<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LogRhythm Threat Intelligence Service crashes MineMeld TAXII in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127543#M96864</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51715"&gt;@kmerolla﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the log you see are normal, by default the minemeld-web service runs with DEBUG log level and those are just DEBUG logs.&lt;/P&gt;
&lt;P&gt;Would you mind sharing&amp;nbsp;the output of POSTMAN Discovery and Collection management requests ?&lt;/P&gt;
&lt;P&gt;You can share them here, or unicast them to my email lmori@paloaltonetworks.com.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
    <pubDate>Fri, 18 Nov 2016 21:25:47 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2016-11-18T21:25:47Z</dc:date>
    <item>
      <title>LogRhythm Threat Intelligence Service crashes MineMeld TAXII</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127541#M96863</link>
      <description>&lt;P&gt;I have a LogRhythm Appliance and the Threat Intelligence service is able to register my TAXII datafeed. &amp;nbsp;However when I try and donwload the feed, the minemeld web server crashes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The feed also crashes using PostMan ... same thing, rabbitmq crashes and restarts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;127.0.0.1 - - [18/Nov/2016:20:53:55 +0000] "POST /taxii-poll-service HTTP/1.0" 200 582 "-" "-"&lt;BR /&gt;DEBUG:amqp:Start from server, version: 0.9, properties: {u'information': u'Licensed under the MPL. See &lt;A href="http://www.rabbitmq.com/" target="_blank"&gt;http://www.rabbitmq.com/&lt;/A&gt;', u'product': u'RabbitMQ', u'copyright': u'Copyright (C) 20 07-2013 GoPivotal, Inc.', u'capabilities': {u'exchange_exchange_bindings': True, u'connection. blocked': True, u'authentication_failure_close': True, u'basic.nack': True, u'consumer_priorit ies': True, u'consumer_cancel_notify': True, u'publisher_confirms': True}, u'platform': u'Erla ng/OTP', u'version': u'3.2.4'}, mechanisms: [u'AMQPLAIN', u'PLAIN'], locales: [u'en_US']&lt;BR /&gt;DEBUG:amqp:Open OK!&lt;BR /&gt;DEBUG:amqp:using channel_id: 1&lt;BR /&gt;DEBUG:amqp:Channel open&lt;BR /&gt;DEBUG:amqp:Start from server, version: 0.9, properties: {u'information': u'Licensed under the MPL. See &lt;A href="http://www.rabbitmq.com/" target="_blank"&gt;http://www.rabbitmq.com/&lt;/A&gt;', u'product': u'RabbitMQ', u'copyright': u'Copyright (C) 20 07-2013 GoPivotal, Inc.', u'capabilities': {u'exchange_exchange_bindings': True, u'connection. blocked': True, u'authentication_failure_close': True, u'basic.nack': True, u'consumer_priorit ies': True, u'consumer_cancel_notify': True, u'publisher_confirms': True}, u'platform': u'Erla ng/OTP', u'version': u'3.2.4'}, mechanisms: [u'AMQPLAIN', u'PLAIN'], locales: [u'en_US']&lt;BR /&gt;DEBUG:amqp:Open OK!&lt;BR /&gt;DEBUG:minemeld.comm.amqp:sending {'reply_to': u'amq.gen-CtlcZUWQMrN1HZ6f_6Yfqw', 'params': {}, 'method': 'status', 'id': '23bc7e8a-add1-11e6-a79d-000d3a153a4f'} to mbus:master:rpc&lt;BR /&gt;DEBUG:minemeld.comm.amqp:start draining events on connection 0&lt;BR /&gt;DEBUG:minemeld.comm.amqp:start draining events on connection None&lt;BR /&gt;DEBUG:amqp:Closed channel #1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the STIXX service is configured by a yml file ... the MineMeld section looks like this (IPs removed):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"StixProviders": [&lt;BR /&gt; {&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"NumofBackDaysData": 7,&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"SourceURL": "https://&amp;lt;minemeld server&amp;gt;/taxii-collection-management-service",&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"UserName": "",&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"Password": "",&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"LastFullDownloadOn": null,&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"ProviderName": "MineMeld",&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"Enabled": true,&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"Retired": false,&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"StixFeedTypes": [&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "Name": "blacklist_taxiiDataFeed",&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "Enabled": true,&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "FeedPollAddress": "https://&amp;lt;minemeld server&amp;gt;/taxii-poll-service"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;}&lt;BR /&gt; ],&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any assistance is greatly appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Kevin&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 21:10:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127541#M96863</guid>
      <dc:creator>kmerolla</dc:creator>
