<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TAXII or STIX contextual data in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-or-stix-contextual-data/m-p/263779#M96783</link>
    <description>&lt;P&gt;Is anyone able to assist me with how I might proceed on this?&lt;/P&gt;</description>
    <pubDate>Fri, 31 May 2019 03:46:55 GMT</pubDate>
    <dc:creator>jtrevaskis</dc:creator>
    <dc:date>2019-05-31T03:46:55Z</dc:date>
    <item>
      <title>TAXII or STIX contextual data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-or-stix-contextual-data/m-p/261721#M96782</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've succcessfuly been using Minemeld for some time now and I'm looking to further implement it&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We currently have TAXII output working to our SIEM, however it just outputs basic data&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;stix:Indicators&amp;gt;&lt;BR /&gt;&amp;lt;stix:Indicator id="minemeld:indicator-fec078bf-881f-4c89-96d1-7138468b2954" timestamp="2019-05-20T22:10:27.149987+00:00" xsi:type="indicator:IndicatorType"&amp;gt;&lt;BR /&gt;&amp;lt;indicator:Title&amp;gt;IPv4: x.x.x.x-x.x.x.x0&amp;lt;/indicator:Title&amp;gt;&lt;BR /&gt;&amp;lt;indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1"&amp;gt;IP Watchlist&amp;lt;/indicator:Type&amp;gt;&lt;BR /&gt;&amp;lt;indicator:Description&amp;gt;IPv4 indicator from mhn_hc&amp;lt;/indicator:Description&amp;gt;&lt;BR /&gt;&amp;lt;indicator:Observable id="minemeld:observable-d13e4a30-2b57-4299-b7c8-2f7eef59fc75"&amp;gt;&lt;BR /&gt;&amp;lt;cybox:Title&amp;gt;IPv4: x.x.x.x&amp;lt;/cybox:Title&amp;gt;&lt;BR /&gt;&amp;lt;cybox:Object id="minemeld:Address-3f43d4be-098c-43db-ba67-41b44b41d146"&amp;gt;&lt;BR /&gt;&amp;lt;cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr"&amp;gt;&lt;BR /&gt;&amp;lt;AddressObj:Address_Value&amp;gt;x.x.x.x&amp;lt;/AddressObj:Address_Value&amp;gt;&lt;BR /&gt;&amp;lt;/cybox:Properties&amp;gt;&lt;BR /&gt;&amp;lt;/cybox:Object&amp;gt;&lt;BR /&gt;&amp;lt;/indicator:Observable&amp;gt;&lt;BR /&gt;&amp;lt;indicator:Confidence timestamp="2019-05-20T22:10:27.150074+00:00"&amp;gt;&lt;BR /&gt;&amp;lt;stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0"&amp;gt;High&amp;lt;/stixCommon:Value&amp;gt;&lt;BR /&gt;&amp;lt;/indicator:Confidence&amp;gt;&lt;BR /&gt;&amp;lt;/stix:Indicator&amp;gt;&lt;BR /&gt;&amp;lt;/stix:Indicators&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However in the Minemeld taxi data feed logs I see all of this great contextual information that I send into Minemeld from various sources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I get all this or some of this additional contextual information that sits in the VALUE field to appear in my STIX object?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will give me many more possibilities on how I can use this data within the SIEM&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 04:22:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-or-stix-contextual-data/m-p/261721#M96782</guid>
      <dc:creator>jtrevaskis</dc:creator>
      <dc:date>2019-05-21T04:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII or STIX contextual data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-or-stix-contextual-data/m-p/263779#M96783</link>
      <description>&lt;P&gt;Is anyone able to assist me with how I might proceed on this?&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 03:46:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-or-stix-contextual-data/m-p/263779#M96783</guid>
      <dc:creator>jtrevaskis</dc:creator>
      <dc:date>2019-05-31T03:46:55Z</dc:date>
    </item>
  </channel>
</rss>

