# Filebeat ThreatIntel MISP Module

**URL:** https://discuss.elastic.co/t/filebeat-threatintel-misp-module/274019
**Category:** Beats
**Tags:** filebeat
**Created:** [May 26, 2021, 7:21am UTC](https://discuss.elastic.co/t/filebeat-threatintel-misp-module/274019 "2021-05-26T07:21:02Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![AndreiRD](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)
#### Post date: [May 26, 2021, 7:21am UTC](https://discuss.elastic.co/t/filebeat-threatintel-misp-module/274019/1 "2021-05-26T07:21:02Z")

</div>

Hi,

I'm getting this error while trying to use the misp threat intel module:  
` [input.httpjson-cursor] v2/request.go:186 error processing response: the requested root field is empty {"input_source": "https://X.X.X.X/events/restSearch/", "input_url": "https://X.X.X.X/events/restSearch/"}`

This is the config in filebeat.yml:

```auto
filebeat.modules:
    - module: threatintel
  abuseurl.enabled: false
  abusemalware.enabled: false
  malwarebazaar.enabled: false
  anomali.enabled: false
  otx.enabled: false
  misp:
    enabled: true
    var.input: httpjson
    var.url: "https://X.X.X.X/events/restSearch"
    var.api_token: APIKEY
    var.ssl.verification_mode: none
    var.filters:
      - type: ["md5", "sha256", "url", "ip-src", "ip-dst", "domain"]
    var.first_interval: 72h
    var.interval: 60m

```

Any idea what causes it?

---

<div class="post-metadata">

### Author: ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)
#### Post date: [May 26, 2021, 8:55pm UTC](https://discuss.elastic.co/t/filebeat-threatintel-misp-module/274019/2 "2021-05-26T20:55:59Z")

</div>

Hello @AndreiRD . I added an answer to a similar question here, hope this helps! 🙂

> [@Threatintel anomali error: the requested root field is empty](https://discuss.elastic.co/t/threatintel-anomali-error-the-requested-root-field-is-empty/270841):
>
> Hi, I gave the threatintel module a try. Successfully ingesting abuseurl, abusemalware and otx. I've a problem with getting anomali to work. First I figured, I have to uncomment the username/password fields to send default guest credentials. But then I get: Apr 21 12:14:47 ingester filebeat[29141]: 2021-04-21T12:14:47.524Z#011INFO#011[input.httpjson-cursor]#011v2/input.go:145#011Input stopped because context was cancelled with: context canceled#011{"input\_source": "https://limo.anomali.com/…

---

<div class="post-metadata">

### Author: ![AndreiRD](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)
#### Post date: [May 28, 2021, 7:24am UTC](https://discuss.elastic.co/t/filebeat-threatintel-misp-module/274019/3 "2021-05-28T07:24:32Z")

</div>

Thanks Marius!  
I managed to make the misp part work by directly configuring the `/etc/filebeat/modules.d/threatintel.yml.disabled` and then run `filebeat modules enable threatintel` . Though, if I use the filtering part, the filebeat service fails to start.  
Work in progress...

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 25, 2021, 9:25am UTC](https://discuss.elastic.co/t/filebeat-threatintel-misp-module/274019/4 "2021-06-25T09:25:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
