# How to use filebeat for pushing misp feeds

**URL:** <https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 28, 2021, 6:50am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293 "2021-05-28T06:50:27Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Drupad\_Soni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drupad_soni/32/89388_2.png) [@Drupad\_Soni](https://discuss.elastic.co/u/Drupad_Soni)\
**Post date:** [May 28, 2021, 6:50am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293/1 "2021-05-28T06:50:27Z")

</div>

Hi Community,

I have been working on MISP and Elasticsearch. I have tried with MISP module and Threatintel module. No feeds are getting pushed in ELK. Please guide/

---

<div class="post-metadata">

**Author:** ![Drupad\_Soni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drupad_soni/32/89388_2.png) [@Drupad\_Soni](https://discuss.elastic.co/u/Drupad_Soni)\
**Post date:** [May 31, 2021, 9:56am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293/2 "2021-05-31T09:56:33Z")

</div>

Hi Community,

I have configured threatintel module in filebeat. Now I am looking at yellow health of filebeat in kibana please guide.

sharing image for reference

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dcdb5862af3346d176d6657d7462b7ce53bfcbb0.png)

Also googled solutions for this. It says about clusters I am not sure about how to resolve this

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 31, 2021, 12:43pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293/3 "2021-05-31T12:43:34Z")

</div>

What's the breakdown of your cluster? It could be something minor like the replicas and primary shards are on the same host, replicas aren't allocated... This article is a simple read on index health, [Elasticsearch Index Red / Yellow — Why? | by Steve Mushero | Medium](https://steve-mushero.medium.com/elasticsearch-index-red-yellow-why-1c4a4a0256ca).

---

<div class="post-metadata">

**Author:** ![Drupad\_Soni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drupad_soni/32/89388_2.png) [@Drupad\_Soni](https://discuss.elastic.co/u/Drupad_Soni)\
**Post date:** [June 21, 2021, 10:47am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293/4 "2021-06-21T10:47:07Z")

</div>

## root@testmispelk:/# service elasticsearch start Job for elasticsearch.service failed because a fatal signal was delivered to the control process. See "systemctl status elasticsearch.service" and "journalctl -xe" for details. root@testmispelk:/# journalctl -xe Jun 21 10:30:29 testmispelk kernel: [3044] 33 3044 620645 554190 4780032 0 0 php Jun 21 10:30:29 testmispelk kernel: [3404] 0 3404 2837 605 61440 0 0 systemctl Jun 21 10:30:29 testmispelk kernel: [3411] 0 3411 5600 882 86016 0 0 systemd-tty-a\> Jun 21 10:30:29 testmispelk kernel: [3412] 129 3412 2407571 1494776 12185600 0 0 java Jun 21 10:30:29 testmispelk kernel: oom-kill:constraint=CONSTRAINT\_NONE,nodemask=(null),cpuset=/,mems\_allowed=0,global\_oo\> Jun 21 10:30:29 testmispelk kernel: Out of memory: Killed process 3412 (java) total-vm:9630284kB, anon-rss:5977164kB, fil\> Jun 21 10:30:29 testmispelk kernel: oom\_reaper: reaped process 3412 (java), now anon-rss:0kB, file-rss:0kB, shmem-rss:0kB Jun 21 10:30:29 testmispelk systemd[1]: elasticsearch.service: Main process exited, code=killed, status=9/KILL -- Subject: Unit process exited -- Defined-By: systemd -- Support: [http://www.ubuntu.com/support](http://www.ubuntu.com/support)

## -- An ExecStart= process belonging to unit elasticsearch.service has exited.

## -- The process' exit code is 'killed' and its exit status is 9. Jun 21 10:30:29 testmispelk systemd[1]: elasticsearch.service: Failed with result 'signal'. -- Subject: Unit failed -- Defined-By: systemd -- Support: [http://www.ubuntu.com/support](http://www.ubuntu.com/support)

## -- The unit elasticsearch.service has entered the 'failed' state with result 'signal'. Jun 21 10:30:29 testmispelk systemd[1]: Failed to start Elasticsearch. -- Subject: A start job for unit elasticsearch.service has failed -- Defined-By: systemd -- Support: [http://www.ubuntu.com/support](http://www.ubuntu.com/support)

