</guid>
      <dc:creator>DaniBCS</dc:creator>
      <dc:date>2019-08-27T08:02:10Z</dc:date>
    </item>
  </channel>
</rss>

