<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic syslog miner - please check rule syntax in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/169409#M99160</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just cloned a syslog miner, following the guide here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see the syslog processed counter moving, so looks like syslog forwarding is working. &amp;nbsp;I'm trying to have any source IP that generates a "critical" TID to be added to the MineMeld EDL. &amp;nbsp;I created the following rule (based on an example on the MineMeld forum):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;conditions:&lt;BR /&gt; - type == 'THREAT'&lt;BR /&gt; - severity == 'critical'&lt;BR /&gt; - src_zone == 'WAN'&lt;BR /&gt;fields: null&lt;BR /&gt;indicators:&lt;BR /&gt; - src_ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this look OK for what I'm trying to accomplish? &amp;nbsp;&lt;STRIKE&gt;And how do I know if the rule is actually hit? &amp;nbsp;&lt;/STRIKE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luca&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;edit: oops I just noticed the "hits" column on the Rules page...&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2017 21:55:49 GMT</pubDate>
    <dc:creator>LucaMarchiori</dc:creator>
    <dc:date>2017-08-01T21:55:49Z</dc:date>
    <item>
      <title>syslog miner - please check rule syntax</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/169409#M99160</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just cloned a syslog miner, following the guide here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see the syslog processed counter moving, so looks like syslog forwarding is working. &amp;nbsp;I'm trying to have any source IP that generates a "critical" TID to be added to the MineMeld EDL. &amp;nbsp;I created the following rule (based on an example on the MineMeld forum):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;conditions:&lt;BR /&gt; - type == 'THREAT'&lt;BR /&gt; - severity == 'critical'&lt;BR /&gt; - src_zone == 'WAN'&lt;BR /&gt;fields: null&lt;BR /&gt;indicators:&lt;BR /&gt; - src_ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this look OK for what I'm trying to accomplish? &amp;nbsp;&lt;STRIKE&gt;And how do I know if the rule is actually hit? &amp;nbsp;&lt;/STRIKE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luca&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;edit: oops I just noticed the "hits" column on the Rules page...&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 21:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/169409#M99160</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-08-01T21:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: syslog miner - please check rule syntax</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/170060#M99161</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;looks good to me. Have you tested it already ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would probably add "log_subtype" and "threat_name" as fields in the rule, to save more context of the original log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 12:30:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/170060#M99161</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-08-04T12:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: syslog miner - please check rule syntax</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/170075#M99162</link>
      <description>&lt;P&gt;Hi lmori,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you mean something like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;conditions:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- type == 'THREAT'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- severity == 'critical'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- src_zone == 'WAN'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;fields:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;SPAN&gt;"log_subtype"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; - "threat_name"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;indicators:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- src_ip&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I had 2 "high" severity and one "critical" events in the threat log since yesterday, and the counter this morning is still at zero hits.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is the config currently (/opt/minemeld/local/config/syslog-miner_rules.yml):&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- conditions: [type == 'THREAT', log_subtype == 'vulnerability', severity == 'high',&lt;BR /&gt; src_zone == 'WAN']&lt;BR /&gt; fields: null&lt;BR /&gt; indicators: [src_ip]&lt;BR /&gt; name: threats-ALL-high&lt;BR /&gt;- conditions: [type == 'THREAT', log_subtype == 'vulnerability', severity == 'critical',&lt;BR /&gt; src_zone == 'WAN']&lt;BR /&gt; fields: null&lt;BR /&gt; indicators: [src_ip]&lt;BR /&gt; name: threats-ALL-critical&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;** edit 2:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Got a few pages of "high" severity threat this morning (TID 40007). &amp;nbsp;No hits on the syslog miner node.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 19:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/170075#M99162</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-08-04T19:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: syslog miner - please check rule syntax</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/170264#M99163</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;which PAN-OS version are you running ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2017 07:31:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/170264#M99163</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-08-07T07:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: syslog miner - please check rule syntax</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/170531#M99164</link>
      <description>&lt;P&gt;Hi Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using 7.1.11&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 14:52:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/170531#M99164</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-08-08T14:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: syslog miner - please check rule syntax</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/171672#M99165</link>
      <description>&lt;P&gt;Hi lmori,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas why the miner node is not getting any hits? &amp;nbsp;Is there a MineMeld rule help doc that I should be looking at instead?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luca&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 15:38:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-miner-please-check-rule-syntax/m-p/171672#M99165</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-08-15T15:38:46Z</dc:date>
    </item>
  </channel>
</rss>