## -- A start job for unit elasticsearch.service has finished with a failure.

-- The job identifier is 3122 and the job result is failed.  
Jun 21 10:30:33 testmispelk sshd[3592]: Invalid user admin1 from 218.111.84.99 port 5931  
Jun 21 10:30:34 testmispelk sshd[3592]: pam\_unix(sshd:auth): check pass; user unknown  
Jun 21 10:30:34 testmispelk sshd[3592]: pam\_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser=\>

logs of elasticsearch

---

<div class="post-metadata">

**Author:** ![Drupad\_Soni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drupad_soni/32/89388_2.png) [@Drupad\_Soni](https://discuss.elastic.co/u/Drupad_Soni)\
**Post date:** [June 21, 2021, 10:47am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293/5 "2021-06-21T10:47:35Z")

</div>

## root@testmispelk:/# service elasticsearch start Job for elasticsearch.service failed because a fatal signal was delivered to the control process. See "systemctl status elasticsearch.service" and "journalctl -xe" for details. root@testmispelk:/# journalctl -xe Jun 21 10:30:29 testmispelk kernel: [3044] 33 3044 620645 554190 4780032 0 0 php Jun 21 10:30:29 testmispelk kernel: [3404] 0 3404 2837 605 61440 0 0 systemctl Jun 21 10:30:29 testmispelk kernel: [3411] 0 3411 5600 882 86016 0 0 systemd-tty-a\> Jun 21 10:30:29 testmispelk kernel: [3412] 129 3412 2407571 1494776 12185600 0 0 java Jun 21 10:30:29 testmispelk kernel: oom-kill:constraint=CONSTRAINT\_NONE,nodemask=(null),cpuset=/,mems\_allowed=0,global\_oo\> Jun 21 10:30:29 testmispelk kernel: Out of memory: Killed process 3412 (java) total-vm:9630284kB, anon-rss:5977164kB, fil\> Jun 21 10:30:29 testmispelk kernel: oom\_reaper: reaped process 3412 (java), now anon-rss:0kB, file-rss:0kB, shmem-rss:0kB Jun 21 10:30:29 testmispelk systemd[1]: elasticsearch.service: Main process exited, code=killed, status=9/KILL -- Subject: Unit process exited -- Defined-By: systemd -- Support: [http://www.ubuntu.com/support](http://www.ubuntu.com/support)

## -- An ExecStart= process belonging to unit elasticsearch.service has exited.

## -- The process' exit code is 'killed' and its exit status is 9. Jun 21 10:30:29 testmispelk systemd[1]: elasticsearch.service: Failed with result 'signal'. -- Subject: Unit failed -- Defined-By: systemd -- Support: [http://www.ubuntu.com/support](http://www.ubuntu.com/support)

## -- The unit elasticsearch.service has entered the 'failed' state with result 'signal'. Jun 21 10:30:29 testmispelk systemd[1]: Failed to start Elasticsearch. -- Subject: A start job for unit elasticsearch.service has failed -- Defined-By: systemd -- Support: [http://www.ubuntu.com/support](http://www.ubuntu.com/support)

## -- A start job for unit elasticsearch.service has finished with a failure.

-- The job identifier is 3122 and the job result is failed.  
Jun 21 10:30:33 testmispelk sshd[3592]: Invalid user admin1 from 218.111.84.99 port 5931  
Jun 21 10:30:34 testmispelk sshd[3592]: pam\_unix(sshd:auth): check pass; user unknown  
Jun 21 10:30:34 testmispelk sshd[3592]: pam\_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser=\>

logs of elasticsearch

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [June 21, 2021, 11:02am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293/6 "2021-06-21T11:02:14Z")

</div>

> [@Drupad\_Soni](#):
>
> Jun 21 10:30:29 testmispelk kernel: Out of memory: Killed process 3412 (java) total-vm:9630284kB, anon-rss:5977164kB, fil\>

I'm going to say this is why your service is crashing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2021, 11:02am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-for-pushing-misp-feeds/274293/7 "2021-07-19T11:02:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
