<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to export sample miner from minemeld app in autofocus in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-export-sample-miner-from-minemeld-app-in-autofocus/m-p/207744#M97804</link>
    <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a customer who uses Autofocus with Minemeld and, uses splunk.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This customer is using two minemeld. One of Minemeld is from Autofocus app and, another is Standalone Minemeld deployed on Splunk.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but, I found out difference number of miner samples between Autofocus app and Standalone Minemeld.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is number of samples when search keyword "autofocus"&lt;/P&gt;
&lt;P&gt;1. Standalone Minemeld&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="stand.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14501i26773FC5200BE210/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="stand.jpg" alt="stand.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Autofocus app Minemeld&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clould.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14500i5FB92635C36C136D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="clould.jpg" alt="clould.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, Customer wants to export miner samples from Autofocus app and, import samples on Standalone Minemeld.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise to me and will appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Jihoon&lt;/P&gt;</description>
    <pubDate>Wed, 28 Mar 2018 00:43:33 GMT</pubDate>
    <dc:creator>jilim</dc:creator>
    <dc:date>2018-03-28T00:43:33Z</dc:date>
    <item>
      <title>How to export sample miner from minemeld app in autofocus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-export-sample-miner-from-minemeld-app-in-autofocus/m-p/207744#M97804</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a customer who uses Autofocus with Minemeld and, uses splunk.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This customer is using two minemeld. One of Minemeld is from Autofocus app and, another is Standalone Minemeld deployed on Splunk.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but, I found out difference number of miner samples between Autofocus app and Standalone Minemeld.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is number of samples when search keyword "autofocus"&lt;/P&gt;
&lt;P&gt;1. Standalone Minemeld&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="stand.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14501i26773FC5200BE210/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="stand.jpg" alt="stand.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Autofocus app Minemeld&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clould.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14500i5FB92635C36C136D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="clould.jpg" alt="clould.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, Customer wants to export miner samples from Autofocus app and, import samples on Standalone Minemeld.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise to me and will appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Jihoon&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 00:43:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-export-sample-miner-from-minemeld-app-in-autofocus/m-p/207744#M97804</guid>
      <dc:creator>jilim</dc:creator>
      <dc:date>2018-03-28T00:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to export sample miner from minemeld app in autofocus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-export-sample-miner-from-minemeld-app-in-autofocus/m-p/208227#M97805</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75880"&gt;@jilim&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Being able to extract indicators from AutoFocus searches is one of the few features not available in the MineMeld Community edition. Only the AutoFocus hosted MineMeld instance includes a miner capable of it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Said that, there is a special miner named "JSONSeq" that allows a MineMeld-to-MineMeld kind of connection. Using this miner you can "pipe" all indicators from the hosted MineMeld instance to your on-premises MineMeld one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following is a step-by-step guide on how to achieve this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 1: Route your AF samples indicators to a feed output node&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The following screen capture shows a graph in an AutoFocus MineMeld instance routing samples searches to a feed output node.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-47-21.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14568i7CA36FC5F596AF8D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-47-21.png" alt="2018-03-30_08-47-21.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click on the output node to confirm the number of indicators and other details for the feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-49-09.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14569i029D5062459B2EA0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-49-09.png" alt="2018-03-30_08-49-09.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that, by default, all AutoFocus hosted feeds are authenticated (in this case with the tags "active_campaigns" and "test_tag"). This means that you'll need the corresponding user and password for the on-premises MineMeld instance to be able to import indicators from this feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Copy the URL of the feed. You'll need it in the next step.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 2: Create a new JSONSeq miner prototype&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Look in your on-premises MineMeld instance for the JSONSeq standard prototype.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-52-20.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14570iA6D7F97AB93E69E1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-52-20.png" alt="2018-03-30_08-52-20.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click on it an create a new prototype from this base.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-53-00.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14572i8772C2966FB92406/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-53-00.png" alt="2018-03-30_08-53-00.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use, in the new prototype, the URL you captured in the step 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-55-24.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14573iBF44736BE8539C71/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-55-24.png" alt="2018-03-30_08-55-24.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now locate this recently created prototype and clone it to a working node.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-56-30.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14577iA27DDE812475E14C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-56-30.png" alt="2018-03-30_08-56-30.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-57-07.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14578i83F94C7137F5F113/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-57-07.png" alt="2018-03-30_08-57-07.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-57-46.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14579i980F87C2FE781690/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-57-46.png" alt="2018-03-30_08-57-46.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now commit the configuration. And navigate to the "Nodes" tab to realize there is an error in the miner.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_08-59-11.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14580i924DE375C5FFBCA3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_08-59-11.png" alt="2018-03-30_08-59-11.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As said before, AF hosted feeds are, by default, protected with basic authentication. You must provide a valid username and password to the miner so it can successfully grab the indicators. Once you do so, you'll see how the indicators are imported by the on-premises MineMeld instance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_09-00-18.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14581iEFAC6357E96FB01E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_09-00-18.png" alt="2018-03-30_09-00-18.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click on any node's log entry to confirm not only the indicators but the full context is being extracted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-03-30_09-01-04.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14582i9E301676BBA700C6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-03-30_09-01-04.png" alt="2018-03-30_09-01-04.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 07:31:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-export-sample-miner-from-minemeld-app-in-autofocus/m-p/208227#M97805</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-03-30T07:31:19Z</dc:date>
    </item>
  </channel>
</rss>

