<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom IOC Feed Validations - CSV   (R81.10 verse R8.120) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221713#M36972</link>
    <description>&lt;UL&gt;
&lt;LI&gt;Feed was added in via Smartconsole and same feeds since install of firewalls (I.e the ones we have on R81.20 were all net new installs; combo of cloudguard and cluster HW sites.&lt;/LI&gt;
&lt;LI&gt;For my feed, its fetched from an internal web server from a txt file that is shared by various sources.&amp;nbsp; &amp;nbsp;Therefore our parameters for the Feed Parsing:
&lt;UL&gt;
&lt;LI&gt;Format:&amp;nbsp; Custom CSV&lt;/LI&gt;
&lt;LI&gt;Data Type: IP Address&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Data Column: 1&lt;/LI&gt;
&lt;LI&gt;Delimiter: Space&lt;/LI&gt;
&lt;LI&gt;Ignore lines with prefix: Hash (#)&lt;/LI&gt;
&lt;LI&gt;Type Column: 0&lt;/LI&gt;
&lt;LI&gt;Nothing under additional columns; All zeros&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Also note we have a domain based one with these settings:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Format:&amp;nbsp; Custom CSV&lt;/LI&gt;
&lt;LI&gt;Data Type: Domain&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Data Column: 1&lt;/LI&gt;
&lt;LI&gt;Delimiter: Space&lt;/LI&gt;
&lt;LI&gt;Ignore lines with prefix: Hash (#)&lt;/LI&gt;
&lt;LI&gt;Type Column: 0&lt;/LI&gt;
&lt;LI&gt;Nothing under additional columns; All zeros&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in this case&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, I think your example and mine are different due to the use of the custom CSV verses STIX.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jul 2024 16:57:27 GMT</pubDate>
    <dc:creator>Scottc98</dc:creator>
    <dc:date>2024-07-23T16:57:27Z</dc:date>
    <item>
      <title>Custom IOC Feed Validations - CSV   (R81.10 verse R8.120)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221629#M36957</link>
      <description>&lt;P&gt;Does anyone know if there is any difference between validating the IOC feed entries between R81.10 and R81.20?&lt;/P&gt;
&lt;P&gt;On our R81.10 locations, we would cat the following files and it would output all of the observables.&lt;/P&gt;
&lt;P&gt;Name of example feed "Test_Block_IP"&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;cat /opt/CPsuite-R81.10/fw1/external_ioc/Test_Block_IP/Test_Block_IP_https_custom.csv&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In R81.20, the same csv file is present but blank.&amp;nbsp; (Only change being the "CPsuite-R81.20" directory).&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;cat /opt/CPsuite-R81.20/fw1/external_ioc/Test_Block_IP/Test_Block_IP_https_custom.csv&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In both cases, the Smartconsole logs show success with&amp;nbsp;"External IOC - Fetch succeeded"&amp;nbsp; messages.&lt;/P&gt;
&lt;P&gt;What is the user experience for R81.20 users?&amp;nbsp; &amp;nbsp;Are yours blank or there are just another location to see these now?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance:)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 19:22:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221629#M36957</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2024-07-22T19:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feed Validations - CSV   (R81.10 verse R8.120)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221631#M36958</link>
      <description>&lt;P&gt;Anything in here?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$FWDIR/log/ioc_feeder.elg search for failed or ERROR&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Did you try to remove the feed and create it again? You added it via SmartConsole or CLI?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 19:37:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221631#M36958</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-22T19:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feed Validations - CSV   (R81.10 verse R8.120)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221646#M36961</link>
      <description>&lt;P&gt;Will test it in the lab Tuesday and let you know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 02:49:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221646#M36961</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-23T02:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feed Validations - CSV   (R81.10 verse R8.120)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221649#M36962</link>
