<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: minemeld and feeding info via CEF into ArcSight in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220569#M98362</link>
    <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can any one help about that&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jul 2018 07:51:07 GMT</pubDate>
    <dc:creator>ahmed_hassan</dc:creator>
    <dc:date>2018-07-05T07:51:07Z</dc:date>
    <item>
      <title>minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/103029#M98347</link>
      <description>&lt;P&gt;Can you select formatting or would I need to create a wrapper that manipulates the data pushed by minemeld to forward in CEF? &amp;nbsp;Glad an opensource community on this exist for this. &amp;nbsp;Additionally I need an rpm based package or just a way to compile from source I am using CentOS any thoughts or is there a source package for this&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 14:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/103029#M98347</guid>
      <dc:creator>socfocus.com</dc:creator>
      <dc:date>2016-08-15T14:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/103595#M98348</link>
      <description>&lt;P&gt;Hi socfocus,&lt;/P&gt;
&lt;P&gt;CEF output node is definitely on my todo list (see ER#39 at&amp;nbsp;&lt;A href="https://github.com/PaloAltoNetworks/minemeld-core/issues/39" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-core/issues/39&lt;/A&gt;). I am looking of a good example on how to translate Threat Intelligence into CEF format, do you have something I could look at ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Installation based on RPM is on the TODO list, shall be quite easy to accomplish.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 20:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/103595#M98348</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-16T20:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/141357#M98349</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/4936"&gt;@socfocus.com&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;starting with 0.9.32 you can use an external extension to achieve this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/minemeld-cef" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-cef&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/141357#M98349</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-02-06T19:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/164569#M98351</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Is minemeld-cef extension support Hash aggregator processors (MD5, SHA256)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does&amp;nbsp;&lt;SPAN&gt;minemeld-cef support all aggegators on minemeld?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 02:12:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/164569#M98351</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2017-07-05T02:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/164759#M98352</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67821"&gt;@iThreatHunt&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;this could be supported by changing the template, but in which CEF field would you put the hash indicator ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 20:21:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/164759#M98352</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-07-05T20:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/164798#M98353</link>
      <description>&lt;P&gt;Could MD5, SHA256 mapping with Device Custom String3?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now Device Custom field is used&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="06-07-2017 10-23-53.jpg" style="width: 245px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10076iE454C03C2B4F9AF1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="06-07-2017 10-23-53.jpg" alt="06-07-2017 10-23-53.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 03:25:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/164798#M98353</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2017-07-06T03:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/165354#M98354</link>
      <description>&lt;P&gt;I found some error when activate mindmeld-cef 0.17b. Pleas advise me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Obtaining file:///opt/minemeld/local/library/7d86cdf2-c97e-4835-a5df-acdad36fd48d&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Complete output from command python setup.py egg_info:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unable to find pgen, not compiling formal grammar.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; warning: no files found matching '*.pyx' under directory 'Cython/Debugger/Tests'&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; warning: no files found matching '*.pxd' under directory 'Cython/Debugger/Tests'&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; warning: no files found matching '*.h' under directory 'Cython/Debugger/Tests'&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; warning: no files found matching '*.pxd' under directory 'Cython/Utility'&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; unable to execute 'x86_64-linux-gnu-gcc': No such file or directory&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Traceback (most recent call last):&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "&amp;lt;string&amp;gt;", line 1, in &amp;lt;module&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/local/library/7d86cdf2-c97e-4835-a5df-acdad36fd48d/setup.py", line 50, in &amp;lt;module&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; entry_points=_entry_points&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/usr/lib/python2.7/distutils/core.py", line 111, in setup&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; _setup_distribution = dist = klass(attrs)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/setuptools/dist.py", line 320, in __init__&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; self.fetch_build_eggs(attrs['setup_requires'])&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/setuptools/dist.py", line 377, in fetch_build_eggs&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; replace_conflicting=True,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/pkg_resources/__init__.py", line 852, in resolve&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dist = best[req.key] = env.best_match(req, ws, installer)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/pkg_resources/__init__.py", line 1124, in best_match&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; return self.obtain(req, installer)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/pkg_resources/__init__.py", line 1136, in obtain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; return installer(requirement)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/setuptools/dist.py", line 445, in fetch_build_egg&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; return cmd.easy_install(req)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/setuptools/command/easy_install.py", line 673, in