<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Minemeld PA syslog processing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-pa-syslog-processing/m-p/190862#M97582</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I installed Minemeld. I'm now trying to mine the PA traffic logs via syslog. It seems that the processing works but no indicators are extracted? The PA is running 7.1.13 and sending the syslog messages on TCP port 13514 to the Minemeld server.&lt;BR /&gt;I already looked into the /var/log/rsyslog.log file but I do not see any messages. How can I troubleshoot this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Tnx&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12918i1575D65C494AC2B1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Dec 2017 16:08:04 GMT</pubDate>
    <dc:creator>jorisVD</dc:creator>
    <dc:date>2017-12-08T16:08:04Z</dc:date>
    <item>
      <title>Minemeld PA syslog processing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-pa-syslog-processing/m-p/190862#M97582</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I installed Minemeld. I'm now trying to mine the PA traffic logs via syslog. It seems that the processing works but no indicators are extracted? The PA is running 7.1.13 and sending the syslog messages on TCP port 13514 to the Minemeld server.&lt;BR /&gt;I already looked into the /var/log/rsyslog.log file but I do not see any messages. How can I troubleshoot this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Tnx&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12918i1575D65C494AC2B1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 16:08:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-pa-syslog-processing/m-p/190862#M97582</guid>
      <dc:creator>jorisVD</dc:creator>
      <dc:date>2017-12-08T16:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld PA syslog processing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-pa-syslog-processing/m-p/193054#M97583</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/851"&gt;@jorisVD&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;please, could you attach a screenshot of your indicators extracting rules?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2017 07:51:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-pa-syslog-processing/m-p/193054#M97583</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-12-26T07:51:59Z</dc:date>
    </item>
  </channel>
</rss>

