<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MS-ISAC Soltra Feed? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/197995#M97681</link>
    <description>&lt;P&gt;Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am also trying to integrate with MS-ISAC. Can you provide instructions for customizing a TAXII client prototype to access this? Unfortunately I am having issues figuring out how to authenticate via minemeld to the TAXII feed. Please advise,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jan 2018 18:55:29 GMT</pubDate>
    <dc:creator>ENCITAdmins</dc:creator>
    <dc:date>2018-01-31T18:55:29Z</dc:date>
    <item>
      <title>MS-ISAC Soltra Feed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/155846#M97676</link>
      <description>&lt;P&gt;Through MS-ISAC we are able to consume a Taxii feed (I believe it originates as a Soltra Edge feed).&amp;nbsp; Currently this is going straight into my palo as an EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to&amp;nbsp;bring it in&amp;nbsp;through minemeld so I can add other feeds and take advantage of the other features in MineMeld.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I look at prototypes for Miners, I don't see any that refer to MS-ISAC.&amp;nbsp; How might I go about adding this as a miner?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 20:56:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/155846#M97676</guid>
      <dc:creator>kevink</dc:creator>
      <dc:date>2017-05-09T20:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: MS-ISAC Soltra Feed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/155875#M97677</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34431"&gt;@kevink&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;MS-ISAC is supported. You have to customize a TAXII Client prototype to access MS-ISAC. Let me find the instructions for you.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 22:50:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/155875#M97677</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-05-09T22:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: MS-ISAC Soltra Feed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/155911#M97678</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;My customer also would like to take advantage of the FS-ISAC data source. Could you tell me the instructions please?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 06:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/155911#M97678</guid>
      <dc:creator>tasano</dc:creator>
      <dc:date>2017-05-10T06:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: MS-ISAC Soltra Feed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/156021#M97679</link>
      <description>&lt;P&gt;Kevin, I've done this before with MS-ISAC and it can absolutely be done. &amp;nbsp;One thing to note though is that MS-ISAC recently moved from Soltra Edge to utilizing Anomali. &amp;nbsp;They also just recently enabled the TAXII feeds on the Anomali side. &amp;nbsp;I am working on doing discovery and integration now to get that operational. &amp;nbsp;Basically it breaks down into a couple of steps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. &amp;nbsp;Clone an existing TAXII prototype (hailataxii is the easiest) and input the necessary components (taxii-discovery-service, feed, etc).&lt;/P&gt;
&lt;P&gt;2. &amp;nbsp;Make sure that your initial load looks back at least 7 days if not longer to make sure you get some data. &amp;nbsp;It is important to note that the feed starts the moment you start the node, there isn't anything rearward looking unless you configure it as such.&lt;/P&gt;
&lt;P&gt;3. &amp;nbsp;Create the miner/node associated with the prototype and put in your authentication credentials here. &amp;nbsp;You can do it in the prototype as well, but it really isn't necessary.&lt;/P&gt;
&lt;P&gt;4. &amp;nbsp;Utilize your miner/node in the feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Things to point out are to make sure that you are using the correct discovery service URL and that your credentials are correct. &amp;nbsp;It will take a little time to pull in and parse the data. &amp;nbsp;Be patient, if you have authenticated appropriately you should have little issue. &amp;nbsp;When in doubt utilize the CLI test commands on your VM in order to make sure it's going.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 18:33:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/156021#M97679</guid>
      <dc:creator>tschlottog</dc:creator>
      <dc:date>2017-05-10T18:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: MS-ISAC Soltra Feed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/197995#M97681</link>
      <description>&lt;P&gt;Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am also trying to integrate with MS-ISAC. Can you provide instructions for customizing a TAXII client prototype to access this? Unfortunately I am having issues figuring out how to authenticate via minemeld to the TAXII feed. Please advise,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 18:55:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-isac-soltra-feed/m-p/197995#M97681</guid>
      <dc:creator>ENCITAdmins</dc:creator>
      <dc:date>2018-01-31T18:55:29Z</dc:date>
    </item>
  </channel>
</rss>

