# Filebeat misp module

**URL:** <https://discuss.elastic.co/t/filebeat-misp-module/267843>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 19, 2021, 5:32pm UTC](https://discuss.elastic.co/t/filebeat-misp-module/267843 "2021-03-19T17:32:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles100](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charles100/32/82544_2.png) [@Charles100](https://discuss.elastic.co/u/Charles100)\
**Post date:** [March 19, 2021, 5:32pm UTC](https://discuss.elastic.co/t/filebeat-misp-module/267843/1 "2021-03-19T17:32:41Z")

</div>

Hi, I'm playing the filebeat MISP module and getting this error when starting filebeat : : ERROR fileset/factory.go:97 Error creating input: (assert) value of type 'string' not convertible into unsupported go type 'tlscommon.Config' accessing 'request.ssl'

This error seems related to this option in misp.yml:

```auto
var.ssl: |-
     {
       verification_mode: none
     }

```

If I commented this, filebeat is saying that the certificate is not trusted but thats normal (it's a self-signed). Any idea how to use a misp self-signed certificate with filebeat ?

Thx

---

<div class="post-metadata">

**Author:** ![Charles100](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charles100/32/82544_2.png) [@Charles100](https://discuss.elastic.co/u/Charles100)\
**Post date:** [March 19, 2021, 5:56pm UTC](https://discuss.elastic.co/t/filebeat-misp-module/267843/2 "2021-03-19T17:56:47Z")

</div>

Oh, I just found that there's a new filebeat module called "Threath intel" where there's a mips mention:

- `misp` : Supports gathering threat intel attributes from MISP (replaces MISP module).

So I guess I should use that module instead

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [March 22, 2021, 1:09am UTC](https://discuss.elastic.co/t/filebeat-misp-module/267843/3 "2021-03-22T01:09:16Z")

</div>

Hi Charles,

I think what you are referring to in your last comment is this documentation page:

> **[Threat Intel module | Filebeat Reference \[7.12\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.12/filebeat-module-threatintel.html#_misp_fileset_settings)**

However the issue is this will be rolled out in 7.12 which is not live until now.  
In the current 7.11 you still have to use MISP module:

> **[MISP module | Filebeat Reference \[7.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.11/filebeat-module-misp.html)**

So the question here would rather be possible that the yaml identation is wrong and additionally why using the json syntax for this singular setting?  
So I would set it up in misp.yml like this one:

```auto
- module: misp
  threat:
    enabled: true
    var.api_key: xxxx
    var.http_request_body.limit: 1000
    var.url: xxxx
    var.ssl.verification_mode: none 

```

Can you give this a shot?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 1:09am UTC](https://discuss.elastic.co/t/filebeat-misp-module/267843/4 "2021-04-19T01:09:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
