I noticed that when creating the '_process_item' code for a new miner, you generate data as an indicator, and a value. I am able to generate an EDL with my code, but it looks like the values associated with the indicators are not present.
Does anybody know what types of feeds you would need to create to see the values associated with their corresponding indicators?
sorry for the late reply, you can click on LOGS in the top right corner of the Miner window to see all the indicators/values generatred by the Miner. See screenshots below.
To see the value in the feed you should:
hi @lmori - thanks for your reply..
So I am using a prototype with name "stdlib.feedHCRedWithValue PROTOTYPE"
As for the URL to download the feed, are you saying it would look like the following :
(I'm sure that's not it as I get an 'Unknown feed' message...)
hi @lmori -
thanks - works great.
Ingesting this data into a Palo Alto device, I'm assuming the only way is via an EDL, and that would just be the standard/generic feed input (i.e., '<ip address start>-<ip address end>') Is that correct?
for ingesting with Palo Alto Networks NGFW you can use EDL format ("plain") or DAG output nodes.
EDL can be used for IPs (/32, ranges and CIDRs), URLs and domains.
DAG output node only for /32 IPs.
My suggestion for traditional feeds is using EDLs.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!