<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Withdraw mesage source in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/withdraw-mesage-source/m-p/118973#M99776</link>
    <description>Perfect answer! Just what I needed to know! Thank you @Imori</description>
    <pubDate>Wed, 12 Oct 2016 10:25:55 GMT</pubDate>
    <dc:creator>Forseti</dc:creator>
    <dc:date>2016-10-12T10:25:55Z</dc:date>
    <item>
      <title>Withdraw mesage source</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/withdraw-mesage-source/m-p/118966#M99774</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently working on connecting MineMeld with our SIEM solution. I however ran into a question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When receiving an update message it states which sources the IOC originated from, also if there are multiple. example: (binarydefense and badips)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{"message":"{\"@indicator\":\"120.69.220.5-120.69.220.5\",\"direction\":\"inbound\",\"@origin\":\"IPv4_Aggregator\",\"type\":\"IPv4\",\"@timestamp\":\"2016-10-11T17:13:35.693563Z\",\"confidence\":50,\"share_level\":\"green\",\&lt;STRONG&gt;"sources\":[\"binarydefense.banlist\",\"badips.any_3\"]&lt;/STRONG&gt;,\"logstash_output_node\":\"Output-To-Logstash-5514\",\"message\":\"update\",\"@version\":1,\"first_seen\":\"2016-09-30T13:50:29.164000Z\",\"last_seen\":\"2016-09-30T13:50:34.330000Z\"}","@version":"1","@timestamp":"2016-10-11T15:13:35.693Z","host":"127.0.0.1","port":34402}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However all withdraw messages I receive do not include this field.&lt;/P&gt;&lt;P&gt;Question: are withdraw messages generated when the IOC is removed rom &lt;STRONG&gt;ALL&lt;/STRONG&gt; sources or is a messages generated for &lt;STRONG&gt;each source&lt;/STRONG&gt; individually?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Forseti&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 08:42:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/withdraw-mesage-source/m-p/118966#M99774</guid>
      <dc:creator>Forseti</dc:creator>
      <dc:date>2016-10-12T08:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Withdraw mesage source</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/withdraw-mesage-source/m-p/118969#M99775</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48459"&gt;@Forseti﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;WITHDRAW messages have no body and an aggregator generates a withdraw for an indicator only when all the Miners have withdrawn the indicator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Longer explanation:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let's suppose you have a graph with 2 Miners M1 and M2, connected to an aggregator A, and A is connected to a single output node O. This is how WITHDRAWs work:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;suppose that in the initial state both M1 and M2 have published an indicator I. M1 published I with a set of attributes AM1. M2 published I with a set of attributes AM2. Aggregator A then has published to O the indicator I with a set of attributes (AM1+AM2).&lt;/LI&gt;
&lt;LI&gt;Miner M1 expires indicator I (expiration of indicators depends on the age out configuration in each single Miner, i.e. each Miner can apply a different age out policy) and sends a WITHDRAW of indicator I to aggregator A.&lt;/LI&gt;
&lt;LI&gt;Aggregator A generates an UPDATE message to output O for indicator I with a set of attributes AM2, as AM1 have been removed.&lt;/LI&gt;
&lt;LI&gt;Miner M2 expires indicator I (according to its own age out policy) and sends a WITHDRAW of indicator I to aggregator A.&lt;/LI&gt;
&lt;LI&gt;Aggregator A at this point should remove indicator I because all the original Miners sources of I have withdrawn the indicator. Aggregator A then generates a WITHDRAW message for indicator I to output O.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luigi&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 09:37:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/withdraw-mesage-source/m-p/118969#M99775</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-10-12T09:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Withdraw mesage source</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/withdraw-mesage-source/m-p/118973#M99776</link>
      <description>Perfect answer! Just what I needed to know! Thank you @Imori</description>
      <pubDate>Wed, 12 Oct 2016 10:25:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/withdraw-mesage-source/m-p/118973#M99776</guid>
      <dc:creator>Forseti</dc:creator>
      <dc:date>2016-10-12T10:25:55Z</dc:date>
    </item>
  </channel>
</rss>

