# Indicator match rule not matched and Mapped with filebeat-\* (MISP Module)

**URL:** <https://discuss.elastic.co/t/indicator-match-rule-not-matched-and-mapped-with-filebeat-misp-module/266315>\
**Category:** SIEM\
**Created:** [March 5, 2021, 5:17am UTC](https://discuss.elastic.co/t/indicator-match-rule-not-matched-and-mapped-with-filebeat-misp-module/266315 "2021-03-05T05:17:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![raviraja](https://avatars.discourse-cdn.com/v4/letter/r/5daacb/32.png) [@raviraja](https://discuss.elastic.co/u/raviraja)\
**Post date:** [March 5, 2021, 5:17am UTC](https://discuss.elastic.co/t/indicator-match-rule-not-matched-and-mapped-with-filebeat-misp-module/266315/1 "2021-03-05T05:17:50Z")

</div>

Hi guys,

We are using ELK 7.11.1 version.

We have ingested threat intelligence feeds from MISP server and stored in Elasticsearch through Filebeat.(Using Module MISP) and we want to map and match with Zscalerlog.

Based on the above condition, we have created **indicator match** rule.

The following way we had tested.

1. I took one malicious URL from MISP server attribute lists and get it browsed via browser ([http://ww.gzcfr5axf6.com/](http://ww.gzcfr5axf6.com/)) , In the filebeat-\*-MISP indices : misp.threat\_indicator.attack\_pattern\_kql and from kibana discover it is shown as misp.threat\_indicator.attack\_pattern\_kql: source.domain: "[ww.gzcfr5axf6.com](http://ww.gzcfr5axf6.com)" OR destination.domain: "[ww.gzcfr5axf6.com](http://ww.gzcfr5axf6.com)".
2. In the zscalerlog indice , url.destination shown as url.destination: [http://ww.gzcfr5axf6.com/](http://ww.gzcfr5axf6.com/) where by this results will be shown once we accessed to it via web browser.

`we have many times tested, but the results didn't match with filebeat-*-MISP and also we got alerts but incorrect results, it is only show first 100 Zscalerlog record without match and map with Filebeat-*-MISP, the rule run every 5 minutes scheduling .`

Please see our rule:-  
 ![Rule1](https://us1.discourse-cdn.com/elastic/original/3X/d/f/dfa45ef1f6aa2e003b55005dd59f54ee8e85427c.jpeg)

Please see our result:-

 ![Rule2](https://us1.discourse-cdn.com/elastic/original/3X/7/9/797926dff994d4448118c88b0755b8a7d11f5c6d.jpeg)

Notes:-

1. Filebeat-\*- MISP don't have duplicate records.
2. Filebeat-\*- MISP current total records is 600k
3. ZscalerLog is real-time logs.
4. ZscalerLog, each 10 minutes once will receive 3k records.

Can you help me?

Thanks.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [March 5, 2021, 10:01pm UTC](https://discuss.elastic.co/t/indicator-match-rule-not-matched-and-mapped-with-filebeat-misp-module/266315/2 "2021-03-05T22:01:05Z")

</div>

We try not to flood the system, so it stops at the first 100 matches.

Your indicator mapping is:

```auto
url.destination MATCHES misp.threat_indicator.attack_pattern_kql

```

What it will do is take the `misp.threat_indicator.attack_pattern_kql` and match them against your source index pattern which would be `url.destination`.

In your rows in your screenshot if you added the column of `url.destination` that will show you what which `url.destination` it matched against as those rows are a copy of the data it matched against in the red blocked out index you have in your screen shot.

It looks like `misp.threat_indicator.attack_pattern_kql` from your data set is KQL strings? Is that strings such as `source.domain: "ww.gzcfr5axf6.com" OR destination.domain: "ww.gzcfr5axf6.com".`?

You will want to try out matching with `misp.threat_indicator.attack_pattern` instead. The matching does not take a KQL string but rather data directly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2021, 10:01pm UTC](https://discuss.elastic.co/t/indicator-match-rule-not-matched-and-mapped-with-filebeat-misp-module/266315/3 "2021-04-02T22:01:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
