<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MineMeld Splunk App in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/180770#M97984</link>
    <description>&lt;P&gt;I found this page while looking at some Splunk/MineMeld integration post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find here&lt;BR /&gt;&lt;A href="https://scubarda.wordpress.com/category/threat-intelligence/" target="_blank"&gt;https://scubarda.wordpress.com/category/threat-intelligence/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some note:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;on post 1 I show the architecture&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;on post 2 I show how-to write a custom prototype and the IoC integration with our SOC Splunk application. This is the fully automated near real&amp;nbsp;feature&amp;nbsp;we are using today to check IoC&amp;nbsp;access.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;on post 3 I show how-to create a STIX/TAXII output miner to export IoC&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;on post 4 I show how I integrated IoC events (updates/withdraw) into Splunk; to do this I wrote a TA to parse coming data (via logstash connector) and an app to show some stats (both on github).&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope this is useful&lt;BR /&gt;Giovanni&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2017 07:35:23 GMT</pubDate>
    <dc:creator>soc_enav</dc:creator>
    <dc:date>2017-10-09T07:35:23Z</dc:date>
    <item>
      <title>MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/140160#M97976</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm new to this community. At the moment, we are actively exploring MineMeld in our environment and would like to know if there is any&amp;nbsp;connectors available for Splunk to consume intel collected by MineMeld .&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 00:29:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/140160#M97976</guid>
      <dc:creator>ammaleswaran</dc:creator>
      <dc:date>2017-01-31T00:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/140956#M97977</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My name is Brian Torres-Gil and my team owns&amp;nbsp;the Splunk integration at Palo Alto Networks. &amp;nbsp;A Minemeld-Splunk integration is in the works, and&amp;nbsp;I'd love to hear any use cases you have so we can ensure they're handled by the integration. &amp;nbsp;Please tell me what you'd like to see from a Splunk integration with Minemeld and any problems you'd solve with it. &amp;nbsp;This will really help us with the final design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-Brian&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 16:59:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/140956#M97977</guid>
      <dc:creator>btorresgil</dc:creator>
      <dc:date>2017-02-03T16:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/142873#M97978</link>
      <description>&lt;P&gt;We will provide MineMeld as a Service for our PAN Firewall customers. Therefore it would be nice to see a graphical presentation of the currently connected Firewalls and to which feeds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Roland&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 10:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/142873#M97978</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2017-02-14T10:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/143128#M97979</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5885"&gt;@gafrol&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;this would be a nice feature to have inside MineMeld. With the current release&amp;nbsp;if you are already using Splunk or a system able to process syslog logs to create a dashboard, you can configure nginx on MineMeld to forward logs to an external syslog server. Using the nginx logs you can visualize and track firewalls connecting to the different feeds.&lt;/P&gt;
&lt;P&gt;Details: &lt;A href="https://nginx.org/en/docs/syslog.html" target="_self"&gt;https://nginx.org/en/docs/syslog.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 10:03:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/143128#M97979</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-02-15T10:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/149688#M97980</link>
      <description>&lt;P&gt;I would also be interested in using the minemeld app to ingest the node logs into Splunk, so that Splunk could have knowledge of the additions, updates, withdrawls, etc. occuring for each indicator.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 17:36:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/149688#M97980</guid>
      <dc:creator>mboehlke</dc:creator>
      <dc:date>2017-03-27T17:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/150099#M97981</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/57393"&gt;@mboehlke&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;are&amp;nbsp;you interested in sending indicators updates/withdraws to Splunk ? Or using the MineMeld feeds as lookup tables inside Splunk ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 09:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/150099#M97981</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-03-29T09:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/150103#M97982</link>
