<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: JSON Parsing - ProofPoint in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/198283#M98384</link>
    <description>&lt;P&gt;For any one interested here is a working config provided by xhoms&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="works.JPG" style="width: 497px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13601i35F4117F82B19E50/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="works.JPG" alt="works.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Feb 2018 17:17:18 GMT</pubDate>
    <dc:creator>jt1025</dc:creator>
    <dc:date>2018-02-01T17:17:18Z</dc:date>
    <item>
      <title>JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197675#M98376</link>
      <description>&lt;P&gt;Has anyone been able to get ProofPoint TAP logs into MineMeld?&amp;nbsp; I think the issue I'm having is with my JSON configuration.&amp;nbsp; Here's what I have so far but it's not pulling any indicators.&amp;nbsp; I've tested my query on&amp;nbsp;&lt;A href="http://jmespath.org/" target="_blank"&gt;http://jmespath.org/&lt;/A&gt; with sucessful results.&amp;nbsp; The field I'm trying to extract is the URL in the threat field - &lt;SPAN&gt;badsite.zz in the example below&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="json.JPG" style="width: 493px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13515iBDE76E4C878371B5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="json.JPG" alt="json.JPG" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sample Log:&lt;/P&gt;
&lt;P&gt;{&lt;/P&gt;
&lt;P&gt;"messagesDelivered":[&lt;BR /&gt; {&lt;BR /&gt; "GUID":"c26dbea0-80d5-463b-b93c-4e8b708219ce",&lt;BR /&gt; "QID":"r2FNwRHF004109",&lt;BR /&gt; "ccAddresses":[&lt;BR /&gt; "bruce.wayne@university-of-education.zz"&lt;BR /&gt; ],&lt;BR /&gt; "clusterId":"pharmtech_hosted",&lt;BR /&gt; "completelyRewritten":"true",&lt;BR /&gt; "fromAddress":"badguy@evil.zz",&lt;BR /&gt; "headerCC":"\"Bruce Wayne\" &amp;lt;bruce.wayne@university-of-education.zz&amp;gt;",&lt;BR /&gt; "headerFrom":"\"A. Badguy\" &amp;lt;badguy@evil.zz&amp;gt;",&lt;BR /&gt; "headerReplyTo":null,&lt;BR /&gt; "headerTo":"\"Clark Kent\" &amp;lt;clark.kent@pharmtech.zz&amp;gt;; \"Diana Prince\" &amp;lt;diana.prince@pharmtech.zz&amp;gt;",&lt;BR /&gt; "impostorScore":0,&lt;BR /&gt; "malwareScore":100,&lt;BR /&gt; "messageID":"20160624211145.62086.mail@evil.zz",&lt;BR /&gt; "messageParts":[&lt;BR /&gt; {&lt;BR /&gt; "contentType":"text/plain",&lt;BR /&gt; "disposition":"inline",&lt;BR /&gt; "filename":"text.txt",&lt;BR /&gt; "md5":"008c5926ca861023c1d2a36653fd88e2",&lt;BR /&gt; "oContentType":"text/plain",&lt;BR /&gt; "sandboxStatus":"unsupported",&lt;BR /&gt; "sha256":"85738f8f9a7f1b04b5329c590ebcb9e425925c6d0984089c43a022de4f19c281"&lt;BR /&gt; },&lt;BR /&gt; {&lt;BR /&gt; "contentType":"application/pdf",&lt;BR /&gt; "disposition":"attached",&lt;BR /&gt; "filename":"Invoice for Pharmtech.pdf",&lt;BR /&gt; "md5":"5873c7d37608e0d49bcaa6f32b6c731f",&lt;BR /&gt; "oContentType":"application/pdf",&lt;BR /&gt; "sandboxStatus":"threat",&lt;BR /&gt; "sha256":"2fab740f143fc1aa4c1cd0146d334c5593b1428f6d062b2c406e5efe8abe95ca"&lt;BR /&gt; }&lt;BR /&gt; ],&lt;BR /&gt; "messageTime":"2016-06-24T21:18:38.000Z",&lt;BR /&gt; "modulesRun":[&lt;BR /&gt; "pdr",&lt;BR /&gt; "sandbox",&lt;BR /&gt; "spam",&lt;BR /&gt; "urldefense"&lt;BR /&gt; ],&lt;BR /&gt; "phishScore":46,&lt;BR /&gt; "policyRoutes":[&lt;BR /&gt; "default_inbound",&lt;BR /&gt; "executives"&lt;BR /&gt; ],&lt;BR /&gt; "quarantineFolder":"Attachment Defense",&lt;BR /&gt; "quarantineRule":"module.sandbox.threat",&lt;BR /&gt; "recipient":[&lt;BR /&gt; "clark.kent@pharmtech.zz",&lt;BR /&gt; "diana.prince@pharmtech.zz"&lt;BR /&gt; ],&lt;BR /&gt; "replyToAddress":null,&lt;BR /&gt; "sender":"e99d7ed5580193f36a51f597bc2c0210@evil.zz",&lt;BR /&gt; "senderIP":"192.0.2.255",&lt;BR /&gt; "spamScore":4,&lt;BR /&gt; "subject":"Please find a totally safe invoice attached.",&lt;BR /&gt; "threatsInfoMap":[&lt;BR /&gt; {&lt;BR /&gt; "campaignId":"46e01b8a-c899-404d-bcd9-189bb393d1a7",&lt;BR /&gt; "classification":"MALWARE",&lt;BR /&gt; "threat":"badsite.zz",&lt;BR /&gt; "threatId":"3ba97fc852c66a7ba761450edfdfb9f4ffab74715b591294f78b5e37a76481aa",&lt;BR /&gt; "threatTime":"2016-06-24T21:18:07.000Z",&lt;BR /&gt; "threatType":"URL",&lt;BR /&gt; "threatUrl":"&lt;A href="https://threatinsight.proofpoint.com/#/73aa0499-dfc8-75eb-1de8-a471b24a2e75/threat/u/3ba97fc852c66a7ba761450edfdfb9f4ffab74715b591294f78b5e37a76481aa" target="_blank"&gt;https://threatinsight.proofpoint.com/#/73aa0499-dfc8-75eb-1de8-a471b24a2e75/threat/u/3ba97fc852c66a7ba761450edfdfb9f4ffab74715b591294f78b5e37a76481aa&lt;/A&gt;"&lt;BR /&gt; }&lt;BR /&gt; ],&lt;BR /&gt; "toAddresses":[&lt;BR /&gt; "clark.kent@pharmtech.zz",&lt;BR /&gt; "diana.prince@pharmtech.zz"&lt;BR /&gt; ]&lt;BR /&gt; },&lt;BR /&gt; "xmailer":"Spambot v2.5"&lt;BR /&gt; ],&lt;BR /&gt; "queryEndTime":"2016-06-24T21:36:00Z"&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;]&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 13:39:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197675#M98376</guid>
      <dc:creator>jt1025</dc:creator>
      <dc:date>2018-01-31T13:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197769#M98377</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64643"&gt;@jt1025&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you, please, check example log? The one that you have copied is an invalid JSON document.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As "messagesDelivered" proterty is a list of objects, its second item should be '&lt;EM&gt;&lt;STRONG&gt;{&lt;/STRONG&gt;"xmailer":"Spambot v2.5"&lt;STRONG&gt;}&lt;/STRONG&gt;&lt;/EM&gt;' instead of '&lt;EM&gt;"xmailer":"Spambot v2.5"&lt;/EM&gt;'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;JSON miner will produce unpredictible results for non-valid JSON documents&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Xavi&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 06:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197769#M98377</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-31T06:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197873#M98378</link>
      <description>&lt;P&gt;Thanks xhoms.&amp;nbsp; You are correct.&amp;nbsp; The sample log I provided was incorrect.&amp;nbsp; Here is a sanitized log I pulled directly from the API which I believe is correctly formatted.&amp;nbsp; I've also tried&amp;nbsp;&lt;SPAN&gt;messagesDelivered[*].threatsInfoMap[*] for the extractor.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;{&lt;BR /&gt; "queryEndTime": "2018-01-29T18:57:00Z",&lt;BR /&gt; "messagesDelivered": [&lt;BR /&gt; {&lt;BR /&gt; "spamScore": 4,&lt;BR /&gt; "phishScore": 46,&lt;BR /&gt; "threatsInfoMap": [&lt;BR /&gt; {&lt;BR /&gt; "threatID": "2fab740f143fc1aa4c1cd0146d334c5593b1428f6d062b2c406e5efe8abe95ca",&lt;BR /&gt; "threatStatus": "active",&lt;BR /&gt; "classification": "MALWARE",&lt;BR /&gt; "threatUrl": "&lt;A href="https://threatinsight.proofpoint.com/#/73aa0499-dfc8-75eb-1de8-a471b24a2e75/threat/u/2fab740f143fc1aa4c1cd0146d334c5593b1428f6d062b2c406e5efe8abe95ca" target="_blank"&gt;https://threatinsight.proofpoint.com/#/73aa0499-dfc8-75eb-1de8-a471b24a2e75/threat/u/2fab740f143fc1aa4c1cd0146d334c5593b1428f6d062b2c406e5efe8abe95ca&lt;/A&gt;",&lt;BR /&gt; "threatTime": "2018-01-29T18:41:20.000Z",&lt;BR /&gt; "threat": "badsite.zz",&lt;BR /&gt; "campaignID": "46e01b8a-c899-404d-bcd9-189bb393d1a7",&lt;BR /&gt; "threatType": "URL"&lt;BR /&gt; }&lt;BR /&gt; ],&lt;BR /&gt; "messageTime": "2018-01-23T15:44:07.000Z",&lt;BR /&gt; "impostorScore": 0,&lt;BR /&gt; "malwareScore": 