MineMeld Discussions

Reply
Highlighted
L3 Networker
Posts: 70
Registered: ‎04-03-2017

Re: O365 URL rewrite

@lmori

 

Can you reply to this thread once this is updated, or do you suggest we monitor github?  

L2 Linker
Posts: 12
Registered: ‎07-05-2018

Re: O365 URL rewrite

This thread. I do not monitor github.

L2 Linker
Posts: 12
Registered: ‎07-05-2018

Re: O365 URL rewrite

The rewrite rule is not working for top level domains, but it is for subdomains. I would expect to see 

*.skype.com

skype.com

It is working for *.broadcast.skype.com.

 

image.png

L7 Applicator
Posts: 1,036
Registered: ‎03-03-2011

Re: O365 URL rewrite

Hi @ckemp,

just tested this and I can see the doubled entries for skype.com. I am about to release the binary packages for the updates. Which version are you running on?

2019-01-11_11-12-45.png

L2 Linker
Posts: 12
Registered: ‎07-05-2018

Re: O365 URL rewrite

I am on 0.9.52.

 

ubuntu@minemeld:~$ sudo /usr/sbin/minemeld-auto-update
2019-01-11 13:06:45,572 INFO:0.9.11 Current status:
2019-01-11 13:06:45,572 INFO:0.9.11 minemeld-engine: current: 0.9.52 latest: 0.9.52
2019-01-11 13:06:45,573 INFO:0.9.11 minemeld-webui: current: 0.9.52 latest: 0.9.52
2019-01-11 13:06:45,573 INFO:0.9.11 minemeld-prototypes: current: 0.9.52 latest: 0.9.52
2019-01-11 13:06:45,739 DEBUG:0.9.11 curl output:
2019-01-11 13:06:45,773 DEBUG:0.9.11 curl output:
2019-01-11 13:06:45,773 DEBUG:0.9.11 gpgv: /usr/bin/gpgv --ignore-time-conflict --keyring /etc/apt/trusted.gpg --keyring /etc/apt/trusted.gpg.d/minemeld.gpg /tmp/mmaupackagesgpgDWAPvd /tmp/mmaupackagesQUUdhl
2019-01-11 13:06:45,778 INFO:0.9.11 gpgv output: gpgv: Signature made Fri 07 Dec 2018 09:32:50 AM UTC using RSA key ID 7B630999
gpgv: Good signature from "Palo Alto Networks, MineMeld Team <minemeld@paloaltonetworks.com>"
gpgv: aka "[invalid image]"

2019-01-11 13:06:45,783 INFO:0.9.11 No package to deploy, exit
ubuntu@minemeld:~$

L7 Applicator
Posts: 1,036
Registered: ‎03-03-2011

Re: O365 URL rewrite

Hi @ckemp,

you need 0.9.52.post1, not available yet on the binary update channel. I will publish it tomorrow.

 

Luigi

L7 Applicator
Posts: 1,036
Registered: ‎03-03-2011

Re: O365 URL rewrite

@ckemp @Sec101, I have just published the binary package of 0.9.52.post1 to the update channel. This contains the improvement to the output feed to cope with PAN-OS limitation.

L2 Linker
Posts: 12
Registered: ‎07-05-2018

Re: O365 URL rewrite

Updated Minemeld.

image.png

Restart Minemeld engine and force import on PA. Not showing up in EDL.

image.png

 

L7 Applicator
Posts: 1,036
Registered: ‎03-03-2011

Re: O365 URL rewrite

Could you check directly the MineMeld feed with the browser?

 

luigi

L2 Linker
Posts: 12
Registered: ‎07-05-2018

Re: O365 URL rewrite

Pulled the file into Notepad++

image.png

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!