<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DAGPusher and DAG in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73580#M99613</link>
    <description>&lt;P&gt;Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got no output from the command. I suspect a problem in the DagPusher connection to the firewall. What is the best course to troubleshoot that the handled device is correctly connected from Minemeld?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bertrand&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2016 16:19:15 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2016-02-25T16:19:15Z</dc:date>
    <item>
      <title>DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73563#M99610</link>
      <description>&lt;P&gt;Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you confirm DAGPusher name should match tag for DAG in PAN-OS? &amp;nbsp;I can't have the DAG updated with Minemeld indicators&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bertrand&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 15:03:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73563#M99610</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2016-02-25T15:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73569#M99612</link>
      <description>&lt;P&gt;Hi Bertrand,&lt;/P&gt;
&lt;P&gt;no relationship between dagpuhser name and DAG on PAN-OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you check with "show object registered-ip all" ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should be something like:&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;admin@PA-VM-Minemeld&amp;gt; show object registered-ip all &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;registered IP &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Tags&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;----------------------------------------&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;-----------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;lt;IP edited&amp;gt;&amp;nbsp;#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;"mmld_confidence_high"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;"mmld_direction_unknown"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;"mmld_pushed"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[...]&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;&lt;SPAN class="s1"&gt;NOTE: only unicast IP will be pushed, as DAG API only support unicast IPs.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 15:13:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73569#M99612</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-02-25T15:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73580#M99613</link>
      <description>&lt;P&gt;Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got no output from the command. I suspect a problem in the DagPusher connection to the firewall. What is the best course to troubleshoot that the handled device is correctly connected from Minemeld?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bertrand&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 16:19:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73580#M99613</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2016-02-25T16:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73582#M99614</link>
      <description>&lt;P&gt;You should check /opt/minemeld/logs/minemeld-engine.log file for errors.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 16:31:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73582#M99614</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-02-25T16:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73592#M99615</link>
      <description>&lt;P&gt;Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried with the following (as Office365 is still experimental):&lt;/P&gt;
&lt;P&gt;Miner:&amp;nbsp;&lt;A class="ng-binding" href="https://192.168.35.129/#/prototypes/malwaredomainlist/ip" target="_blank"&gt;malwaredomainlist.ip&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Aggregator:&amp;nbsp;&lt;A class="ng-binding" href="https://192.168.35.129/#/prototypes/stdlib/aggregatorIPv4Generic" target="_blank"&gt;stdlib.aggregatorIPv4Generic&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And dagPusher as the Output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't get any result in viewing objects on PA devices and got the attached screenshots which makes me feel the dagPusher is not processing, while receiving, indicators.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no error in the minemeld-engine.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bertrand&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 17:29:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73592#M99615</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2016-02-25T17:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73593#M99616</link>
      <description>&lt;P&gt;Hi Bertrand,&lt;/P&gt;
&lt;P&gt;if you see updates and 0 indicators it means indicators have been discarded.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aggregator generates IPv4 ranges, in this case you may want to remove it from the chain and directly connect malwaredomainlist.ip miner to dagpusher.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will improve the dagPusher to keep a metric about discarded indicator and improve the check on unicast IPs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Luigi&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 17:43:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73593#M99616</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-02-25T17:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73634#M99617</link>
      <description>&lt;P&gt;Thanks Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Understood and it works much better. Very good job by the way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;B.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 22:11:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73634#M99617</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2016-02-25T22:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73635#M99618</link>
      <description>&lt;P&gt;Thanks, next minor release should have a more flexible dag pusher node. You will be able to use an IPv4 Aggregator as upstream node.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luigi&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 22:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/73635#M99618</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-02-25T22:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/78759#M99619</link>
      <description>&lt;P&gt;Can the tags be modified somewhere? I want a tag for each input my DAGPusher is sending. Unless there is another way to create multiple pushed DAG's on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For instance those with the tag O365 get DAG name O365 and end up with a firewall ACL&amp;nbsp;that is an allow. Other blacklist inputs go into a "verybadIP"&amp;nbsp;list and get a drop traffic action ACL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;104.214.35.244 #&lt;BR /&gt;"mmld_confidence_high"&lt;BR /&gt;"mmld_direction_unknown"&lt;BR /&gt;"mmld_pushed"&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;&lt;EM&gt;"mmld_o365ip"&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;&lt;EM&gt;1.1.1.1&amp;nbsp;#&lt;BR /&gt;"mmld_confidence_high"&lt;BR /&gt;"mmld_direction_unknown"&lt;BR /&gt;"mmld_pushed"&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;&lt;EM&gt;"mmld_verybadIP"&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 20:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/78759#M99619</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2016-05-27T20:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: DAGPusher and DAG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/78790#M99620</link>
      <description>&lt;P&gt;Hi bspilde,&lt;/P&gt;
&lt;P&gt;that is definitely possible. Solution:&lt;/P&gt;
&lt;P&gt;- go to CONFIG and click on &lt;STRONG&gt;browse prototypes&lt;/STRONG&gt; button&lt;/P&gt;
&lt;P&gt;- search for stdlibg.dagPusher prototype and click on it&lt;/P&gt;
&lt;P&gt;- click on the NEW button to create a new prototype based on that&lt;/P&gt;
&lt;P&gt;- in the config section define the tag_prefix property, like in the picture below&lt;/P&gt;
&lt;P&gt;- click OK&lt;/P&gt;
&lt;P&gt;- and then create a new node based on this new prototype&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When using this new prototype all the tags have prefix "badipbad_" and you can filter on "badipbad_pushed" to collect all the IPs pushed by this new node. Tags will look like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#008000"&gt;&lt;EM&gt;1.1.1.1&amp;nbsp;#&lt;BR /&gt;"&lt;SPAN&gt;badipbad_&lt;/SPAN&gt;confidence_high"&lt;BR /&gt;"&lt;SPAN&gt;badipbad_&lt;/SPAN&gt;direction_unknown"&lt;BR /&gt;"&lt;SPAN&gt;badipbad_&lt;/SPAN&gt;pushed"&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-05-30 at 10.05.48.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4186iDD0CA6DA023CAE58/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2016-05-30 at 10.05.48.png" alt="Screen Shot 2016-05-30 at 10.05.48.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2016 08:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dagpusher-and-dag/m-p/78790#M99620</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-05-30T08:11:05Z</dc:date>
    </item>
  </channel>
</rss>