0,&lt;BR /&gt; "cluster": "pharmtech_hosted",&lt;BR /&gt; "subject": "Please find a totally safe invoice attached.",&lt;BR /&gt; "quarantineFolder": "Attachment Defense",&lt;BR /&gt; "quarantineRule": "module.sandbox.threat",&lt;BR /&gt; "policyRoutes": [&lt;BR /&gt; "default_inbound"&lt;BR /&gt; ],&lt;BR /&gt; "modulesRun": [&lt;BR /&gt; "sandbox",&lt;BR /&gt; "spam",&lt;BR /&gt; "pdr"&lt;BR /&gt; ],&lt;BR /&gt; "messageSize": 6191,&lt;BR /&gt; "headerFrom": "A. Badguy &amp;lt;badguy@evil.zz&amp;gt;",&lt;BR /&gt; "headerReplyTo": null,&lt;BR /&gt; "fromAddress": [&lt;BR /&gt; "badguy@evil.zz"&lt;BR /&gt; ],&lt;BR /&gt; "ccAddresses": [&lt;BR /&gt; "bruce.wayne@university-of-education.zz"&lt;BR /&gt; ],&lt;BR /&gt; "replyToAddress": null,&lt;BR /&gt; "toAddresses": [&lt;BR /&gt; "clark.kent@pharmtech.zz",&lt;BR /&gt; "diana.prince@pharmtech.zz"&lt;BR /&gt; ],&lt;BR /&gt; "xmailer": "Spambot v2.5",&lt;BR /&gt; "messageParts": [&lt;BR /&gt; {&lt;BR /&gt; "disposition": "inline",&lt;BR /&gt; "sha256": "85738f8f9a7f1b04b5329c590ebcb9e425925c6d0984089c43a022de4f19c281",&lt;BR /&gt; "md5": "008c5926ca861023c1d2a36653fd88e2",&lt;BR /&gt; "filename": "text.txt",&lt;BR /&gt; "sandboxStatus": "UNSUPPORTED_TYPE",&lt;BR /&gt; "oContentType": "text/plain",&lt;BR /&gt; "contentType": "text/plain"&lt;BR /&gt; },&lt;BR /&gt; {&lt;BR /&gt; "disposition": "inline",&lt;BR /&gt; "sha256": "2fab740f143fc1aa4c1cd0146d334c5593b1428f6d062b2c406e5efe8abe95ca",&lt;BR /&gt; "md5": "5873c7d37608e0d49bcaa6f32b6c731f",&lt;BR /&gt; "filename": "text.html",&lt;BR /&gt; "sandboxStatus": "UNSUPPORTED_TYPE",&lt;BR /&gt; "oContentType": "text/html",&lt;BR /&gt; "contentType": "text/html"&lt;BR /&gt; }&lt;BR /&gt; ],&lt;BR /&gt; "completelyRewritten": "true",&lt;BR /&gt; "QID": "r2FNwRHF004109",&lt;BR /&gt; "GUID": "c26dbea0-80d5-463b-b93c-4e8b708219ce",&lt;BR /&gt; "sender": "e99d7ed5580193f36a51f597bc2c0210@evil.zz",&lt;BR /&gt; "recipient": [&lt;BR /&gt; "clark.kent@pharmtech.zz"&lt;BR /&gt; ],&lt;BR /&gt; "senderIP": "192.0.2.255",&lt;BR /&gt; "messageID": "20160624211145.62086.mail@evil.zz"&lt;BR /&gt; }&lt;BR /&gt; ]&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 13:47:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197873#M98378</guid>
      <dc:creator>jt1025</dc:creator>
      <dc:date>2018-01-31T13:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197918#M98379</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64643"&gt;@jt1025&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your JMESPath expression is projecting a List of Lists. And the expected result must be a list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One option is to use the following flatten projection:&lt;/P&gt;
&lt;PRE&gt;extractor = 'messagesDelivered[].threatsInfoMap[].{"indicator":threat}'&lt;/PRE&gt;
&lt;P&gt;Another option is to flatten the threatsInfoMap object and then enrich the indicator with the the additional attributes you want to collect. For instance:&lt;/P&gt;
&lt;PRE&gt;extractor = 'messagesDelivered[].threatsInfoMap[]'
indicator = 'threat'
fields = [ 'threatID', 'threatStatus', 'classification', 'campaignID', 'threatType'] &lt;/PRE&gt;</description>
      <pubDate>Wed, 31 Jan 2018 14:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197918#M98379</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-31T14:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197950#M98380</link>
      <description>&lt;P&gt;Thanks again xhoms.&amp;nbsp; I tried both options as seen below but I'm still not pulling any indictors.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="flatten.JPG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13561iF31E1A18C0A31160/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="flatten.JPG" alt="flatten.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fields.JPG" style="width: 498px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13562iDAEE6CDE875F7F8A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="fields.JPG" alt="fields.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 16:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197950#M98380</guid>