      <description>&lt;P&gt;With the file, I get the same. If I use actual feed, this is what I see.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# pwd&lt;BR /&gt;/opt/CPsuite-R81.20/fw1/external_ioc/emerging_threats&lt;BR /&gt;[Expert@CP-GW:0]# ls&lt;BR /&gt;emerging_threats.is_slow_path emerging_threats_https.err&lt;BR /&gt;emerging_threats_https emerging_threats_https_version&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26940iECC12DA6FDABA13D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 03:08:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221649#M36962</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-23T03:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feed Validations - CSV   (R81.10 verse R8.120)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221713#M36972</link>
      <description>&lt;UL&gt;
&lt;LI&gt;Feed was added in via Smartconsole and same feeds since install of firewalls (I.e the ones we have on R81.20 were all net new installs; combo of cloudguard and cluster HW sites.&lt;/LI&gt;
&lt;LI&gt;For my feed, its fetched from an internal web server from a txt file that is shared by various sources.&amp;nbsp; &amp;nbsp;Therefore our parameters for the Feed Parsing:
&lt;UL&gt;
&lt;LI&gt;Format:&amp;nbsp; Custom CSV&lt;/LI&gt;
&lt;LI&gt;Data Type: IP Address&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Data Column: 1&lt;/LI&gt;
&lt;LI&gt;Delimiter: Space&lt;/LI&gt;
&lt;LI&gt;Ignore lines with prefix: Hash (#)&lt;/LI&gt;
&lt;LI&gt;Type Column: 0&lt;/LI&gt;
&lt;LI&gt;Nothing under additional columns; All zeros&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Also note we have a domain based one with these settings:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Format:&amp;nbsp; Custom CSV&lt;/LI&gt;
&lt;LI&gt;Data Type: Domain&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Data Column: 1&lt;/LI&gt;
&lt;LI&gt;Delimiter: Space&lt;/LI&gt;
&lt;LI&gt;Ignore lines with prefix: Hash (#)&lt;/LI&gt;
&lt;LI&gt;Type Column: 0&lt;/LI&gt;
&lt;LI&gt;Nothing under additional columns; All zeros&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in this case&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, I think your example and mine are different due to the use of the custom CSV verses STIX.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 16:57:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221713#M36972</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2024-07-23T16:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feed Validations - CSV   (R81.10 verse R8.120)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221714#M36973</link>
      <description>&lt;P&gt;Totally ommited that...Homer Simpson moment...DOH lol&lt;/P&gt;
&lt;P&gt;Anyway, I see what you mean&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28302"&gt;@Scottc98&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is what I see now.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# ls&lt;BR /&gt;emerging_threats.is_slow_path emerging_threats_https_custom.csv&lt;BR /&gt;emerging_threats_https emerging_threats_https_custom.csv.err&lt;BR /&gt;emerging_threats_https.old emerging_threats_https_version&lt;BR /&gt;[Expert@CP-GW:0]# more emerging_threats_https_custom.csv&lt;BR /&gt;[Expert@CP-GW:0]# pwd&lt;BR /&gt;/opt/CPsuite-R81.20/fw1/external_ioc/emerging_threats&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 17:06:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221714#M36973</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-23T17:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feed Validations - CSV   (R81.10 verse R8.120)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221736#M36976</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;So that looks like an issue with R81.20 then in regards to validations.&amp;nbsp; &amp;nbsp;You can 'cat' the CSV in R81.10 to view the entries but can't in R81.20&amp;nbsp; &amp;nbsp;(for note, I have tried on gWs running Take 41, T53 and T65 with same results).&lt;/P&gt;
&lt;P&gt;Is this a bug here Checkpoint or is there something new process to get this data?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 21:48:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221736#M36976</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2024-07-23T21:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feed Validations - CSV   (R81.10 verse R8.120)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221737#M36977</link>
      <description>&lt;P&gt;Not sure, maybe. Device I ran it on is R81.20 jumbo 76 (newest one, not even a week old)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# cat /opt/CPsuite-R81.20/fw1/external_ioc/emerging_threats/emerging_threats_https_custom.csv&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 21:54:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-IOC-Feed-Validations-CSV-R81-10-verse-R8-120/m-p/221737#M36977</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-23T21:54:05Z</dc:date>
    </item>
  </channel>
</rss>

