<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: configure airgapped miner for on premise minemeld in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/re-configure-airgapped-miner-for-on-premise-minemeld/m-p/229334#M98267</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;we recently setup a minemeld server meant for a airgapped environment and we are trying to figure out how to setup a airgapped miner with the other information found here on customizing a miner.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-Create-a-Custom-Miner/ta-p/227694" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-Create-a-Custom-Miner/ta-p/227694&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there any available article for a requirement to a airgapped setup for the miner as well as if the miner must use https/http to access the intell feeds or any other format eg:scp/ssh/smb will do?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2018 05:16:58 GMT</pubDate>
    <dc:creator>Gerard_Ng</dc:creator>
    <dc:date>2018-09-04T05:16:58Z</dc:date>
    <item>
      <title>Re: configure airgapped miner for on premise minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-configure-airgapped-miner-for-on-premise-minemeld/m-p/229334#M98267</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;we recently setup a minemeld server meant for a airgapped environment and we are trying to figure out how to setup a airgapped miner with the other information found here on customizing a miner.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-Create-a-Custom-Miner/ta-p/227694" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-Create-a-Custom-Miner/ta-p/227694&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there any available article for a requirement to a airgapped setup for the miner as well as if the miner must use https/http to access the intell feeds or any other format eg:scp/ssh/smb will do?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 05:16:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-configure-airgapped-miner-for-on-premise-minemeld/m-p/229334#M98267</guid>
      <dc:creator>Gerard_Ng</dc:creator>
      <dc:date>2018-09-04T05:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: configure airgapped miner for on premise minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-configure-airgapped-miner-for-on-premise-minemeld/m-p/229370#M98268</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90901"&gt;@Gerard_Ng&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unfortunately there isn't any "generic miner" capable of extracting indicators from local files (or network mounted files).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Option 1 is to code a new miner (either contributing to minemeld-core or creating a minemeld extension)&lt;/P&gt;
&lt;P&gt;Option 2 is to use the "LocalDB" miner and push local indicators to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to explore Option 2 then I'd recoment to take a look at the article &lt;A title=" Using MineMeld as an Incident Response Platform" href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-as-an-Incident-Response-Platform/ta-p/174690" target="_self"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-as-an-Incident-Response-Platform/ta-p/174690&lt;/A&gt; and to take a closer look to its Annex 2 where the API for the LocalDB Miner is explained. You could also leverage the &lt;A href="https://gist.github.com/jtschichold/95f3906566b18b50cf2e3e1a44f1e785" target="_self"&gt;minemeld-sync.py script&lt;/A&gt; created by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt; that allows you to sync the LocalDB stored indicators with the ones present on a given local file.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 10:14:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-configure-airgapped-miner-for-on-premise-minemeld/m-p/229370#M98268</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-09-04T10:14:16Z</dc:date>
    </item>
  </channel>
</rss>

