<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to add my own bulk IOCs into Minemeld in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-add-my-own-bulk-iocs-into-minemeld/m-p/139400#M98698</link>
    <description>&lt;P&gt;Trying to find a way to do this with some of the miners but it seems that you can only add 1 indicator at a time.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2017 18:27:02 GMT</pubDate>
    <dc:creator>lgiancaterini</dc:creator>
    <dc:date>2017-01-25T18:27:02Z</dc:date>
    <item>
      <title>how to add my own bulk IOCs into Minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-add-my-own-bulk-iocs-into-minemeld/m-p/139400#M98698</link>
      <description>&lt;P&gt;Trying to find a way to do this with some of the miners but it seems that you can only add 1 indicator at a time.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 18:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-add-my-own-bulk-iocs-into-minemeld/m-p/139400#M98698</guid>
      <dc:creator>lgiancaterini</dc:creator>
      <dc:date>2017-01-25T18:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: how to add my own bulk IOCs into Minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-add-my-own-bulk-iocs-into-minemeld/m-p/139896#M98699</link>
      <description>&lt;P&gt;Clone&amp;nbsp;a new indicator list from prototype '&lt;SPAN&gt;stdlib.listIPv4Generic'. For example name it My_BlackList.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Create a new entry with the attributes you like.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Login to your minemeld console via ssh.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Have a look at your indicator list (be aware, the example is my list with my preferred attributes):&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;$ head /opt/minemeld/local/config/BlackList_indicators.yml
- {indicator: 60.190.98.50, share_level: red}
- {indicator: 60.7.70.94, share_level: red}
- {indicator: 91.148.217.244, share_level: red}
- {indicator: 123.183.209.138, share_level: red}&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Create your indicator list in the same format (use awk or something like that).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Just copy the resulting file over the existing one. The MineMeld engine takes care of the new updates immediately&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You may also just edit the indicator file wiht 'nano' or 'vi' an insert the indicators in correct format.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Always use the same format. Do not try to create a entries with differnet attributes. (of course you can do it for exercise and find out what's happening)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Klaus&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2017 20:54:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-add-my-own-bulk-iocs-into-minemeld/m-p/139896#M98699</guid>
      <dc:creator>KlausGroeger</dc:creator>
      <dc:date>2017-01-28T20:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: how to add my own bulk IOCs into Minemeld</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-add-my-own-bulk-iocs-into-minemeld/m-p/140466#M98700</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2017 12:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-add-my-own-bulk-iocs-into-minemeld/m-p/140466#M98700</guid>
      <dc:creator>lgiancaterini</dc:creator>
      <dc:date>2017-02-01T12:58:44Z</dc:date>
    </item>
  </channel>
</rss>

