Reply
Highlighted
L0 Member
Posts: 2
Registered: ‎07-10-2017

What MM version is support currently recommending fo PAN OS 8.x.x version

Currently there is a project to upgrade all Palo Alto's to a 8.x.x platform.

What MM version is support currently recommending fo PAN OS 8.x.x version?

Also need to consider Active directory integration as an option within the upgraded design. How we can acheive this?

 

L3 Networker
Posts: 84
Registered: ‎02-13-2015

Re: What MM version is support currently recommending fo PAN OS 8.x.x version

Hi @JeelaniGh

 

I am not working for PAN, so I can't vouch for the recommendation, but at our company we have been using minemeld successfully since summer 2017, and just now starting to use minemeld together with other software stacks, like a SIEM and graylog.

L0 Member
Posts: 2
Registered: ‎07-10-2017

Re: What MM version is support currently recommending fo PAN OS 8.x.x version

Thanks for reply, looking some suggestions from other folks here...

L1 Bithead
Posts: 10
Registered: ‎12-11-2017

Re: What MM version is support currently recommending fo PAN OS 8.x.x version

Hello @borising_,

Just wondering, what are you doing exactly with Graylog? Trying to find a good solution to monitor feeds and analyze them.

Thanks :) 

L3 Networker
Posts: 84
Registered: ‎02-13-2015

Re: What MM version is support currently recommending fo PAN OS 8.x.x version

Hi @michael.gabriel,

 

We were looking into this article:

https://live.paloaltonetworks.com/t5/MineMeld-Articles/Correlating-PAN-OS-syslog-with-indicators/ta-...

 

And thought of using graylog for the receiving end, as this was a system we already use internally, nothing more special in that :)

 

Though I am having some issues getting it to work, as there are no correlations being sent out, so haven't looked more into it the last couple of months.

L1 Bithead
Posts: 10
Registered: ‎12-11-2017

Re: What MM version is support currently recommending fo PAN OS 8.x.x version

Very interesting @borising_

I actually wound up doing something very similar to this by using MM and Splunk Free. MM sends LogStash info to Splunk, and NGFW sends syslogs to Splunk. Works pretty well! Here are the MM apps for Splunk:

 

https://github.com/gmellini/minemeld-analysis/ 

https://github.com/gmellini/TA-custom-minemeld_ioc 

 

And for the NGFW syslog parsing, the PAN plugins for Splunk work perfectly.  

 

 

L3 Networker
Posts: 84
Registered: ‎02-13-2015

Re: What MM version is support currently recommending fo PAN OS 8.x.x version

Hi @michael.gabriel

 

That´s perfect! I was just looking at the same setup for my home lab, will try it out! Thank you for joining in with your valuable feedback, much appreciated!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!