<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A few questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175311#M97175</link>
    <description>&lt;P&gt;Afternoon&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Firstly I want to say I really like this product, it has endless possibilities in improving internal security in our environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a few questions I hope you can help me clarify so I understand how to use the product better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using a syslog miner to send syslog TRAFFIC and THREAT data to Mine Meld from my Paloalto firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. &amp;nbsp;When I look on the miner logs I see threats being recorded, then shortly after an hour later I see a 'EMIT_WITHDRAW' log entry. If I look in the feed connected to the miner, I see the IP address in the EMIT_WITHDRAW is removed the the feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you able to explain how this aging process works and how I can keep IP's in the feed longer? I'd like 7 or 30 days instead of an hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Is it possible to have multiple&amp;nbsp;syslog miners for incoming PA events? I'd like to use multiple miners so I can process threat and traffic events seperately. Also I'd like to control confidence of events individually which seems to require seperate miners that can feed into seperate feeds.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps I am approaching this wrong, any advice would be good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;If I trigger a threat type event on my PA, I recieve the threat event in my miner. Also If I redirect the rsyslog to a file, I see that threat info in a file.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However for traffic data, I see it in a syslog redirect file, but I never see traffic data in the miner. I also see no data in the stats/syslog section of the miner&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything specific I need to do to use traffic data?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a basic rule setup for traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;conditions:&lt;BR /&gt; - type == 'TRAFFIC'&lt;BR /&gt;fields:&lt;BR /&gt; - src_ip&lt;BR /&gt;indicators:&lt;BR /&gt; - src_ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any assistance or advice you can provide&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2017 03:52:44 GMT</pubDate>
    <dc:creator>jtrevaskis</dc:creator>
    <dc:date>2017-09-07T03:52:44Z</dc:date>
    <item>
      <title>A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175311#M97175</link>
      <description>&lt;P&gt;Afternoon&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Firstly I want to say I really like this product, it has endless possibilities in improving internal security in our environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a few questions I hope you can help me clarify so I understand how to use the product better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using a syslog miner to send syslog TRAFFIC and THREAT data to Mine Meld from my Paloalto firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. &amp;nbsp;When I look on the miner logs I see threats being recorded, then shortly after an hour later I see a 'EMIT_WITHDRAW' log entry. If I look in the feed connected to the miner, I see the IP address in the EMIT_WITHDRAW is removed the the feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you able to explain how this aging process works and how I can keep IP's in the feed longer? I'd like 7 or 30 days instead of an hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Is it possible to have multiple&amp;nbsp;syslog miners for incoming PA events? I'd like to use multiple miners so I can process threat and traffic events seperately. Also I'd like to control confidence of events individually which seems to require seperate miners that can feed into seperate feeds.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps I am approaching this wrong, any advice would be good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;If I trigger a threat type event on my PA, I recieve the threat event in my miner. Also If I redirect the rsyslog to a file, I see that threat info in a file.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However for traffic data, I see it in a syslog redirect file, but I never see traffic data in the miner. I also see no data in the stats/syslog section of the miner&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything specific I need to do to use traffic data?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a basic rule setup for traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;conditions:&lt;BR /&gt; - type == 'TRAFFIC'&lt;BR /&gt;fields:&lt;BR /&gt; - src_ip&lt;BR /&gt;indicators:&lt;BR /&gt; - src_ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any assistance or advice you can provide&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 03:52:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175311#M97175</guid>
      <dc:creator>jtrevaskis</dc:creator>
      <dc:date>2017-09-07T03:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175343#M97176</link>
      <description>&lt;P&gt;Does your PANOS device run release 8.0? MineMeld 0.9.42 introduced a new miner class (&amp;nbsp;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;minemeld.ft.localdb.Miner&lt;/FONT&gt; ) exposed through the&amp;nbsp;&lt;FONT face="courier new,courier"&gt;stdlib.localDB&lt;/FONT&gt; prototype that can be used to accept indicators from any system that can forward alerts using a RESTful API. And PANOS 8.0 introduced the feature called &lt;A href="https://live.paloaltonetworks.com/t5/HTTP-Log-Forwarding/ct-p/HTTPLogForwarding" target="_self"&gt;HTTP Log Forwarding&lt;/A&gt;&amp;nbsp;that fits into it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This combination provides you with a unique way to bind PANOS devices with MineMeld as explained in the section 5 or the article&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-as-a-Incident-Response-Platform/ta-p/174690" target="_self"&gt;Using MineMeld as a Incident Response Platform&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can use&amp;nbsp;PANOS log forwarding profiles that create JSON documents out of log fileds and send them to MineMeld. This way&amp;nbsp;the source specifies&amp;nbsp;attributes like "ttl" (aging time in seconds), "confidence" and "share_level". A single localDB miner could be used by many log forwarding profiles and honor the aging provided by each of them&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 09:09:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175343#M97176</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-09-07T09:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175548#M97177</link>