      <dc:creator>jt1025</dc:creator>
      <dc:date>2018-01-31T16:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197952#M98381</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64643"&gt;@jt1025&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you check URL, username and password with curl command?&lt;/P&gt;
&lt;PRE&gt;curl -u &amp;lt;username&amp;gt;:&amp;lt;password&amp;gt; -o output.json "&amp;lt;URL&amp;gt;"&lt;/PRE&gt;
&lt;P&gt;if it works then I'd love to get access to your output.json to reproduce your issue in my lab&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 16:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/197952#M98381</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-31T16:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/198012#M98382</link>
      <description>&lt;P&gt;The curl was sucessful. I was able to create a miner using regex to pull the indicators as a workaround.&amp;nbsp; Is there a way to share files directly through the community?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 20:16:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/198012#M98382</guid>
      <dc:creator>jt1025</dc:creator>
      <dc:date>2018-01-31T20:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/198022#M98383</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64643"&gt;@jt1025&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes. You can. Use the attachements section bellow the text area.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do not want to share it publicly in the community then just drom me an email message (xhoms@paloaltonetworks.com)&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 20:46:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/198022#M98383</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-31T20:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/198283#M98384</link>
      <description>&lt;P&gt;For any one interested here is a working config provided by xhoms&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="works.JPG" style="width: 497px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13601i35F4117F82B19E50/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="works.JPG" alt="works.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 17:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/198283#M98384</guid>
      <dc:creator>jt1025</dc:creator>
      <dc:date>2018-02-01T17:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/228693#M98385</link>
      <description>&lt;P&gt;That's a very interesting one. Is there any way we can have this in the predefined set of prototypes so we don't have to manually create it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, I've deployed this one and seems is not working for me. Connection seems successful, but it just doesn't get any indicator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the config:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2TAP.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16383iAF32B7F22CED698E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2TAP.png" alt="2TAP.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the status:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1TAP.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16382iEB191CCF6342800E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1TAP.png" alt="1TAP.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64643"&gt;@jt1025&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;, any idea on how to troubleshoot? Does minemeld host logs give more information?