<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Same Version Differnt Results in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174187#M99220</link>
    <description>&lt;P&gt;xhoms - Yep, had done all that which is what was really confusing me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update: I stopped services, deleted all exisiting data files in /opt/minemeld/local/data, restarted services.&lt;BR /&gt;Now the two instances are reporting the same numbers across the board.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I possibly correct in assuming there was some difference in learned confidence values as the dev instance had been runnning for an additional 60ish days, or some other built in logic?&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2017 16:01:56 GMT</pubDate>
    <dc:creator>0isac0</dc:creator>
    <dc:date>2017-08-31T16:01:56Z</dc:date>
    <item>
      <title>Same Version Differnt Results</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174145#M99218</link>
      <description>&lt;P&gt;I have two instances of MineMeld, both built off the instructions at &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-install-MineMeld-on-Ubuntu-Server-14-04/ta-p/98454" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-install-MineMeld-on-Ubuntu-Server-14-04/ta-p/98454&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My dev instance built in June and reporting version 0.9.40 appears to be functioning correctly&lt;/P&gt;&lt;P&gt;My prod instance built in Aug and reporting version 0.9.40 appears to be simply echoing the raw data as the output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This does not occur on all datafeeds.&amp;nbsp; In particular it does occur on a cloned protoype for IPv4, stdlib.aggregatorIPv4Generic.&lt;/P&gt;&lt;P&gt;The source miner nodes all report the same number of IOCs.&amp;nbsp; Once the data hits the processor node the dev instance reports 139 IOCs while the prod reports 1236 IOCs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have attempted to verify permissions, compare files etc.&amp;nbsp; The last modification was copying the same custom prototypes file minemeldlocal.yml to both instances.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 14:34:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174145#M99218</guid>
      <dc:creator>0isac0</dc:creator>
      <dc:date>2017-08-31T14:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Same Version Differnt Results</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174162#M99219</link>
      <description>&lt;P&gt;Thinks I'd check:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Grab configuration files from both instances (Config -&amp;gt; Export) and double check they're exactly the same.&lt;/LI&gt;
&lt;LI&gt;Deep dive into the filter configuration section of all processors and output nodes. Different share_levels and confidence matching conditions could explain it.&lt;/LI&gt;
&lt;LI&gt;Verify the share_level attribute in the miners is the expected one.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 31 Aug 2017 15:24:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174162#M99219</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-08-31T15:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Same Version Differnt Results</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174187#M99220</link>
      <description>&lt;P&gt;xhoms - Yep, had done all that which is what was really confusing me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update: I stopped services, deleted all exisiting data files in /opt/minemeld/local/data, restarted services.&lt;BR /&gt;Now the two instances are reporting the same numbers across the board.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I possibly correct in assuming there was some difference in learned confidence values as the dev instance had been runnning for an additional 60ish days, or some other built in logic?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 16:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174187#M99220</guid>
      <dc:creator>0isac0</dc:creator>
      <dc:date>2017-08-31T16:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Same Version Differnt Results</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174197#M99221</link>
      <description>&lt;P&gt;Depending on the age_out policy of a miner you can expect the instance running for more time to keep indicators that have never been seen by the newer instance. But if the number of indicators at the miner level between instances is the same then I would assume they all have the same confidence values.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A common mistake is to "clone" a miner prototype from the library that has "share_level = red" and attaching it to a processor with a filter that only accepts indicators in the "share_level = green"&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 16:10:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-version-differnt-results/m-p/174197#M99221</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-08-31T16:10:16Z</dc:date>
    </item>
  </channel>
</rss>

