<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure MineMeld to forward Logs to RSA Security Analytics in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/162595#M99036</link>
    <description>&lt;P&gt;Hi Imori thank a lot for your quick response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact I already install CEF extension, and I can create a node with this output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CLASS mmcef.node.Output&lt;/P&gt;&lt;P&gt;PROTOTYPE cef.testCEF&lt;/P&gt;&lt;P&gt;STATE started&lt;/P&gt;&lt;P&gt;# INDICATORS 938&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this node doesn´t not give me a list or other information, I just can see all LOGS of this output in the upper right corner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What´s next from here, I didn´t find information about that; how can I forward this output to RSA or Where does this logs are stored to see if I can get them and send to RSA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2017 21:55:51 GMT</pubDate>
    <dc:creator>vhgambit</dc:creator>
    <dc:date>2017-06-21T21:55:51Z</dc:date>
    <item>
      <title>How to configure MineMeld to forward Logs to RSA Security Analytics</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/161457#M99034</link>
      <description>&lt;P&gt;I want to forward the output of output nodes in minemeld to SIEM, I want to see the output indicators in Security Analytics to create rules and when an indicator match generate an alert, actually I have configured PaloAlto Firrewalls with Dynamic List but I would like to send output indicators to SIEM&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 23:35:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/161457#M99034</guid>
      <dc:creator>vhgambit</dc:creator>
      <dc:date>2017-06-15T23:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure MineMeld to forward Logs to RSA Security Analytics</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/161942#M99035</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66450"&gt;@vhgambit&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;you could try 2 methods:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;use the CEF extension for MineMeld to generate indicators in CEF format and forward them to RSA (&lt;A href="https://github.com/PaloAltoNetworks/minemeld-cef" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-cef&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;starting from 0.9.40, MineMeld supports generating feeds in CSV format. RSA Security Analytics should be able to ingest feeds in CSV (&lt;A href="https://community.rsa.com/docs/DOC-54891" target="_blank"&gt;https://community.rsa.com/docs/DOC-54891&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 19 Jun 2017 12:55:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/161942#M99035</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-06-19T12:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure MineMeld to forward Logs to RSA Security Analytics</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/162595#M99036</link>
      <description>&lt;P&gt;Hi Imori thank a lot for your quick response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact I already install CEF extension, and I can create a node with this output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CLASS mmcef.node.Output&lt;/P&gt;&lt;P&gt;PROTOTYPE cef.testCEF&lt;/P&gt;&lt;P&gt;STATE started&lt;/P&gt;&lt;P&gt;# INDICATORS 938&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this node doesn´t not give me a list or other information, I just can see all LOGS of this output in the upper right corner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What´s next from here, I didn´t find information about that; how can I forward this output to RSA or Where does this logs are stored to see if I can get them and send to RSA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 21:55:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/162595#M99036</guid>
      <dc:creator>vhgambit</dc:creator>
      <dc:date>2017-06-21T21:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure MineMeld to forward Logs to RSA Security Analytics</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/162778#M99037</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66450"&gt;@vhgambit&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;you should customize the cef.testCEF prototype to specify the host, port and protocol to communicate with your RSA SIEM.&lt;/P&gt;
&lt;P&gt;You can do this by:&lt;/P&gt;
&lt;P&gt;- click on CONFIG&lt;/P&gt;
&lt;P&gt;- click on the hamburger icon in the bottom right corner&lt;/P&gt;
&lt;P&gt;- search for &amp;nbsp;testCEF and click on it&lt;/P&gt;
&lt;P&gt;- click on NEW (not CLONE)&lt;/P&gt;
&lt;P&gt;- modify the config and specify host, port and protocol of the SIEM&lt;/P&gt;
&lt;P&gt;- click OK&lt;/P&gt;
&lt;P&gt;- create a new output node with the new prototype&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 16:25:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-minemeld-to-forward-logs-to-rsa-security/m-p/162778#M99037</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-06-22T16:25:07Z</dc:date>
    </item>
  </channel>
</rss>

