I find myself wanting processor or output nodes to aggregate IPv4 addresses into new ranges and in order. Since some Palo boxes have a limitation of 50K addresses in a Dynamic List Object, it would help a lot to make my outputs fit in there. Especially since I find myself in front of an output that looks like this in some parts:
188.8.131.52-184.108.40.206 220.127.116.11-18.104.22.168 22.214.171.124-126.96.36.199 188.8.131.52-184.108.40.206 220.127.116.11-18.104.22.168 22.214.171.124-126.96.36.199 188.8.131.52-184.108.40.206 220.127.116.11-18.104.22.168 22.214.171.124-126.96.36.199 188.8.131.52-184.108.40.206
It could easily read 220.127.116.11-18.104.22.168... Any way to do this?
Solved! Go to Solution.
current MineMeld implementation can't do that. And I have some concerns about such agrupation. For instance, what the confidence level should be for the agrupated range? The average of the confidence level of its individual contributors?
What about splitting the list based on attribute values? By confidence? By source? etc. This way you could feed the low end devices with a subset of indicators (the most important ones) and the big end devices with the full list.
Thanks for the insight @xhoms ! You make a very valid point, and ultimately I want to do exactly that, but what is a little bit dissapointing for me is that some miners have an average of up to 60K entries... Let's say I was aiming at one of those miners to be an important one? What do I do with the target PAN-OS (only PAN-OS within a PA-5000 series and 7000 series can accept more than 50K IP's, going up to 150K) ?
It's the default alienvault.reputation miner. I don't even know yet if I want to use it, rather than asking myself if it is useful for a miner to have as many entries.
this is what indicator attributes are for. The Alien Vault miner attaches the following valuable attributes to each indicator:
You can create multiple output nodes attached to the same source selecting only the indicators that match a given input filter criteria. For instance, the following graph splits the current +65K indicator list provided by Alien Vault based on the alienvault_risk attribute value.
As you can see, there are only around 500 indicators with risk 4. You might combine the indicators with risk 4 and 5 into a general availability "critical EDL" and only consume the rest in high-end devices.
Example of node prototype to filter Alien Vault indicators based on its risk value.
Super interesting! I had completely overlooked this while reading documentation, thank you very much @xhoms !
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!