# MISP Configuration issue in Filebeat module

**URL:** <https://discuss.elastic.co/t/misp-configuration-issue-in-filebeat-module/292002>\
**Category:** Elasticsearch\
**Created:** [December 15, 2021, 3:19pm UTC](https://discuss.elastic.co/t/misp-configuration-issue-in-filebeat-module/292002 "2021-12-15T15:19:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tejas.tech](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@tejas.tech](https://discuss.elastic.co/u/tejas.tech)\
**Post date:** [December 15, 2021, 3:19pm UTC](https://discuss.elastic.co/t/misp-configuration-issue-in-filebeat-module/292002/1 "2021-12-15T15:19:16Z")

</div>

Error while processing http request: failed to execute http client.Do: failed to execute http client.Do: Post "[https://127.0.0.1/events/restSearch](https://127.0.0.1/events/restSearch)": POST [https://127.0.0.1/events/restSearch](https://127.0.0.1/events/restSearch) giving up after 6 attempts {"id": "4A96BE5284B83AD6", "input\_source": "[https://127.0.0.1/events/restSearch](https://127.0.0.1/events/restSearch)", "input\_url": "[https://127.0.0.1/events/restSearch](https://127.0.0.1/events/restSearch)"}

````auto
Configuration:

  misp:
    enabled: true

    # Input used for ingesting threat intel data, defaults to JSON.
    var.input: httpjson

    # The URL of the MISP instance, should end with "/events/restSearch".
    var.url: "https://127.0.0.1/events/restSearch"

    # The authentication token used to contact the MISP API. Found when looking at user account in the MISP UI.
    var.api_token: API KEY

    # Configures the type of SSL verification done, if MISP is running on self signed certificates
    # then the certificate would either need to be trusted, or verification_mode set to none.
    var.ssl.verification_mode: none

    # Optional filters that can be applied to the API for filtering out results. This should support the majority of fields in a MISP context.
    # For examples please reference the filebeat module documentation.
    #var.filters:
    # - threat_level: [4, 5]
    # - to_ids: true

    # How far back to look once the beat starts up for the first time, the value has to be in hours. Each request afterwards will filter on any event newer
    # than the last event that was already ingested.
    var.first_interval: 300h

    # The interval to poll the API for updates.
    var.interval: 5m```

MISP and Filebeat are both installed on the same machine. On the MISP dashboard, I am unable to see any data.
Could you please walk me through the entire process, from MISP setting to Filebeat? I'd like to double-check this, and I'll have to fix this problem as well.
Please accept my heartfelt gratitude in advance.
````

---

<div class="post-metadata">

**Author:** ![tejas.tech](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@tejas.tech](https://discuss.elastic.co/u/tejas.tech)\
**Post date:** [December 15, 2021, 3:22pm UTC](https://discuss.elastic.co/t/misp-configuration-issue-in-filebeat-module/292002/2 "2021-12-15T15:22:36Z")

</div>

MISP and Filebeat are both installed on the same machine. On the MISP dashboard, I am unable to see any data.  
Could you please walk me through the entire process, from MISP setting to Filebeat? I'd like to double-check this, and I'll have to fix this problem as well.  
Please accept my heartfelt gratitude in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2022, 3:23pm UTC](https://discuss.elastic.co/t/misp-configuration-issue-in-filebeat-module/292002/3 "2022-01-12T15:23:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
