# Msip threat intel import not working

**URL:** <https://discuss.elastic.co/t/msip-threat-intel-import-not-working/283210>\
**Category:** Elastic Security\
**Created:** [September 2, 2021, 6:54pm UTC](https://discuss.elastic.co/t/msip-threat-intel-import-not-working/283210 "2021-09-02T18:54:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [September 2, 2021, 6:54pm UTC](https://discuss.elastic.co/t/msip-threat-intel-import-not-working/283210/1 "2021-09-02T18:54:44Z")

</div>

I've edited the `/etc/filebeat/modules.d/threatintel.yml` and updated the entry for misp to enable it and also to add the API key from my local misp server.

My config looks like this:

```auto
misp:
     enabled: true
     var.input: httpjson
     var.url: https://10.1.2.50/events/restSearch
     var.api_token: ml9wio5eGLGwt32Gl1QNXr0HwLZAcEg1QpAVynBB
     var.ssl.verification_mode: none
     var.first_interval: 30h
     var.interval: 5m

```

The errors I'm seeing in the filebeat journal are:

`ERROR [input.httpjson-cursor] v2/input.go:115 Error while processing http request: failed to execute http client.Do: failed to execute http client.Do: Post "https://10.1.2.50/events/restSearch": POST "https://10.1.2.50/events/restSearch": POST https://10.1.2.50/events/restSearch giving up after 6 attempts {"id": "7C8F59266C173D38", "input_source": "https://10.1.2.50/events/restSearch", "input_url": "https://10.1.2.50/events/restSearch"}`

Which doesn't make much sense to me.  
Is there any config change required on the misp server to allow data to be grabbed?  
I thought presenting a valid API key should be sufficient.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [September 3, 2021, 1:57pm UTC](https://discuss.elastic.co/t/msip-threat-intel-import-not-working/283210/2 "2021-09-03T13:57:43Z")

</div>

What version? Can you post anymore of the logs? It appears that filebeat is having issues connecting to MISP all together.

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [September 5, 2021, 6:05pm UTC](https://discuss.elastic.co/t/msip-threat-intel-import-not-working/283210/3 "2021-09-05T18:05:07Z")

</div>

Hi Alex,  
Version is 7.14.1 - I can post all of the log, but to be fair, it's just this one line repeated over (6 times before it gives up) there's nothing else very helpful there. The threat intel feeds from the default feeds are all importing correctly.

The logfile is pretty long, and very wide - is there a particular bit of the log file that would help?  
I'm happy to email it to you so you can look at it in detail if you like?

Cheers,  
John.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2021, 6:06pm UTC](https://discuss.elastic.co/t/msip-threat-intel-import-not-working/283210/4 "2021-10-03T18:06:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
