# Built-in CEL within Custom Threat Intelligence Integration

**URL:** <https://discuss.elastic.co/t/built-in-cel-within-custom-threat-intelligence-integration/373945>\
**Category:** Endpoint Security\
**Created:** [January 31, 2025, 2:08pm UTC](https://discuss.elastic.co/t/built-in-cel-within-custom-threat-intelligence-integration/373945 "2025-01-31T14:08:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akodo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akodo/32/141073_2.png) [@Akodo](https://discuss.elastic.co/u/Akodo)\
**Post date:** [January 31, 2025, 2:08pm UTC](https://discuss.elastic.co/t/built-in-cel-within-custom-threat-intelligence-integration/373945/1 "2025-01-31T14:08:11Z")

</div>

Morning. I found this integration in pre-release, Custom Threat Intelligence, and it fits perfect into our TI feed for hashes with a Trend Micro server we have. But I'm running into an issue, where I'm getting a CEL error:

failed eval: ERROR: :32:22: no such key: objects  
| ).do\_request().as(resp, (resp.StatusCode == 200 || resp.StatusCode == 206) ?  
| .....................^,  
Processor "conditional" with tag "" in pipeline "logs-ti\_custom.indicator-0.6.0" failed with message "Error during CEL program evaluation"

User **[efd6](https://github.com/efd6)** told me that this would be better placed here. He also stated: " From the error you have posted, you are likely using the built-in CEL program. What is happening is that the document being returned by the API endpoint does not contain a field "objects", which the program expects (you can see that [here](https://github.com/elastic/integrations/blob/661a312c6be43b2d0fe81789c42b7cda0ac0b117/packages/ti_custom/data_stream/indicator/agent/stream/cel.yml.hbs#L98))."

If anyone has had this issue with this integration, it would be greatly appreciated for your help.

---

<div class="post-metadata">

**Author:** ![chemamartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chemamartinez/32/124508_2.png) [@chemamartinez](https://discuss.elastic.co/u/chemamartinez)\
**Post date:** [January 31, 2025, 4:44pm UTC](https://discuss.elastic.co/t/built-in-cel-within-custom-threat-intelligence-integration/373945/2 "2025-01-31T16:44:41Z")

</div>

Hi @Akodo,

That's right. The built-in CEL program in that integration is designed to support TI feeds compatible with the TAXII protocol. Servers that follow that protocol should send indicators inside the `objects` field, and it seems that the feed server you are targeting to doesn't follow that specification.

I recommend you verify that point, and in case it doesn't support TAXII, you need to disable the option `Enable TAXII 2.1` in the integration configuration, as well as add a custom CEL program that meets the feed server specifications.

You can read this [blogpost](https://www.elastic.co/blog/custom-threat-intelligence-integration) and the [integration docs](https://www.elastic.co/blog/custom-threat-intelligence-integration) where this process is more detailed.

Please reach out if you have further questions or need some assistance with the setup, and we'll be happy to help.

---

<div class="post-metadata">

**Author:** ![Akodo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akodo/32/141073_2.png) [@Akodo](https://discuss.elastic.co/u/Akodo)\
**Post date:** [January 31, 2025, 5:07pm UTC](https://discuss.elastic.co/t/built-in-cel-within-custom-threat-intelligence-integration/373945/3 "2025-01-31T17:07:05Z")

</div>

First, thank you for the response. I'll look into what you've said and sent. Second, if I have any issues, I'll get back to you, and hopefully you can help! Thank you again!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2025, 5:07pm UTC](https://discuss.elastic.co/t/built-in-cel-within-custom-threat-intelligence-integration/373945/4 "2025-02-28T17:07:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