easy_install&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; return self.install_item(spec, dist.location, tmpdir, deps)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/setuptools/command/easy_install.py", line 699, in install_item&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dists = self.install_eggs(spec, download, tmpdir)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/setuptools/command/easy_install.py", line 880, in install_eggs&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; return self.build_and_install(setup_script, setup_base)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/setuptools/command/easy_install.py", line 1119, in build_and_install&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; self.run_setup(setup_script, setup_base, args)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File "/opt/minemeld/engine/0.9.40/local/lib/python2.7/site-packages/setuptools/command/easy_install.py", line 1107, in run_setup&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; raise DistutilsError("Setup script exited with %s" % (v.args[0],))&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; distutils.errors.DistutilsError: Setup script exited with error: command 'x86_64-linux-gnu-gcc' failed with exit status 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------------------------------------&lt;BR /&gt;Command "python setup.py egg_info" failed with error code 1 in /opt/minemeld/local/library/7d86cdf2-c97e-4835-a5df-acdad36fd48d/&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2017 06:27:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/165354#M98354</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2017-07-08T06:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/165357#M98355</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="08-07-2017 21-23-47.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10255i5CDA3940A108A005/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="08-07-2017 21-23-47.jpg" alt="08-07-2017 21-23-47.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2017 14:26:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/165357#M98355</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2017-07-08T14:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/165732#M98356</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67821"&gt;@iThreatHunt&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;installing minemeld-cef from source requires a compiler, and this is not available by default on MineMeld VMs (security).&lt;/P&gt;
&lt;P&gt;You can instead download the wheel file from here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/minemeld-cef/releases" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-cef/releases&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And upload it to MineMeld via SYSTEM &amp;gt; EXTENSIONS page.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 06:34:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/165732#M98356</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-07-11T06:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/196106#M98357</link>
      <description>&lt;P&gt;is there any CEF output that mine meld generate?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2018 21:50:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/196106#M98357</guid>
      <dc:creator>ahmed_hassan</dc:creator>
      <dc:date>2018-01-21T21:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/196244#M98358</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54912"&gt;@ahmed_hassan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you elaborate a bit your question? CEF is just an interface to encapsulate indicators. MineMeld supports such an interface through an extension which means that you can output anything that your want to a CEF receiver.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 17:50:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/196244#M98358</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-22T17:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220453#M98359</link>
      <description>&lt;P&gt;when sending Hashes using CEF format ,&amp;nbsp;Hash value is not sent to Arcsight.&lt;/P&gt;
&lt;P&gt;so, i view raw data that is sent to Arcsight&amp;nbsp;, i found field that cantain&amp;nbsp;Hash value is empty.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54912"&gt;@ahmed_hassan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you elaborate a bit your question? CEF is just an interface to encapsulate indicators. MineMeld supports such an interface through an extension which means that you can output anything that your want to a CEF receiver.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 03 Jul 2018 21:17:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220453#M98359</guid>
      <dc:creator>ahmed_hassan</dc:creator>
      <dc:date>2018-07-03T21:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220454#M98360</link>
      <description>&lt;P&gt;when sending Hashes using CEF format ,&amp;nbsp;Hash value is not sent to Arcsight.&lt;/P&gt;
&lt;P&gt;so, i view raw data that is sent to Arcsight&amp;nbsp;, i found field that cantain&amp;nbsp;Hash value is empty.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 03 Jul 2018 21:18:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220454#M98360</guid>
      <dc:creator>ahmed_hassan</dc:creator>
      <dc:date>2018-07-03T21:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220462#M98361</link>
      <description>&lt;P&gt;Please find this raw log that is sent to arcsight&amp;nbsp;with out hashvalue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Raw Event: &amp;lt;53&amp;gt;Feb 21 18:48:40 CEF:0|Palo Alto Networks|MineMeld CEF Output|0.1|withdraw|MineMeld IOC|0|deviceFacility=sha256 deviceExternalId=MineMeld deviceProcessName=Malicious_Hash_To_Arcsight cs2Label=Sources cn2Label=NumberOfSources deviceCustomDate1=1519148121391 deviceCustomDate2=1519148121391 deviceCustomDate2Label=LastSeen cs1Label=ShareLevel cn2=1 deviceCustomDate1Label=FirstSeen cn1=100 cn1Label=Confidence cs2=ADIB_Hash_Malware_Miner endTime=1519238920025 cs1=red&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 21:37:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220462#M98361</guid>
      <dc:creator>ahmed_hassan</dc:creator>
      <dc:date>2018-07-03T21:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220569#M98362</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can any one help about that&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 07:51:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/220569#M98362</guid>
      <dc:creator>ahmed_hassan</dc:creator>
      <dc:date>2018-07-05T07:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: minemeld and feeding info via CEF into ArcSight</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/237316#M98364</link>
      <description>Please update minemeld-cef output for supporting hash value (MD5,SHA1,SHA256).</description>
      <pubDate>Fri, 26 Oct 2018 16:19:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-and-feeding-info-via-cef-into-arcsight/m-p/237316#M98364</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2018-10-26T16:19:19Z</dc:date>
    </item>
  </channel>
</rss>

