<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Minemeld diminishing numbers when passing from miner to processor. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-diminishing-numbers-when-passing-from-miner-to/m-p/244669#M97194</link>
    <description>&lt;P&gt;Which aggregator are you using?&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jan 2019 07:47:37 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2019-01-02T07:47:37Z</dc:date>
    <item>
      <title>Minemeld diminishing numbers when passing from miner to processor.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-diminishing-numbers-when-passing-from-miner-to/m-p/244600#M97193</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to integrate Recorded Future IP risk list with our SIEM to do correlation after that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have set up correctly the miner, which gives us around 50k indicators.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We then proceed to&amp;nbsp; pass it to the processor stdlib.aggregatorIPv4Generic, which just process 20k indicators.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finall we convert it to CEF format with the output cef.testCEF than at the same time just process around 8k indicator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked the logs and some of the IPs jsut don't seem to never being grabbed by the processor as they don't show up on it's logs, but the do show up on the logs of the miner, same thing happens when it's parsing from processor to CEF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to grab those 50k indicators and when that is working going more indepth as how we can filters indicators that might be more interesting to us (higher confidence, etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just as an indication this is the first time we are pulling information from this API and we currently don't have more feeds applied on Minemeld.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is happening and why are we receiving so few numbers?&amp;nbsp; Are we doing something wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using the latest version of Minemeld and the prototypes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Sat, 29 Dec 2018 00:45:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-diminishing-numbers-when-passing-from-miner-to/m-p/244600#M97193</guid>
      <dc:creator>userlevel1</dc:creator>
      <dc:date>2018-12-29T00:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld diminishing numbers when passing from miner to processor.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-diminishing-numbers-when-passing-from-miner-to/m-p/244669#M97194</link>
      <description>&lt;P&gt;Which aggregator are you using?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2019 07:47:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-diminishing-numbers-when-passing-from-miner-to/m-p/244669#M97194</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2019-01-02T07:47:37Z</dc:date>
    </item>
  </channel>
</rss>

