# Filebeat Threat Intel module, multiple Anomali filesets

**URL:** <https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 21, 2022, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761 "2022-02-21T13:25:51Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rob3](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@Rob3](https://discuss.elastic.co/u/Rob3)\
**Post date:** [February 21, 2022, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/1 "2022-02-21T13:25:51Z")

</div>

How can multiple Anomali filsets be enabled?

For example, if I want to enable both collections 135 and 136 as per below, seems that the last read wins and only collection 136 will be configured.

Is this possible? Can't find anything in the documentation.

```auto
        anomali:
          enabled: true
          var.input: httpjson
          var.url: https://limo.anomali.com/api/v1/taxii2/feeds/collections/135/objects?match[type]=indicator
          var.username: guest
          var.password: guest
          var.interval: 60m
        anomali:
          enabled: true
          var.input: httpjson
          var.url: https://limo.anomali.com/api/v1/taxii2/feeds/collections/136/objects?match[type]=indicator
          var.username: guest
          var.password: guest
          var.interval: 60m

```

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [February 21, 2022, 2:51pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/2 "2022-02-21T14:51:29Z")

</div>

You'll need multiple Threatintel modules such as below. You can put this in the threatintel.yml file I also recommend adding the other filesets to disable them.

```auto
- module: threatintel
  anomali:
          enabled: true
          var.input: httpjson
          var.url: https://limo.anomali.com/api/v1/taxii2/feeds/collections/135/objects?match[type]=indicator
          var.username: guest
          var.password: guest
          var.interval: 60m
- module: threatintel
  anomali:
          enabled: true
          var.input: httpjson
          var.url: https://limo.anomali.com/api/v1/taxii2/feeds/collections/136/objects?match[type]=indicator
          var.username: guest
          var.password: guest
          var.interval: 60m

```

---

<div class="post-metadata">

**Author:** ![Rob3](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@Rob3](https://discuss.elastic.co/u/Rob3)\
**Post date:** [February 21, 2022, 2:55pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/3 "2022-02-21T14:55:53Z")

</div>

Interesting. Will try this, though I believe I already had, and observed the same behaivour.

I did find some documention of a sort, in the blog post:

> **[Ingesting threat data with the Threat Intel Filebeat module](https://www.elastic.co/blog/ingesting-threat-data-with-threat-intel-filebeat-module)**
>
> In this blog series, we cover how to use the Elastic Stack to integrate threat data indicators identified by other threat research teams into security operations to identify potentially malicious endpoint and network events.

Multiple threatintel modules are not specified in that.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [February 21, 2022, 2:58pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/4 "2022-02-21T14:58:09Z")

</div>

U definitely need the multiple modules as having a dictionary with duplicate keys will just overwrite first with the second.

---

<div class="post-metadata">

**Author:** ![Rob3](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@Rob3](https://discuss.elastic.co/u/Rob3)\
**Post date:** [February 21, 2022, 3:00pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/5 "2022-02-21T15:00:52Z")

</div>

> [@legoguy1000](#):
>
> U definitely need the multiple modules as having a dictionary with duplicate keys will just overwrite first with the second.

Thats exactly what looks like is happening. Unfortunately it seems to happen with multiple threatintel modules as well. Given the below configs, I only ever see collection 136 in the logs.

```auto
      - module: threatintel
        anomali:
          enabled: true
          var.input: httpjson
          var.url: https://limo.anomali.com/api/v1/taxii2/feeds/collections/135/objects
          var.username: guest
          var.password: guest
          var.interval: 60m
      - module: threatintel
        anomali:
          enabled: true
          var.input: httpjson
          var.url: https://limo.anomali.com/api/v1/taxii2/feeds/collections/136/objects
          var.username: guest
          var.password: guest
          var.interval: 60m

```

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [February 21, 2022, 3:13pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/6 "2022-02-21T15:13:43Z")

</div>

Where are u defining this config? In the filebeat.yml or the the threatintel.yml? There was a bug that was just fixed when defining duplicate modules in the filebeat.yml that caused what you're seeing. Try in the threatintel.yml

---

<div class="post-metadata">

**Author:** ![Rob3](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@Rob3](https://discuss.elastic.co/u/Rob3)\
**Post date:** [February 21, 2022, 5:04pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/7 "2022-02-21T17:04:56Z")

</div>

> [@legoguy1000](#):
>
> Where are u defining this config? In the filebeat.yml or the the threatintel.yml? There was a bug that was just fixed when defining duplicate modules in the filebeat.yml that caused what you're seeing. Try in the threatintel.yml

Thanks! That sounds like it will be the issue. This is a deployment into kubernetes and the helm chart defines the configs in filebeat.yml.

Got a link to the bug issue handy?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [February 21, 2022, 5:20pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/8 "2022-02-21T17:20:15Z")

</div>

[[Filebeat] Fix multiple modules in filebeat.yml by legoguy1000 · Pull Request #29952 · elastic/beats · GitHub](https://github.com/elastic/beats/pull/29952) is the PR that fixed it. I think it will be in 8.1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2022, 7:20pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-module-multiple-anomali-filesets/297761/9 "2022-03-21T19:20:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
