<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Couple of issues with MineMeld 0.9.42, PanOS 7.1.11 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183940#M99381</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for pointing me in the right direction.&amp;nbsp; I think that the problem was I had manually created a copy of a config file.&amp;nbsp; After deleting that file, export works just fine!&amp;nbsp; A little (linux) knowledge... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule issue fixed as well...&amp;nbsp; &amp;nbsp;There was a typo (dst_zone) that got into some of the rules. "&lt;STRONG&gt;dest_zone&lt;/STRONG&gt;" is the correct field.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luca&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2017 21:21:47 GMT</pubDate>
    <dc:creator>LucaMarchiori</dc:creator>
    <dc:date>2017-10-26T21:21:47Z</dc:date>
    <item>
      <title>Couple of issues with MineMeld 0.9.42, PanOS 7.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183286#M99376</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a couple of problems with MineMeld (on a VM from ova template).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp; I recently seem to have lost the ability to export a system backup (which was working until recently).&amp;nbsp; In the log, I can see a bunch of "GET /jobs/status-backup/.....", but the actual download never starts.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;[2017-10-23 16:12:19 UTC] [1971] [INFO] AUDIT - {"msg": null, "action": "POST /status/backup", "params": [["jsonbody", "{\"p\": \"password\"}"]], "user": "admin/luca.admin"}
[2017-10-23 16:12:19 UTC] [1971] [INFO] redis connection pool: in use: 0 available: 1
127.0.0.1 - - [23/Oct/2017:16:12:19 +0000] "POST /status/backup?_=1508775151 HTTP/1.0" 200 55 "https://10.0.50.65/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36"
[2017-10-23 16:12:19 UTC] [1971] [INFO] Executing job mm-jobs-status-backup-e1db206f-a1e3-4988-898d-ca0f02c9e23c - ['/usr/bin/7z', 'a', '-ppassword', '-y', '/tmp/mm-local-backupn9IHT9.zip', '/opt/minemeld/local/prototypes', '/opt/minemeld/local/config'] cwd: /tmp/mm-jobs-status-backup-e1db206f-a1e3-4988-898d-ca0f02c9e23cXTBsCU logfile: /opt/minemeld/log/mm-jobs-status-backup-e1db206f-a1e3-4988-898d-ca0f02c9e23c.log
[2017-10-23 16:12:22 UTC] [1971] [DEBUG] redis session connection pool: in use: 0 available: 5
[2017-10-23 16:12:22 UTC] [1971] [INFO] redis connection pool: in use: 0 available: 1
127.0.0.1 - - [23/Oct/2017:16:12:22 +0000] "GET /jobs/status-backup/e1db206f-a1e3-4988-898d-ca0f02c9e23c?_=1508775154 HTTP/1.0" 200 463 "https://10.0.50.65/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36"
[2017-10-23 16:12:25 UTC] [1971] [DEBUG] redis session connection pool: in use: 0 available: 5
[2017-10-23 16:12:25 UTC] [1971] [INFO] redis connection pool: in use: 0 available: 1
127.0.0.1 - - [23/Oct/2017:16:12:25 +0000] "GET /jobs/status-backup/e1db206f-a1e3-4988-898d-ca0f02c9e23c?_=1508775157 HTTP/1.0" 200 463 "https://10.0.50.65/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36"
[2017-10-23 16:12:28 UTC] [1971] [DEBUG] redis session connection pool: in use: 0 available: 5
[2017-10-23 16:12:28 UTC] [1971] [INFO] redis connection pool: in use: 0 available: 1
127.0.0.1 - - [23/Oct/2017:16:12:28 +0000] "GET /jobs/status-backup/e1db206f-a1e3-4988-898d-ca0f02c9e23c?_=1508775161 HTTP/1.0" 200 463 "https://10.0.50.65/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36"
[2017-10-23 16:12:31 UTC] [1971] [DEBUG] redis session connection pool: in use: 0 available: 5
[2017-10-23 16:12:31 UTC] [1971] [INFO] redis connection pool: in use: 0 available: 1
127.0.0.1 - - [23/Oct/2017:16:12:31 +0000] "GET /jobs/status-backup/e1db206f-a1e3-4988-898d-ca0f02c9e23c?_=1508775164 HTTP/1.0" 200 463 "https://10.0.50.65/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36"
[2017-10-23 16:12:33 UTC] [1971] [DEBUG] redis session connection pool: in use: 0 available: 5
127.0.0.1 - - [23/Oct/2017:16:12:33 +0000] "GET /supervisor?_=1508775165 HTTP/1.0" 200 594 "https://10.0.50.65/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36"
[2017-10-23 16:12:34 UTC] [1971] [DEBUG] redis session connection pool: in use: 0 available: 5&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I try a manual back from SSH (ubuntu user), I get this (permission denied?):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;ubuntu@minemeld:/tmp$ sudo service minemeld stop
 * Stopping: minemeld                                                                                                                                                                    minemeld-supervisord-listener: stopped
minemeld-traced: stopped
minemeld-engine: stopped
minemeld-web: stopped
                                                                                                                                                                                  [ OK ]
ubuntu@minemeld:/tmp$ tar -cvzf backup.tar.gz /opt/minemeld/local/config/ /opt/minemeld/local/prototypes/
tar: Removing leading `/' from member names
/opt/minemeld/local/config/
tar: /opt/minemeld/local/config/wlWhiteListIPv4_indicators.yml.copy: Cannot open: Permission denied
tar: /opt/minemeld/local/config/node-syslog-miner-local-30d_rules.yml.copy: Cannot open: Permission denied
tar: /opt/minemeld/local/config/committed-config.yml: Cannot open: Permission denied
/opt/minemeld/local/config/api/
/opt/minemeld/local/config/api/20-local.yml
/opt/minemeld/local/config/api/10-defaults.yml
tar: /opt/minemeld/local/config/api/50-api-users-attrs.yml: Cannot open: Permission denied
/opt/minemeld/local/config/api/wsgi.htpasswd
tar: /opt/minemeld/local/config/running-config.yml.1508772314: Cannot open: Permission denied
tar: /opt/minemeld/local/config/running-config.yml: Cannot open: Permission denied
tar: /opt/minemeld/local/config/running-config.yml.1508771982: Cannot open: Permission denied
tar: /opt/minemeld/local/config/node-syslog-miner-local-30d_rules.yml: Cannot open: Permission denied
tar: /opt/minemeld/local/config/committed-config.yml.copy: Cannot open: Permission denied
/opt/minemeld/local/config/traced/
/opt/minemeld/local/config/traced/traced.yml
tar: /opt/minemeld/local/config/wlWhiteListIPv4_indicators.yml: Cannot open: Permission denied
/opt/minemeld/local/prototypes/
tar: /opt/minemeld/local/prototypes/minemeldlocal.yml.copy: Cannot open: Permission denied
