<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zscaler and Minemeld in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213216#M97932</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using Minemeld &lt;SPAN&gt;0.9.44 and I would&amp;nbsp;&lt;/SPAN&gt;to get 'range' from the URL&amp;nbsp;&lt;A href="https://ips.zscaler.net/cenr/json" target="_blank"&gt;https://ips.zscaler.net/cenr/json&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;After several attempts&amp;nbsp;with JSON prototype, trying to&amp;nbsp;set different&amp;nbsp;extractor, field (indicator set as range).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm still not able to get any information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please let me know what is the best what to extract 'range'?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;BR /&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 May 2018 17:39:59 GMT</pubDate>
    <dc:creator>lvmh_onenetwork</dc:creator>
    <dc:date>2018-05-04T17:39:59Z</dc:date>
    <item>
      <title>Zscaler and Minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213216#M97932</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using Minemeld &lt;SPAN&gt;0.9.44 and I would&amp;nbsp;&lt;/SPAN&gt;to get 'range' from the URL&amp;nbsp;&lt;A href="https://ips.zscaler.net/cenr/json" target="_blank"&gt;https://ips.zscaler.net/cenr/json&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;After several attempts&amp;nbsp;with JSON prototype, trying to&amp;nbsp;set different&amp;nbsp;extractor, field (indicator set as range).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm still not able to get any information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please let me know what is the best what to extract 'range'?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;BR /&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 17:39:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213216#M97932</guid>
      <dc:creator>lvmh_onenetwork</dc:creator>
      <dc:date>2018-05-04T17:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Zscaler and Minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213871#M97933</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46321"&gt;@lvmh_onenetwork&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the following SimpleJSON based prototype works for me&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;age_out:
    default: null
    interval: 257
    sudden_death: true
attributes:
    confidence: 100
    share_level: green
    type: IPv4
extractor: '"zscaler.net".*.*[][]'
indicator: range
prefix: zs
source_name: zscaler
url: https://ips.zscaler.net/cenr/json
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 06:22:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213871#M97933</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-05-10T06:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Zscaler and Minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213962#M97934</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it works perfectly, but i'm not sure to understand the&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;'"zscaler.net".*.*[][]'&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how does it works?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 19:45:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213962#M97934</guid>
      <dc:creator>lvmh_onenetwork</dc:creator>
      <dc:date>2018-05-10T19:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Zscaler and Minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213976#M97935</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46321"&gt;@lvmh_onenetwork&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you familiar with JMESPath expressions? Do you know the site &lt;A href="http://jmespath.org/" target="_self"&gt;http://jmespath.org/&lt;/A&gt; ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I highly recommend you to paste the JSON code from the ZSCALER URL into the JMESPath interactive test site to play with different expressions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, basically,&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;"zscaler.net" selects the root object&lt;/LI&gt;
&lt;LI&gt;.* selects any object inside "zscaler.net" ("continent : Europe", "continent : US &amp;amp; Canada", ...)&lt;/LI&gt;
&lt;LI&gt;.* selects any object insite the continents ("city : Amsterdam", "city : Brussels", ...)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you play in the interactive site you'll realize that "zscaler.net".*.* produces an array of continents containing each one of them an array of rages for each city.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[] is a flatten projection that removes the "city" dimension to achieve all ranges to be direct elements inside each "contient"&lt;/LI&gt;
&lt;LI&gt;the second [] flatten projection removes the "continent" dimension to achieve all ranges being direct elements of the top array.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The result is an array of ranges whose elements can be yielded into the MineMeld engine.&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 21:29:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/213976#M97935</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-05-10T21:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Zscaler and Minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/214008#M97936</link>
      <description>&lt;P&gt;Thank you for the detail.&amp;nbsp; I will&amp;nbsp;study that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 06:32:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zscaler-and-minemeld/m-p/214008#M97936</guid>
      <dc:creator>lvmh_onenetwork</dc:creator>
      <dc:date>2018-05-11T06:32:47Z</dc:date>
    </item>
  </channel>
</rss>