      <dc:date>2016-11-18T21:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: LogRhythm Threat Intelligence Service crashes MineMeld TAXII</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127543#M96864</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51715"&gt;@kmerolla﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the log you see are normal, by default the minemeld-web service runs with DEBUG log level and those are just DEBUG logs.&lt;/P&gt;
&lt;P&gt;Would you mind sharing&amp;nbsp;the output of POSTMAN Discovery and Collection management requests ?&lt;/P&gt;
&lt;P&gt;You can share them here, or unicast them to my email lmori@paloaltonetworks.com.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 21:25:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127543#M96864</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-18T21:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: LogRhythm Threat Intelligence Service crashes MineMeld TAXII</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127554#M96865</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Postman Collection Information Request:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;lt;taxii_11:Collection_Information_Response xmlns:taxii="&lt;A href="http://taxii.mitre.org/messages/taxii_xml_binding-1" target="_blank"&gt;http://taxii.mitre.org/messages/taxii_xml_binding-1&lt;/A&gt;" xmlns:taxii_11="&lt;A href="http://taxii.mitre.org/messages/taxii_xml_binding-1.1" target="_blank"&gt;http://taxii.mitre.org/messages/taxii_xml_binding-1.1&lt;/A&gt;" xmlns:tdq="&lt;A href="http://taxii.mitre.org/query/taxii_default_query-1" target="_blank"&gt;http://taxii.mitre.org/query/taxii_default_query-1&lt;/A&gt;" message_id="3446523018790861401" in_response_to="26300"&amp;gt;&lt;BR /&gt; &amp;lt;taxii_11:Collection collection_name="blacklist_taxiiDataFeed" collection_type="DATA_FEED" available="true"&amp;gt;&lt;BR /&gt; &amp;lt;taxii_11:Description&amp;gt;blacklist_taxiiDataFeed Data Feed&amp;lt;/taxii_11:Description&amp;gt;&lt;BR /&gt; &amp;lt;taxii_11:Content_Binding binding_id="urn:stix.mitre.org:xml:1.1.1"/&amp;gt;&lt;BR /&gt; &amp;lt;taxii_11:Polling_Service&amp;gt;&lt;BR /&gt; &amp;lt;taxii_11:Protocol_Binding&amp;gt;urn:taxii.mitre.org:protocol:http:1.0&amp;lt;/taxii_11:Protocol_Binding&amp;gt;&lt;BR /&gt; &amp;lt;taxii_11:Address&amp;gt;https://&amp;lt;&amp;lt;host&amp;gt;&amp;gt;/taxii-poll-service&amp;lt;/taxii_11:Address&amp;gt;&lt;BR /&gt; &amp;lt;taxii_11:Message_Binding&amp;gt;urn:taxii.mitre.org:message:xml:1.1&amp;lt;/taxii_11:Message_Binding&amp;gt;&lt;BR /&gt; &amp;lt;/taxii_11:Polling_Service&amp;gt;&lt;BR /&gt; &amp;lt;/taxii_11:Collection&amp;gt;&lt;BR /&gt;&amp;lt;/taxii_11:Collection_Information_Response&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Postman Poll Request (spins for 5 minutes before crashing)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 22:34:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127554#M96865</guid>
      <dc:creator>kmerolla</dc:creator>
      <dc:date>2016-11-18T22:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: LogRhythm Threat Intelligence Service crashes MineMeld TAXII</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127643#M96866</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51715"&gt;@kmerolla﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;an issue could be the number of indicators stored in the feed. If LogRythm is asking for all of them at once, the resulting response&amp;nbsp;could be too big to be handled. How many indicators do you have in the feed ?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2016 13:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/127643#M96866</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-19T13:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: LogRhythm Threat Intelligence Service crashes MineMeld TAXII</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/152355#M96867</link>
      <description>&lt;P&gt;Is this still a concern or has it been addressed?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 17:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/152355#M96867</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2017-04-12T17:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: LogRhythm Threat Intelligence Service crashes MineMeld TAXII</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/260932#M96868</link>
      <description>&lt;P&gt;We are also planning to bring Minemeld threat intel into our SIEM LogRhythm. Is anyone doing that is kind enough to share how they set it up and if it is proving valuable?&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 15:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logrhythm-threat-intelligence-service-crashes-minemeld-taxii/m-p/260932#M96868</guid>
      <dc:creator>LeeSeeman</dc:creator>
      <dc:date>2019-05-14T15:26:49Z</dc:date>
    </item>
  </channel>
</rss>