tar: /opt/minemeld/local/prototypes/minemeldlocal.yml: Cannot open: Permission denied
tar: Exiting with failure status due to previous errors
ubuntu@minemeld:/tmp$
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. I setup a panos syslog miner.&amp;nbsp; It's working&amp;nbsp;great for log_subtype = flood, but not at all for subtype vulnerability.&amp;nbsp; I cannot get any vulnerability events to generate a hit on the correspondent rule(s).&amp;nbsp; Very similar flood rules are working perfectly.&amp;nbsp; Example of a rule that is not working:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;conditions:
  - type == 'THREAT'
  - log_subtype == 'vulnerability'
  - severity == 'critical'
  - src_zone == 'WAN'
  - dst_zone == 'DMZ'
fields:
  - log_subtype
  - threat_name
indicators:
  - src_ip&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example of a rule that is working:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;conditions:
  - type == "THREAT"
  - log_subtype == "flood"
  - severity == "critical"
  - src_zone == "WAN"
  - dest_zone == "DMZ"
  - action == "drop"
fields:
  - log_subtype
  - threat_name
indicators:
  - src_ip&lt;/PRE&gt;
&lt;P&gt;I tried making the log_subtype vulnerability rules more specific, for instance by adding a threat name:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;threat_name == 'Wireless IP Camera Pre-Auth Info Leak Vulnerability(33556)'&lt;/PRE&gt;
&lt;P&gt;or an action:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;action == 'block-ip'&lt;/PRE&gt;
&lt;P&gt;Nothing has worked so far.&amp;nbsp; I can see the events in the THREAT log that match the rules conditions, but the rules are not picking those up.&amp;nbsp; Any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 17:18:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183286#M99376</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-10-23T17:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Couple of issues with MineMeld 0.9.42, PanOS 7.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183748#M99377</link>
      <description>&lt;P&gt;Anyone?&amp;nbsp; The only difference I can think of between rule working / not working is that the flood rules hit a DoS policy, while the others just hit a security rule (allow) then dropped as critical vulnerabilites.&amp;nbsp; Both type of events are logged in the same Panorama log profile.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 21:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183748#M99377</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-10-25T21:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Couple of issues with MineMeld 0.9.42, PanOS 7.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183897#M99378</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;1 - when you press EXPORT BACKUP after some seconds you should see a window like this one, please click on &lt;STRONG&gt;here&lt;/STRONG&gt; to download the encrypted zip file&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MineMeld-backup.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12114iEEDFD7207F339041/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="MineMeld-backup.png" alt="MineMeld-backup.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;2 - have you tried simplifying the rule (just type and log_subtype) to see&amp;nbsp;if it is matched ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 14:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183897#M99378</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-10-26T14:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Couple of issues with MineMeld 0.9.42, PanOS 7.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183918#M99379</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That "Download backup" windows just never appears.&amp;nbsp; After clicking on&amp;nbsp; the "Export Backup" button and typing the backup password, both the Export and Restore Backup buttons are grayed out, and stay like that until I click on a different tab and then back to System.&amp;nbsp; I've waited over 10-15 minutes.&amp;nbsp; I use Chrome (popup blocker is disabled for the site), but also tried Firefox.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As previously mentioned, manual backup fails as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will try simplyfing the vulnerability rules to see if I'm getting anywhere with that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 15:11:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183918#M99379</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-10-26T15:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Couple of issues with MineMeld 0.9.42, PanOS 7.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183939#M99380</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the reason manual backup is failing is that you need to be minemeld user to access some of those files, please try:&lt;/P&gt;
&lt;PRE&gt;sudo -u minemeld tar -cvzf backup.tar.gz /opt/minemeld/local/config/ /opt/minemeld/local/prototypes/&lt;/PRE&gt;
&lt;P&gt;In the directory /opt/minemeld/log you should find the logs of the backup logs, could you check them to see if there is a clue about the cause of the failures ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 15:38:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183939#M99380</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-10-26T15:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Couple of issues with MineMeld 0.9.42, PanOS 7.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183940#M99381</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for pointing me in the right direction.&amp;nbsp; I think that the problem was I had manually created a copy of a config file.&amp;nbsp; After deleting that file, export works just fine!&amp;nbsp; A little (linux) knowledge... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule issue fixed as well...&amp;nbsp; &amp;nbsp;There was a typo (dst_zone) that got into some of the rules. "&lt;STRONG&gt;dest_zone&lt;/STRONG&gt;" is the correct field.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 21:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-issues-with-minemeld-0-9-42-panos-7-1-11/m-p/183940#M99381</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-10-26T21:21:47Z</dc:date>
    </item>
  </channel>
</rss>

