<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: indicators and values in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162097#M99018</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;- thanks for your reply..&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;So I am using a prototype with name "stdlib.feedHCRedWithValue &lt;SPAN class="prototypedetail-description"&gt;PROTOTYPE"&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the URL to download the feed, are you saying it would look like the following :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://&amp;lt;minemeld_server&amp;gt;/feeds/&amp;lt;feed_output&amp;gt;&amp;amp;v=json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(I'm sure that's not it as I get an 'Unknown feed' message...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks...&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jun 2017 21:47:46 GMT</pubDate>
    <dc:creator>vb0398</dc:creator>
    <dc:date>2017-06-19T21:47:46Z</dc:date>
    <item>
      <title>indicators and values</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/160497#M99016</link>
      <description>&lt;P&gt;&amp;nbsp;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;I noticed that when creating the '_process_item' code for a new miner, you generate data as an indicator, and a value. &amp;nbsp;I am able to generate an EDL with my code, but it looks like the values associated with the indicators are not present. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anybody know what types of feeds you would need to create to see the values associated with their corresponding indicators?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2017 01:44:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/160497#M99016</guid>
      <dc:creator>vb0398</dc:creator>
      <dc:date>2017-06-10T01:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: indicators and values</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/161933#M99017</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/63193"&gt;@vb0398&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;sorry for the late reply, you can click on LOGS in the top right corner of the Miner window to see all the indicators/values generatred by the Miner. See screenshots below.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MineMeld-1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9804iE0DE12A65F9E2113/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="MineMeld-1.png" alt="MineMeld-1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2017-06-19 at 14.29.58.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9806i89BFA7C6ADC3B5C2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2017-06-19 at 14.29.58.png" alt="Screen Shot 2017-06-19 at 14.29.58.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To see the value in the feed you should:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;use a prototype with name stdlib.feed*WithValue&lt;/LI&gt;
&lt;LI&gt;in the URL of the feed, add the parameter to specify a format rendering the value - like v=json&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 19 Jun 2017 12:33:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/161933#M99017</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-06-19T12:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: indicators and values</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162097#M99018</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;- thanks for your reply..&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;So I am using a prototype with name "stdlib.feedHCRedWithValue &lt;SPAN class="prototypedetail-description"&gt;PROTOTYPE"&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the URL to download the feed, are you saying it would look like the following :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://&amp;lt;minemeld_server&amp;gt;/feeds/&amp;lt;feed_output&amp;gt;&amp;amp;v=json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(I'm sure that's not it as I get an 'Unknown feed' message...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks...&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 21:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162097#M99018</guid>
      <dc:creator>vb0398</dc:creator>
      <dc:date>2017-06-19T21:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: indicators and values</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162221#M99019</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/63193"&gt;@vb0398&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;you should use a URL like this:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;https://&amp;lt;minemeld_server&amp;gt;/feeds/&amp;lt;feed_output&amp;gt;&lt;STRONG&gt;?&lt;/STRONG&gt;v=json&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(note the question mark instead of the &amp;amp;)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 10:10:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162221#M99019</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-06-20T10:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: indicators and values</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162405#M99020</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;-&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;thanks - works great.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ingesting this data into a Palo Alto device, I'm assuming the only way is via an EDL, and that would just be the standard/generic feed input&amp;nbsp;(i.e., '&amp;lt;ip address start&amp;gt;-&amp;lt;ip address end&amp;gt;') &amp;nbsp;Is that correct?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 21:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162405#M99020</guid>
      <dc:creator>vb0398</dc:creator>
      <dc:date>2017-06-20T21:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: indicators and values</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162471#M99021</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/63193"&gt;@vb0398&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;for ingesting with Palo Alto Networks NGFW you can use EDL format ("plain") or DAG output nodes.&lt;/P&gt;
&lt;P&gt;EDL can be used for IPs (/32, ranges and CIDRs), URLs and domains.&lt;/P&gt;
&lt;P&gt;DAG output node only for /32 IPs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My suggestion for traditional feeds is using EDLs.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 08:34:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/indicators-and-values/m-p/162471#M99021</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-06-21T08:34:46Z</dc:date>
    </item>
  </channel>
</rss>

