<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TAXII into QRadar in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120131#M98197</link>
    <description>&lt;P&gt;It looks like I'm on 0.9.24:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;$ ls -l /opt/minemeld/engine/current&lt;BR /&gt;lrwxrwxrwx 1 root root 27 Sep 30 02:20 /opt/minemeld/engine/current -&amp;gt; /opt/minemeld/engine/0.9.24&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2016 11:45:04 GMT</pubDate>
    <dc:creator>DanWoodruff</dc:creator>
    <dc:date>2016-10-19T11:45:04Z</dc:date>
    <item>
      <title>TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/119075#M98192</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Is there any guidance for how to set up TAXII output for QRadar to ingest? I see in the latest release notes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- &lt;SPAN class="lia-search-match-lithium"&gt;TAXII&lt;/SPAN&gt; DataFeed now translated IP Ranges into CIDR for better compatibility with 3rd party &lt;SPAN class="lia-search-match-lithium"&gt;TAXII&lt;/SPAN&gt; clients (read IBM QRadar)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I figure it must be possible &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; but when I put the discover service URL into the Threat Intelligence app (https://&amp;lt;hostname&amp;gt;/taxii-discovery-service) I get a very generic error of:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;STRONG&gt;&lt;/STRONG&gt;There is a problem connecting to the TAXII server. Please check your connection information and verify that the TAXII server is available"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In MineMeld I've setup an output node of type stdlib.taxiiDataFeed with an input of one of the aggregators. I'm&amp;nbsp;trying to figure out how to get more detailed error logs from QRadar in the mean time...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;
&lt;P&gt;Dan&lt;/P&gt;
&lt;DIV class="row" data-reactid=".1.1.0.0.$=11:0.1.0.0.0.0.1"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 13 Oct 2016 12:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/119075#M98192</guid>
      <dc:creator>DanWoodruff</dc:creator>
      <dc:date>2016-10-13T12:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/119631#M98193</link>
      <description>&lt;P&gt;Hi Dan,&lt;/P&gt;
&lt;P&gt;is the certificate on MineMeld signed by a known CA ? QRadar verifies the certificate and drops the connection if the cert is not valid. I haven't found a flag to disable it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luigi&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2016 19:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/119631#M98193</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-10-17T19:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/119657#M98194</link>
      <description>&lt;P&gt;Hi Luigi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's a valid cert but I think it might have been installed without the full chain. I plan to give that a try soon. Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2016 20:35:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/119657#M98194</guid>
      <dc:creator>DanWoodruff</dc:creator>
      <dc:date>2016-10-17T20:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120049#M98195</link>
      <description>&lt;P&gt;Hi Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found the error logs in QRadar and then got further by adding the root and intermediates to the cert file. However, now I'm getting a different error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2016-10-19 00:10:23,184 [com.ibm.ThreatIntelligence] [INFO] - Sending Discovery request to https://&amp;lt;hostname&amp;gt;/taxii-discovery-service&lt;BR /&gt;2016-10-19 00:10:23,214 [com.ibm.ThreatIntelligence] [INFO] - Sending Collection Information Request to https://&amp;lt;hostname&amp;gt;/taxii-collection-management-service&lt;BR /&gt;2016-10-19 00:10:23,250 [com.ibm.ThreatIntelligence] [ERROR] - Failed to get list of collections from https://&amp;lt;hostname&amp;gt;/taxii-discovery-service; '@available'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Minemeld, the only setup I did was to create an output miner of type&amp;nbsp;stdlib.taxiiDataFeed and then make sure it had some inputs. Is there any other setup I need to do?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI, I'm on QRadar 7.2.7 and 1.0.2 of the Threat Intelligence app, if that's of any use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 00:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120049#M98195</guid>
      <dc:creator>DanWoodruff</dc:creator>
      <dc:date>2016-10-19T00:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120060#M98196</link>
      <description>&lt;P&gt;Hi Dan,&lt;/P&gt;
&lt;P&gt;which MineMeld version are you running ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 04:10:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120060#M98196</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-10-19T04:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120131#M98197</link>
      <description>&lt;P&gt;It looks like I'm on 0.9.24:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;$ ls -l /opt/minemeld/engine/current&lt;BR /&gt;lrwxrwxrwx 1 root root 27 Sep 30 02:20 /opt/minemeld/engine/current -&amp;gt; /opt/minemeld/engine/0.9.24&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 11:45:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120131#M98197</guid>
