<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Processor nodes put IPv4 addresses in order and in new ranges? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197386#M97671</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78845"&gt;@michael.gabriel&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is what indicator attributes are for. The Alien Vault miner attaches the following valuable attributes to each indicator:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;alienvault_reliability&lt;/LI&gt;
&lt;LI&gt;alienvault_risk and&lt;/LI&gt;
&lt;LI&gt;alienvault_type&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create multiple output nodes attached to the same source selecting only the indicators that match a given input filter criteria. For instance, the following graph splits the current +65K indicator list provided by Alien Vault based on the alienvault_risk attribute value.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-29_15-18-59.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13459iBC3D3E3A127EF3D7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-01-29_15-18-59.png" alt="2018-01-29_15-18-59.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see, there are only around 500 indicators with risk 4. You might combine the indicators with risk 4 and 5 into a general availability "critical EDL" and only consume the rest in high-end devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example of node prototype to filter Alien Vault indicators based on its risk value.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-29_15-19-51.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13461iED140EB5BB717866/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-01-29_15-19-51.png" alt="2018-01-29_15-19-51.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2018 14:28:24 GMT</pubDate>
    <dc:creator>xhoms</dc:creator>
    <dc:date>2018-01-29T14:28:24Z</dc:date>
    <item>
      <title>Can Processor nodes put IPv4 addresses in order and in new ranges?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/196927#M97666</link>
      <description>&lt;P&gt;I find myself wanting processor or output nodes to aggregate IPv4 addresses into new ranges and in order. Since some Palo boxes have a limitation of 50K addresses in a Dynamic List Object, it would help a lot to make my outputs fit in there. Especially since I find myself in front of an output that looks like this in some parts:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;108.62.56.100-108.62.56.100
108.62.56.101-108.62.56.101
108.62.56.102-108.62.56.102
108.62.56.103-108.62.56.103
108.62.56.104-108.62.56.104
108.62.56.105-108.62.56.105
108.62.56.106-108.62.56.106
108.62.56.107-108.62.56.107
108.62.56.108-108.62.56.108
108.62.56.109-108.62.56.109&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It could easily read 108.62.56.100-108.62.56.109... Any way to do this?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 20:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/196927#M97666</guid>
      <dc:creator>michael.gabriel</dc:creator>
      <dc:date>2018-01-25T20:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can Processor nodes put IPv4 addresses in order and in new ranges?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/196946#M97667</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78845"&gt;@michael.gabriel&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;current MineMeld implementation can't do that. And I have some concerns about such agrupation. For instance, what the confidence level should be for the agrupated range? The average of the confidence level of its individual contributors?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What about splitting the list based on attribute values? By confidence? By source? etc. This way you could feed the low end devices with a subset of indicators (the most important ones) and the big end devices with the full list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 21:47:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/196946#M97667</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-25T21:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Can Processor nodes put IPv4 addresses in order and in new ranges?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197080#M97668</link>
      <description>&lt;P&gt;Thanks for the insight&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&amp;nbsp;! You make a very valid point, and ultimately I want to do exactly that, but what is a little bit dissapointing for me is that some miners have an average of up to 60K entries... Let's say I was aiming at one of those miners to be an important one? What do I do with the target PAN-OS (only PAN-OS within a PA-5000 series and 7000 series can accept more than 50K IP's, going up to 150K) ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 13:35:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197080#M97668</guid>
      <dc:creator>michael.gabriel</dc:creator>
      <dc:date>2018-01-26T13:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can Processor nodes put IPv4 addresses in order and in new ranges?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197310#M97669</link>
      <description>&lt;P&gt;Can you share with me the config of the Miner that is producing 60K entries?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 06:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197310#M97669</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-29T06:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can Processor nodes put IPv4 addresses in order and in new ranges?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197369#M97670</link>
      <description>&lt;P&gt;It's the default alienvault.reputation miner. I don't even know yet if I want to use it, rather than asking myself if it is useful for a miner to have as many entries.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 13:40:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197369#M97670</guid>
      <dc:creator>michael.gabriel</dc:creator>
      <dc:date>2018-01-29T13:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can Processor nodes put IPv4 addresses in order and in new ranges?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197386#M97671</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78845"&gt;@michael.gabriel&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is what indicator attributes are for. The Alien Vault miner attaches the following valuable attributes to each indicator:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;alienvault_reliability&lt;/LI&gt;
&lt;LI&gt;alienvault_risk and&lt;/LI&gt;
&lt;LI&gt;alienvault_type&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create multiple output nodes attached to the same source selecting only the indicators that match a given input filter criteria. For instance, the following graph splits the current +65K indicator list provided by Alien Vault based on the alienvault_risk attribute value.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-29_15-18-59.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13459iBC3D3E3A127EF3D7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-01-29_15-18-59.png" alt="2018-01-29_15-18-59.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see, there are only around 500 indicators with risk 4. You might combine the indicators with risk 4 and 5 into a general availability "critical EDL" and only consume the rest in high-end devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example of node prototype to filter Alien Vault indicators based on its risk value.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-29_15-19-51.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13461iED140EB5BB717866/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-01-29_15-19-51.png" alt="2018-01-29_15-19-51.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 14:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197386#M97671</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-29T14:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can Processor nodes put IPv4 addresses in order and in new ranges?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197407#M97672</link>
      <description>&lt;P&gt;Super interesting! I had completely overlooked this while reading documentation, thank you very much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&amp;nbsp;!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 14:43:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-processor-nodes-put-ipv4-addresses-in-order-and-in-new/m-p/197407#M97672</guid>
      <dc:creator>michael.gabriel</dc:creator>
      <dc:date>2018-01-29T14:43:41Z</dc:date>
    </item>
  </channel>
</rss>

