TAXII feed for SIEM

Reply
L4 Transporter

Re: TAXII feed for SIEM

@lmori - please find attached minemeld-engine logs.

L1 Bithead

Re: TAXII feed for SIEM

I added the host to the yml file and restarted the engine but I still get:

https://x.x.x.x/taxii-discovery-service

Method Not Allowed

The method is not allowed for the requested URL.

 

I guess while my miner is getting plenty of indicators my aggregtor doesn't except them. I tried both Ipv4 generic and IPv4Outband.

 

Any ideas? Btw: outstanding idea - all other input/outputs work flawless.

Just need to get the taxii service up and running so I can receive STIX and send STIX.

L7 Applicator

Re: TAXII feed for SIEM

Hi franks,

are you using McAfee SIEM ? If yes:

- use https://xxxxxxx/taxii-poll-service instead of https://xxxxxx/taxii-discovery-service

- the error you see it's because the client is sending a GET request instead of a POST, select POST in the feed config

 

If you are not using the McAfee SIEM, could you give us more details about your config ?

 

Note: starting with MineMeld 0.9.20 the change to the yml file is optional.

 

L1 Bithead

Re: TAXII feed for SIEM

Thx for the speedy response. Eventually this should feed in multiple SIEMs. LR, Splunk, custom ELK, AVault ... different groups here use differnt tools :-(. I can't get the aggregator to even receive indicators it seems and for https://xxxxxxx/taxii-poll-service I get the same error as before.  

L7 Applicator

Re: TAXII feed for SIEM

@franks what tool/platform are you using to access MineMeld TAXII data feed ?

 

L1 Bithead

Re: TAXII feed for SIEM

Tried QRadar and Alienvault. No luck. At this point I'd be happy if any of the indicators would show up at the output and not stop at the aggregator. See pic I posted earlier. 

I'm not sure I have the option to feed this in Elasticsearch.

Thanks,

Frank

 

L7 Applicator

Re: TAXII feed for SIEM

@franks Let's start from troubleshooting the config then. Could you open a new thread with a full screenshot of the CONFIG page ? Or could you share the file /opt/minemeld/local/config/running-config.yml ?

 

Thanks,

luigi

L7 Applicator

Re: TAXII feed for SIEM

@franks could you try the latest 0.9.22 ? I have connected it to IBM QRadar TI App via TAXII and I have seen indicators flowing down from MM to QRadar.

L2 Linker

Re: TAXII feed for SIEM

Having the same issue, LogRhythm Threat Intelligence Service for TAXII, using poll or discovery address I get a 400 bad request. MineMeld for Autofocus.

L2 Linker

Re: TAXII feed for SIEM

Using the updated address  "SourceURL": "https://<minemeld server>/taxii-collection-management-service", fixed it

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!