      <dc:creator>DanWoodruff</dc:creator>
      <dc:date>2016-10-19T11:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120169#M98198</link>
      <description>&lt;P&gt;Dan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try MISP, and use the export to feed the Qradar reference sets. The Taxi engine on the qradar app store doesnt work that great...&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 19:02:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120169#M98198</guid>
      <dc:creator>SSattler</dc:creator>
      <dc:date>2016-10-19T19:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120187#M98199</link>
      <description>&lt;P&gt;In MineMeld 0.9.24 we have introduced some changes to improve compatibility with IBM QRadar, and they do interoperate.&lt;/P&gt;
&lt;P&gt;One way to check the TAXII output from MineMeld is using Postman and this collection of requests:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://gist.github.com/jtschichold/65ee13d29038f78e220d75e6668eeea1" target="_blank"&gt;https://gist.github.com/jtschichold/65ee13d29038f78e220d75e6668eeea1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you send the Collection Information Request you should see the list of available feeds. Could you check the list is not empty ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 21:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120187#M98199</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-10-19T21:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120251#M98200</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49021"&gt;@SSattler﻿&lt;/a&gt;&amp;nbsp;thanks for the idea. MISP is on my list of things to play with. I was shooting for a quick win with the Threat Intelligence app though!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Luigi and I determined that the error was caused by having only one TAXII output miner in MineMeld. As soon as we added more than one, QRadar picked them all up.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 13:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120251#M98200</guid>
      <dc:creator>DanWoodruff</dc:creator>
      <dc:date>2016-10-20T13:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120281#M98201</link>
      <description>&lt;P&gt;MISP is a great platform, I am planning a Miner and Output node for it.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 14:43:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/120281#M98201</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-10-20T14:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: TAXII into QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/224720#M98202</link>
      <description>&lt;P&gt;Hi Dan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just follow the below steps:&lt;/P&gt;&lt;P&gt;Login to qradar using root and execute the below command&lt;/P&gt;&lt;P&gt;Step 1&lt;/P&gt;&lt;P&gt;1.&lt;SPAN&gt;/opt/&lt;/SPAN&gt;&lt;SPAN&gt;qradar&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;support&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;qapp_utils&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;py ls&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Step 2:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note down the app id of threat intelligence.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;step 3:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Connect the app container using the below command&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="page"&gt;&lt;DIV class="section"&gt;&lt;DIV class="layoutArea"&gt;&lt;DIV class="column"&gt;&lt;P&gt;&lt;SPAN&gt;#/&lt;/SPAN&gt;&lt;SPAN&gt;opt&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;qradar&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;support&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;qapp_utils&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;py connect &lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;app_id&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Step 4:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Add the host entry of the certficate name with the IP and try to wget to the&amp;nbsp; url which you have added .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Step 5:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Go to the TAXII plugin and while adding the taxii url give the name which you have configured inside the container and try.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;it should work. Actually i tried and its working for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;BR /&gt;Ramprasath&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23156"&gt;@DanWoodruff&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Luigi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a valid cert but I think it might have been installed without the full chain. I plan to give that a try soon. Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23156"&gt;@DanWoodruff&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Luigi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a valid cert but I think it might have been installed without the full chain. I plan to give that a try soon. Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 03 Aug 2018 12:10:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/taxii-into-qradar/m-p/224720#M98202</guid>
      <dc:creator>Nocturnalknight</dc:creator>
      <dc:date>2018-08-03T12:10:16Z</dc:date>
    </item>
  </channel>
</rss>

