syslog miner - please check rule syntax

Reply
L3 Networker

syslog miner - please check rule syntax

Hi,

 

I just cloned a syslog miner, following the guide here:

 

https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262

 

I can see the syslog processed counter moving, so looks like syslog forwarding is working.  I'm trying to have any source IP that generates a "critical" TID to be added to the MineMeld EDL.  I created the following rule (based on an example on the MineMeld forum):

 

conditions:
- type == 'THREAT'
- severity == 'critical'
- src_zone == 'WAN'
fields: null
indicators:
- src_ip

 

Does this look OK for what I'm trying to accomplish?  And how do I know if the rule is actually hit?  

 

 

Luca
 

edit: oops I just noticed the "hits" column on the Rules page...

L7 Applicator

Re: syslog miner - please check rule syntax

Hi @LucaMarchiori,

looks good to me. Have you tested it already ?

 

I would probably add "log_subtype" and "threat_name" as fields in the rule, to save more context of the original log.

 

Thanks,

luigi

L3 Networker

Re: syslog miner - please check rule syntax

Hi lmori,

 

Do you mean something like this:

 

conditions:
- type == 'THREAT'
- severity == 'critical'
- src_zone == 'WAN'
fields:

  - "log_subtype"

  - "threat_name"
indicators:
- src_ip

 

I had 2 "high" severity and one "critical" events in the threat log since yesterday, and the counter this morning is still at zero hits. 

 

This is the config currently (/opt/minemeld/local/config/syslog-miner_rules.yml):

 

- conditions: [type == 'THREAT', log_subtype == 'vulnerability', severity == 'high',
src_zone == 'WAN']
fields: null
indicators: [src_ip]
name: threats-ALL-high
- conditions: [type == 'THREAT', log_subtype == 'vulnerability', severity == 'critical',
src_zone == 'WAN']
fields: null
indicators: [src_ip]
name: threats-ALL-critical

** edit 2:

 

Got a few pages of "high" severity threat this morning (TID 40007).  No hits on the syslog miner node.

 

 

L7 Applicator

Re: syslog miner - please check rule syntax

Hi @LucaMarchiori,

which PAN-OS version are you running ?

 

Thanks,

luigi

L3 Networker

Re: syslog miner - please check rule syntax

Hi Luigi,

 

I'm using 7.1.11

L3 Networker

Re: syslog miner - please check rule syntax

Hi lmori,

 

Any ideas why the miner node is not getting any hits?  Is there a MineMeld rule help doc that I should be looking at instead?

 

 

Luca

 

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!