I'm getting this error while trying to use the misp threat intel module: [input.httpjson-cursor] v2/request.go:186 error processing response: the requested root field is empty {"input_source": "https://X.X.X.X/events/restSearch/", "input_url": "https://X.X.X.X/events/restSearch/"}
Thanks Marius!
I managed to make the misp part work by directly configuring the /etc/filebeat/modules.d/threatintel.yml.disabled and then run filebeat modules enable threatintel . Though, if I use the filtering part, the filebeat service fails to start.
Work in progress...
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.