<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP addresses disappearing from miner in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/217037#M98032</link>
    <description>&lt;P&gt;With the stdlib.localDB miner what is the default age out setting? I do not see it in the config. Is it possible to adjust the default age out for indicators that do not come in with a ttl? &lt;/P&gt;</description>
    <pubDate>Thu, 07 Jun 2018 17:34:58 GMT</pubDate>
    <dc:creator>RodneyBeaudry</dc:creator>
    <dc:date>2018-06-07T17:34:58Z</dc:date>
    <item>
      <title>IP addresses disappearing from miner</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188686#M98026</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've created a miner to add IP address based on stdlib.listIPv4Generic and class minemeld.ft.local.YamlIPv4FT. Default configuration (just cloned).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This week, some IP addresses just disappeared from this miner.&lt;/P&gt;
&lt;P&gt;We added an IP address to the miner last 21st, on the 22&lt;SUP&gt;nd&lt;/SUP&gt; of this month the IP address disappeared from the miner. Older indicators were not removed from the miner.&lt;/P&gt;
&lt;P&gt;When I checked the logs, I found a EMIT_WITHDRAW event:&lt;/P&gt;
&lt;P&gt;{&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "comment": " Win32.Conficker.Cp2p",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "_age_out": 1511357349093,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "confidence": 100,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "_withdrawn": 1511357349181,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "direction": "inbound",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "share_level": "red",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "_last_run": 1511278036128,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "sources": [&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "feed_IPv4"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ],&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "first_seen": 1511277006844,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "type": "IPv4",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "last_seen": 1511277006844&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the EMIT_UPDATE event for this indicator:&lt;/P&gt;
&lt;P&gt;{&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "comment": "Win32.Conficker.Cp2p",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "_age_out": 4294967295000,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "confidence": 100,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "direction": "inbound",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "share_level": "red",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "_last_run": 1511277006844,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "sources": [&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "feed_IPv4"&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;],&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "first_seen": 1511277006844,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "type": "IPv4",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "last_seen": 1511277006844&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is another&amp;nbsp; IP address that had the same issue:&lt;/P&gt;
&lt;P&gt;{&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "comment": "North Korean Trojan: Volgmer",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "_age_out": 1511181387647,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;"confidence": 100,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "_withdrawn": 1511181387873,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "share_level": "red",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "_last_run": 1511027230747,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "sources": [&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "feed_IPv4"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ],&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "first_seen": 1510845540625,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "type": "IPv4",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "last_seen": 1510845540625&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Apparently, 200 IPv4 were removed from this miner and I can’t understand why. As I mentioned, older indicators were not removed from the miner.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please help?&lt;/P&gt;
&lt;P&gt;I am attaching here all events involved in one indicator that went away from the miner.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 14:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188686#M98026</guid>
      <dc:creator>alyssonalmeida</dc:creator>
      <dc:date>2017-11-25T14:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: IP addresses disappearing from miner</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188687#M98027</link>
      <description>&lt;P&gt;I understand now what happened. It is a bug in MineMeld (in my opinion)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let’s say you have two users connected to MineMeld.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first user opens one miner to add an indicator to it. At the same time, a second user opens the same miner. So, they are listing the same indicators.&lt;/P&gt;
&lt;P&gt;Now, let’s say that the first user adds an indicator to the miner, but the second user doest refresh the page and adds an indicator just after the first user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It happens that MineMeld will withdraw the first indicator added by the first user because the browser of the last user (second user) didn’t list that first indicator.&lt;/P&gt;
&lt;P&gt;I did the test here and I could reproduce this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, I guess someone in my company left MineMeld opened and didn’t refresh the browser before adding indicators to MineMeld. &amp;nbsp;We lost 200 indicators because of that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Can someone from MineMeld team confirm that this is a bug?&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 15:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188687#M98027</guid>
      <dc:creator>alyssonalmeida</dc:creator>
      <dc:date>2017-11-25T15:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: IP addresses disappearing from miner</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188695#M98028</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71533"&gt;@alyssonalmeida&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;yes, it's a limitation/bug for the local Miner - something we are phasing out. There is already a new version of the local Miner called "stdlib.localDB" Miner where this limitation has been removed, with additional features (TTL per indicator) and improved API and scalability. My suggestion is to switch from the old local Miner to the new one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 16:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188695#M98028</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-11-25T16:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: IP addresses disappearing from miner</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188698#M98029</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any easy way to export the indicators from the old miner to the new one?&lt;/P&gt;
&lt;P&gt;Trying to save time here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to import a CSV into the miner?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 18:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188698#M98029</guid>
      <dc:creator>alyssonalmeida</dc:creator>
      <dc:date>2017-11-25T18:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: IP addresses disappearing from miner</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188699#M98030</link>
      <description>&lt;P&gt;I found this and I think that will be useful&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/MineMeldArticles/article-id/151" target="_blank"&gt;https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/MineMeldArticles/article-id/151&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 18:53:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/188699#M98030</guid>
      <dc:creator>alyssonalmeida</dc:creator>
      <dc:date>2017-11-25T18:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: IP addresses disappearing from miner</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/193049#M98031</link>
      <description>&lt;P&gt;Yes, that's exactly the best way.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2017 07:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/193049#M98031</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-12-26T07:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: IP addresses disappearing from miner</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/217037#M98032</link>
      <description>&lt;P&gt;With the stdlib.localDB miner what is the default age out setting? I do not see it in the config. Is it possible to adjust the default age out for indicators that do not come in with a ttl? &lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 17:34:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/217037#M98032</guid>
      <dc:creator>RodneyBeaudry</dc:creator>
      <dc:date>2018-06-07T17:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: IP addresses disappearing from miner</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/217106#M98033</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82082"&gt;@RodneyBeaudry&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it defaults to 1800.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/minemeld-core/blob/a94fa48a3d842f50e40d18d5fe88fd3be9ce1f66/minemeld/ft/localdb.py#L47" target="_self"&gt;https://github.com/PaloAltoNetworks/minemeld-core/minemeld/ft/localdb.py#L47&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 21:37:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-addresses-disappearing-from-miner/m-p/217106#M98033</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-06-07T21:37:39Z</dc:date>
    </item>
  </channel>
</rss>

