<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Miner for host file format. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/miner-for-host-file-format/m-p/197279#M97673</link>
    <description>&lt;P&gt;Is there a miner + documentation on how to get it working for a host file list?&lt;/P&gt;
&lt;P&gt;i.e.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts" target="_blank"&gt;https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This tool was recommended by Palo Alto for a project we are working on, howver the documentation on how to actually use it is hard to understand.&lt;A id="fprsl" class="spell" href="https://www.google.com.au/search?client=firefox-b&amp;amp;dcr=0&amp;amp;q=actually&amp;amp;spell=1&amp;amp;sa=X&amp;amp;ved=0ahUKEwiD0cTy8_vYAhVEfbwKHSBMCnoQkeECCCQoAA&amp;amp;biw=2347&amp;amp;bih=854" data-ved="0ahUKEwiD0cTy8_vYAhVEfbwKHSBMCnoQkeECCCQoAA" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2018 00:24:02 GMT</pubDate>
    <dc:creator>DatacomNetadmin</dc:creator>
    <dc:date>2018-01-29T00:24:02Z</dc:date>
    <item>
      <title>Miner for host file format.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/miner-for-host-file-format/m-p/197279#M97673</link>
      <description>&lt;P&gt;Is there a miner + documentation on how to get it working for a host file list?&lt;/P&gt;
&lt;P&gt;i.e.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts" target="_blank"&gt;https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This tool was recommended by Palo Alto for a project we are working on, howver the documentation on how to actually use it is hard to understand.&lt;A id="fprsl" class="spell" href="https://www.google.com.au/search?client=firefox-b&amp;amp;dcr=0&amp;amp;q=actually&amp;amp;spell=1&amp;amp;sa=X&amp;amp;ved=0ahUKEwiD0cTy8_vYAhVEfbwKHSBMCnoQkeECCCQoAA&amp;amp;biw=2347&amp;amp;bih=854" data-ved="0ahUKEwiD0cTy8_vYAhVEfbwKHSBMCnoQkeECCCQoAA" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 00:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/miner-for-host-file-format/m-p/197279#M97673</guid>
      <dc:creator>DatacomNetadmin</dc:creator>
      <dc:date>2018-01-29T00:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Miner for host file format.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/miner-for-host-file-format/m-p/197316#M97674</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72888"&gt;@DatacomNetadmin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use the generic HttpFT class miner for such a lists published through HTTP/S. The following are the steps to mine the list at &lt;A href="https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts" target="_self"&gt;https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;A- Create a new prototype for StevenBlack's list&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Locate in the configuration any prototype using the HttpFT class. For instance the "auscert.1day_dumpsites" one.&lt;/LI&gt;
&lt;LI&gt;Click on "new" to create a new prototype and name it "StevenBlack" (or anything else that suits you)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-29_08-44-55.png" style="width: 300px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13450i9E009574E582865F/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="2018-01-29_08-44-55.png" alt="2018-01-29_08-44-55.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Replace the configuration of the new prototype with this one:&lt;BR /&gt;
&lt;PRE&gt;age_out:
    default: null
    interval: 3600
    sudden_death: true
attributes:
    confidence: 100
    direction: inbound
    interval: 3600
    share_level: green
    type: domain
ignore_regex: ^#
indicator:
    regex: ^0\.0\.0\.0[\s\t](.*\.[a-z]{2,})$
    transform: \1
source_name: StevenBlack
url: https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts&lt;/PRE&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;B- Clone the just created prototype into a working node.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Just locate the new prototype in the configuration and use the "Clone" option.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-29_08-49-36.png" style="width: 300px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13451i85EB01AA4F8CB876/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="2018-01-29_08-49-36.png" alt="2018-01-29_08-49-36.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 07:50:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/miner-for-host-file-format/m-p/197316#M97674</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-29T07:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Miner for host file format.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/miner-for-host-file-format/m-p/197520#M97675</link>
      <description>&lt;P&gt;Hi xhoms,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can&amp;nbsp; see where I got my miner wrong.&lt;/P&gt;
&lt;P&gt;I had the wrong indicator type (URL), I changed it to domain and changed the aggergator to suit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have it working now using the stdlib.aggregatorDomain aggregator and the stdlib.feedHCGreen protype for the output.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Again, much appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DaveC&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 02:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/miner-for-host-file-format/m-p/197520#M97675</guid>
      <dc:creator>DatacomNetadmin</dc:creator>
      <dc:date>2018-01-30T02:07:06Z</dc:date>
    </item>
  </channel>
</rss>