      <description>&lt;P&gt;Thanks this seems like a great solution and I do have Palo 8.0.x running&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am getting a 401 unauthorized though when using minemeld admin credentials,&amp;nbsp;is this something I am doing wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[2017-09-08 02:24:04 UTC] [1327] [INFO] AUDIT - {"msg": null, "action": "POST /config/data/testminer_indicators/append", "params": [["value:t", ["localdb"]], ["jsonbody", "{\"tty\": 7200, \"share_level\": \"green\"}"]], "user": "mm-anonymous"}&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;127.0.0.1 - - [08/Sep/2017:02:24:04 +0000] "POST /config/data/testminer_indicators/append?t=localdb HTTP/1.0" 401 12 "-" "-"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11180i67E12649FE00D765/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error.png" alt="error.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 02:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175548#M97177</guid>
      <dc:creator>jtrevaskis</dc:creator>
      <dc:date>2017-09-08T02:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175576#M97178</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54528"&gt;@jtrevaskis&lt;/a&gt;&amp;nbsp;: Yes. I've also experienced this. Looks like an issue in PANOS 8.0. I've already filled a technical support case. In the meanwhile you can use the following workaround:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use&amp;nbsp;&lt;A href="https://www.blitter.se//utils/basic-authentication-header-generator/" target="_self"&gt;https://www.blitter.se//utils/basic-authentication-header-generator/&lt;/A&gt;&amp;nbsp;to generate a value for your basic authentication. In the case of admin/minemeld the value should be&amp;nbsp;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Basic YWRtaW46bWluZW1lbGQ=&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;(including the "Basic ").&lt;/LI&gt;
&lt;LI&gt;Add a new header called "Authorization" with that value in the Payload section&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Picture1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11183i7F18ACD0553810CF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture1.png" alt="Picture1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175576#M97178</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-09-08T07:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175578#M97179</link>
      <description>&lt;P&gt;thanks ill try that and get back to you&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:29:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175578#M97179</guid>
      <dc:creator>jtrevaskis</dc:creator>
      <dc:date>2017-09-08T07:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175624#M97180</link>
      <description>&lt;P&gt;There must be something wrong with my payload, I've played/changed with this 30 times and still get a similar output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The data flows, but just arrives at Mine Meld with additional \" etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestion you can give would be much appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="erro2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11193iB0617C705A4BE210/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="erro2.png" alt="erro2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="erro3.png" style="width: 771px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11192iBC6D27C8D838F43B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="erro3.png" alt="erro3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 12:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175624#M97180</guid>
      <dc:creator>jtrevaskis</dc:creator>
      <dc:date>2017-09-08T12:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175643#M97181</link>
      <description>&lt;P&gt;Humm ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;which browser are you using to access the PANOS device? It looks like your browser is escaping the double quotes you write in the Payload form/textArea.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can give the CLI a try (the content in my example)&lt;/P&gt;
&lt;PRE&gt;admin@PA-VM&amp;gt; configure
Entering configuration mode
[edit]                                                                                                                                                                                
admin@PA-VM# edit shared log-settings http &lt;FONT color="#0000FF"&gt;&lt;EM&gt;minemeld&lt;/EM&gt;&lt;/FONT&gt; format &lt;FONT color="#3366FF"&gt;&lt;EM&gt;wildfire&lt;/EM&gt;&lt;/FONT&gt; 
[edit shared log-settings http minemeld format wildfire]                                                                                                                              
admin@PA-VM# set payload '{"type":"sha256","indicator":"$filedigest","share_level":"green","ttl":3600}'
&lt;/PRE&gt;</description>
      <pubDate>Fri, 08 Sep 2017 13:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175643#M97181</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-09-08T13:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175818#M97182</link>
      <description>&lt;P&gt;I am using Chrome&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not retried JSON format yet, but I will shortly&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got this working with plain text so far&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2017 02:05:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/175818#M97182</guid>
      <dc:creator>jtrevaskis</dc:creator>
      <dc:date>2017-09-11T02:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/176021#M97183</link>
      <description>&lt;P&gt;Thanks again, this is working great as a threat sharing solution for me between PA and OpenDXL&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 01:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/176021#M97183</guid>
      <dc:creator>jtrevaskis</dc:creator>
      <dc:date>2017-09-12T01:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/250625#M97184</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&amp;nbsp;For you case the issue is still present with PAN OS 8.1.6 under Panorama&lt;/P&gt;&lt;P&gt;Works fine with the header "&lt;SPAN&gt;Authorization"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 12:47:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-questions/m-p/250625#M97184</guid>
      <dc:creator>m_matthey</dc:creator>
      <dc:date>2019-02-20T12:47:25Z</dc:date>
    </item>
  </channel>
</rss>

