# Can I still use Threat Intelligence?

**URL:** <https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962>\
**Category:** SIEM\
**Created:** [November 28, 2022, 4:18pm UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962 "2022-11-28T16:18:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![maof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maof97/32/101433_2.png) [@maof97](https://discuss.elastic.co/u/maof97)\
**Post date:** [November 28, 2022, 4:18pm UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962/1 "2022-11-28T16:18:25Z")

</div>

Hello Community,

I just upgraded one of my test machines from 8.1.2 to 8.5.2 and I noticed that there is now a menu in the security section called "Intelligence", but when I click on it it says "Start a free trial or upgrade your license to Enterprise to use threat intelligence.".  
In 8.1.2 I used Threat Intelligence and Rules to monitor my agents for malicious traffic, all with the free license, but it seems that the feature was put behind a paywall now? If yes on which version was that? I couldn't find any mention of it in the change log.  
It was a really nice feature to have and I certainly can't buy an enterprise license without having a company in the first place (using Elastic SIEM it for home/lab monitoring).

Greetings  
Martin

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 28, 2022, 6:56pm UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962/2 "2022-11-28T18:56:02Z")

</div>

Enterprise license? So this would mean it's not available in Platinum anymore too??

---

<div class="post-metadata">

**Author:** ![maof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maof97/32/101433_2.png) [@maof97](https://discuss.elastic.co/u/maof97)\
**Post date:** [November 28, 2022, 8:08pm UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962/3 "2022-11-28T20:08:48Z")

</div>

Seems like that - although I found that my TI container is still fetching TI data and sending it to Elastic. The question is, if the rules still work...

---

<div class="post-metadata">

**Author:** ![Dhrumil\_Patel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhrumil_patel/32/106454_2.png) [@Dhrumil\_Patel](https://discuss.elastic.co/u/Dhrumil_Patel)\
**Post date:** [November 28, 2022, 9:32pm UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962/4 "2022-11-28T21:32:30Z")

</div>

Hello Martin! I want to provide some clarification here.

The rules (indicator match, and others) and any previous threat intelligence capabilities are still available in the free version.

The newly introduced Intelligence section in 8.5 is new functionality. The Intelligence section currently consists of the [Indicators of Compromise (IoC)](https://www.elastic.co/guide/en/security/master/indicators-of-compromise.html) page which provides users with a centralized view of all their threat intelligence IoCs from all activated [Threat Intelligence integrations](https://www.elastic.co/guide/en/security/master/es-threat-intel-integrations.html) making it easier to analyze all TI data in one place, and investigate IoCs in Timeline.

---

<div class="post-metadata">

**Author:** ![maof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maof97/32/101433_2.png) [@maof97](https://discuss.elastic.co/u/maof97)\
**Post date:** [November 28, 2022, 9:43pm UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962/5 "2022-11-28T21:43:33Z")

</div>

Thank you for the explanation. 🙂

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 28, 2022, 10:03pm UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962/6 "2022-11-28T22:03:32Z")

</div>

It would be nice if those difference are more explicit in the documentation.

I know that the [subscription page](https://www.elastic.co/subscriptions) shows what is available in each license level, but sometimes it is not clear what each thing in the subscription page means when looking at Kibana or Elasticsearch features.

We have a Platinum license and we just set up a new cluster with a trial license to do a temporary migration, we saw the Indicator page and were planning to use it, but now seeing that it is only available on Enterprise we will need to build something similar ourselves.

---

<div class="post-metadata">

**Author:** ![maof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maof97/32/101433_2.png) [@maof97](https://discuss.elastic.co/u/maof97)\
**Post date:** [November 29, 2022, 12:06am UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962/7 "2022-11-29T00:06:20Z")

</div>

I guess my naive question has saved you from a potential shock when your companies trial expires 😁

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2022, 12:06am UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962/8 "2022-12-27T00:06:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
