<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rsyslogd dependencies problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/125671#M98529</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30691"&gt;@uam﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;could you try downgrading to libfastjson&amp;nbsp;0.99.2-0adiscon1trusty1 ? that is the version distributed by minemeld repo.&lt;/P&gt;
&lt;P&gt;We have plans to move to Ubuntu 16.04, there rsyslogd has been updated to 8.16 and will make our life easier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2016 21:36:25 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2016-11-10T21:36:25Z</dc:date>
    <item>
      <title>rsyslogd dependencies problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/125341#M98528</link>
      <description>&lt;P&gt;Hi Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was testing&amp;nbsp;stdlib.localSyslog to correlate paloalto logs with indicator following this article &lt;A href="https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/MineMeldArticles/article-id/11" target="_blank"&gt;https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/MineMeldArticles/article-id/11&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I was unable to make it work. After a while, I have noticed that rsyslogd was not running. If you run "service rsyalogd status" says that is running but it's not. After run manually i got the next error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;root@minemeld:/var/log# rsyslogd&lt;BR /&gt;rsyslogd: error while loading shared libraries: libfastjson.so.3: cannot open shared object file: No such file or directory&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems that rsyslog is compiled&amp;nbsp;against&amp;nbsp;&lt;SPAN&gt;libfastjson3 but ubuntu 14.04 it use&amp;nbsp;libfastjson4.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm using the VM with Ubuntu&amp;nbsp;14.04. Minemeld&amp;nbsp;0.9.26&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2016 18:29:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/125341#M98528</guid>
      <dc:creator>uam</dc:creator>
      <dc:date>2016-11-09T18:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: rsyslogd dependencies problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/125671#M98529</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30691"&gt;@uam﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;could you try downgrading to libfastjson&amp;nbsp;0.99.2-0adiscon1trusty1 ? that is the version distributed by minemeld repo.&lt;/P&gt;
&lt;P&gt;We have plans to move to Ubuntu 16.04, there rsyslogd has been updated to 8.16 and will make our life easier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 21:36:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/125671#M98529</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-10T21:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: rsyslogd dependencies problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/125854#M98530</link>
      <description>&lt;P&gt;Hi Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that's was I did and rsyslogd is up&amp;amp;running now. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have &amp;nbsp;configured successfully&amp;nbsp;the syslog-analyzer&amp;nbsp;and feed stats are now working. By the way, great feature!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I don't really know how to set the rules in the syslog-miner to extract indicators. I have look for any documentation but no luck. Is there any article related? I would like to create a feed with indicators from drop/deny logs from PA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;
&lt;P&gt;Victor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2016 16:49:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/125854#M98530</guid>
      <dc:creator>uam</dc:creator>
      <dc:date>2016-11-11T16:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: rsyslogd dependencies problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/126172#M98531</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30691"&gt;@uam﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;have you checked this&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262&lt;/A&gt; ?&lt;/P&gt;
&lt;P&gt;Really far from being complete, but it should give you an idea of how things work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luigi&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2016 17:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rsyslogd-dependencies-problem/m-p/126172#M98531</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-14T17:43:07Z</dc:date>
    </item>
  </channel>
</rss>

