# Filebeats Threat Intel Module integration with Logstash

**URL:** <https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 16, 2023, 12:28pm UTC](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735 "2023-02-16T12:28:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![viera120](https://avatars.discourse-cdn.com/v4/letter/v/74df32/32.png) [@viera120](https://discuss.elastic.co/u/viera120)\
**Post date:** [February 16, 2023, 12:28pm UTC](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735/1 "2023-02-16T12:28:32Z")

</div>

Hi,

I have the following self hosted setup on ELK stack 8.6.1 :

`Firewall (logs) --> Filebeat --> Logstash --> Elasticsearch Cluster`

I am trying to integrate FIleBeats Threat Intel Module into this setup so that IOCs in logs can be identified.

Can this be done using the existing Filebeat instance or does it require a separate dedicate instance of Filebeat?

The present filebeat.yml has output enabled for logstash:

```auto

output.logstash:
  hosts: ["192.168.1.1:5144"]

```

I am assuming that to integrate Threat Intel data, the threat feed would be sent directly to Elasticsearch whereas the Firewall logs would reach Elasticsearch via Logstash. This is because the logs are being enriched/filtered using logstash filters.

In Filebeat.yml, if we enable Elasticsearch output in addition to the existing Logstash output so as to send Threat intel feed to Elasticsearch, how will filebeat decide which data (logs, threat intel) goes where?

I have tried following the [official documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-threatintel.html). However, I am not able to figure out how the Threat Intel feed can be integrated into the existing setup.

What could i possibly be missing here?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 16, 2023, 12:40pm UTC](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735/2 "2023-02-16T12:40:46Z")

</div>

Filebeat modules relies on ingest pipelines that are executed by Elasticsearch, but Filebeat only supports one output.

If your filebeat is sending data to logstash you still can use the modules, but you need to [follow this documentation](https://www.elastic.co/guide/en/logstash/current/use-ingest-pipelines.html) to configure it.

Basically you will tell logstash which ingest pipeline to use when sending the data to Elasticsearch.

Since you are also collecting Firewall logs, you will need conditionals in your logstash pipeline to tell logstash that your filters should be applied only to logs from your firewall, you can do that adding tags to the firewall input for example.

Another option that will need less work is to run a separate instance of Filebeat.

---

<div class="post-metadata">

**Author:** ![viera120](https://avatars.discourse-cdn.com/v4/letter/v/74df32/32.png) [@viera120](https://discuss.elastic.co/u/viera120)\
**Post date:** [February 17, 2023, 12:53pm UTC](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735/3 "2023-02-17T12:53:44Z")

</div>

Thank you. Will try both options and post back!

Thanks again!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2023, 2:54pm UTC](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735/4 "2023-03-17T14:54:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