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tried manually running the CURL and I get results. The only thing is I use the "/siem/all" instead of the "/siem/messages/delivered", but I've tried both options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;curl -u (myuser):(mypass) -o output.json "&lt;A href="https://tap-api-v2.proofpoint.com/v2/siem/all?format=json&amp;amp;sinceSeconds=3600" target="_blank"&gt;https://tap-api-v2.proofpoint.com/v2/siem/all?format=json&amp;amp;sinceSeconds=3600&lt;/A&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 09:03:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/228693#M98385</guid>
      <dc:creator>MarcelST</dc:creator>
      <dc:date>2018-08-29T09:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/228718#M98386</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44251"&gt;@MarcelST&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SimpleJSON class is basically a JMESPath engine. What I use to do to troubleshot it is to push the JSON document to &lt;A href="http://jmespath.org/tutorial.html" target="_self"&gt;http://jmespath.org/tutorial.html&lt;/A&gt; and to test the extractor expression there (is must provide a simple list of objects)&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 10:17:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/228718#M98386</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-08-29T10:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/228759#M98387</link>
      <description>&lt;P&gt;The service principal is the username and secret is the password.&amp;nbsp; In your screenshot you have it reversed but you should have recieved an error in the last run field if that was the case.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 14:16:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/228759#M98387</guid>
      <dc:creator>jt1025</dc:creator>
      <dc:date>2018-08-29T14:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/236245#M98388</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Trying to get tap info but I cannot see the class minemeld.ft.json.SimpleJSON. please can you let me know who to add this class?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 17:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/236245#M98388</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2018-10-19T17:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/237139#M98390</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10090"&gt;@mikealanni&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;just create a new prototype out of any prototype that already uses the SimpleJSON class (i.e. the aws.AMAZON one)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-10-25_20-15-46.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17298iF3CAC67AD5453952/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-10-25_20-15-46.png" alt="2018-10-25_20-15-46.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 18:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/237139#M98390</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-10-25T18:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Parsing - ProofPoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/237609#M98391</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Thanks, I did it and I can get&amp;nbsp;indectors, but I don't know which process I need to use? I used aggrigator URL but it show zero indicators&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT:&lt;/P&gt;
&lt;P&gt;Nevermind, got to set it as a domin not URL&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 18:21:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/json-parsing-proofpoint/m-p/237609#M98391</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2018-10-29T18:21:27Z</dc:date>
    </item>
  </channel>
</rss>