      <description>&lt;P&gt;I was primarily interested in sending the updates/withdraws to Splunk. There's some hesitation to implementing dynamic block lists everywhere on our network and being able to audit the lists through a utility everyone is familiar with would&amp;nbsp;do a lot to help assuage that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had been looking at just putting a forwarder on the minemeld instance, but the log files I found that appear to contain the logs read in by the MineMeld UI don't exclusively&amp;nbsp;contain text? It looks like there's some binary data in there as well?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 11:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/150103#M97982</guid>
      <dc:creator>mboehlke</dc:creator>
      <dc:date>2017-03-29T11:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/150383#M97983</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/57393"&gt;@mboehlke&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;there are 2 things you could now for this:&lt;/P&gt;
&lt;P&gt;1 - use the logstash output node to push indicators to LogStash and then configure logstash to forward the messages to Splunk. An open point here is the best format to be used on LogStash to push indicators to Splunk.&lt;/P&gt;
&lt;P&gt;2 - use the &lt;A href="https://github.com/PaloAltoNetworks/minemeld-cef" target="_self"&gt;minemeld-cef&lt;/A&gt; extension to generate messages in CEF format. My understanding is that Splunk can understand CEF&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 12:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/150383#M97983</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-03-30T12:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/180770#M97984</link>
      <description>&lt;P&gt;I found this page while looking at some Splunk/MineMeld integration post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find here&lt;BR /&gt;&lt;A href="https://scubarda.wordpress.com/category/threat-intelligence/" target="_blank"&gt;https://scubarda.wordpress.com/category/threat-intelligence/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some note:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;on post 1 I show the architecture&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;on post 2 I show how-to write a custom prototype and the IoC integration with our SOC Splunk application. This is the fully automated near real&amp;nbsp;feature&amp;nbsp;we are using today to check IoC&amp;nbsp;access.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;on post 3 I show how-to create a STIX/TAXII output miner to export IoC&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;on post 4 I show how I integrated IoC events (updates/withdraw) into Splunk; to do this I wrote a TA to parse coming data (via logstash connector) and an app to show some stats (both on github).&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope this is useful&lt;BR /&gt;Giovanni&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 07:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/180770#M97984</guid>
      <dc:creator>soc_enav</dc:creator>
      <dc:date>2017-10-09T07:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/215999#M97985</link>
      <description>&lt;P&gt;Hi! I know I'm late to the party but I'd also like to monitor node updates coming from MM to Splunk, and I'm having trouble finding the right queries to do so.. propably due to the fact that we are very unknowledgeable concerning Splunk here hahahha.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our 7.1 Splunk instance is connected to some MM outputs, and I can correctly find the indicators by using the&amp;nbsp; &lt;STRONG&gt;| `mm_indicators`&lt;/STRONG&gt; search or&amp;nbsp;&lt;STRONG&gt;| from inputlookup:"minemeldfeeds_lookup"&amp;nbsp;&lt;/STRONG&gt;. What I need to do is compare last month's feeds to this month's feeds and return all the new indicators that have appeared in the last 30 days. All this is utlimately to compare to NGFW security policy hits within the last month to know if the new indicators have been hit or not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully someone here could help us with this, maybe&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15566"&gt;@btorresgil&lt;/a&gt;&amp;nbsp;or&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 20:19:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/215999#M97985</guid>
      <dc:creator>michael.gabriel</dc:creator>
      <dc:date>2018-05-30T20:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/216327#M97986</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78845"&gt;@michael.gabriel&lt;/a&gt; The Splunk App/Add-on doesn't track indicators over time by default.&amp;nbsp; The indicators are fed into a KVStore lookup table, which is a database, so it does not natively have a time-component like the main Splunk index does.&amp;nbsp; You can easily create a scheduled search in Splunk that simply indexes the minemeld indicator lookup table every day.&amp;nbsp; Then you can see how the indicators change over time.&amp;nbsp; Would that suggestion work for you?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-Brian&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 18:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/216327#M97986</guid>
      <dc:creator>btorresgil</dc:creator>
      <dc:date>2018-06-01T18:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld Splunk App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/216330#M97987</link>
      <description>&lt;P&gt;Thank you so much for the quick reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15566"&gt;@btorresgil&lt;/a&gt;. I believe that is exactly what I should be doing, if you have the time/patience to do so, could you briefly explain the steps to me please?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 18:23:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-splunk-app/m-p/216330#M97987</guid>
      <dc:creator>michael.gabriel</dc:creator>
      <dc:date>2018-06-01T18:23:55Z</dc:date>
    </item>
  </channel>
</rss>

