# Integration Misp using Filebeat

**URL:** https://discuss.elastic.co/t/integration-misp-using-filebeat/305229
**Category:** Beats
**Tags:** filebeat
**Created:** [May 19, 2022, 7:44pm UTC](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229 "2022-05-19T19:44:26Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![francescouk](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@francescouk](https://discuss.elastic.co/u/francescouk)
#### Post date: [May 19, 2022, 7:44pm UTC](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229/1 "2022-05-19T19:44:26Z")

</div>

Hi there,

I´m trying to integrate MISP using the documentation using filebeat but no go. I´ve tried both (Misp module and Threatintel module) and none of them gets into ELK Stack.

Follow the errors from filebeat journalctl:

```auto
{"log.level":"error","@timestamp":"2022-05-19T16:37:42.021-0300","log.logger":"input.httpjson-cursor","log.origin":{"file.name":"httpjson/request.go","file.line":353},"message":"error processing response: expected map but type is []interface {}","service.name":"filebeat","id":"CAF1EDC614DA8C15","input_source":"https://10.130.0.240/events/restSearch","input_url":"https://XX.XX.XX.XX/events/restSearch","ecs.version":"1.6.0"}

```

Can anyone help me on that?

Thanks for the attention.

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [May 19, 2022, 11:19pm UTC](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229/2 "2022-05-19T23:19:55Z")

</div>

Can u post ur config?

---

<div class="post-metadata">

### Author: ![francescouk](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@francescouk](https://discuss.elastic.co/u/francescouk)
#### Post date: [May 19, 2022, 11:58pm UTC](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229/3 "2022-05-19T23:58:35Z")

</div>

threatintel.yml:

```auto
- module: threatintel
  misp:
    enabled: true
	var.input: httpjson
	var.url: https://XX.XX.XX.XX/attributes/restSearch/last:15m
	var.api_token: REDACTED
    var.ssl.verification_mode: none
	var.interval: 5m

```

---

<div class="post-metadata">

### Author: ![ibra\_013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibra_013/32/104827_2.png) [@ibra\_013](https://discuss.elastic.co/u/ibra_013)
#### Post date: [May 20, 2022, 10:54am UTC](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229/4 "2022-05-20T10:54:53Z")

</div>

Hi @francescouk

in threatintel module [you have to use events not attributes](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-threatintel.html#misp)

> [@francescouk](#):
>
> `var.url: https://XX.XX.XX.XX/attributes/restSearch/last:15m`

```auto

- module: threatintel
  misp:
    enabled: true
    var.input: httpjson
    var.url: https://SERVER/events/restSearch
    var.api_token: xVfaM3DSt8QEwO2J1ix00V4ZHJs14nq5GMsHcK6Z
    var.first_interval: 24h
    var.interval: 60m

```

---

<div class="post-metadata">

### Author: ![francescouk](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@francescouk](https://discuss.elastic.co/u/francescouk)
#### Post date: [May 20, 2022, 12:38pm UTC](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229/5 "2022-05-20T12:38:02Z")

</div>

I´ve tried that also and did not work. Will make the changes again and post the results here. ☹

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 17, 2022, 2:38pm UTC](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229/6 "2022-06-17T14:38:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
