# No threat intelligence data

**URL:** <https://discuss.elastic.co/t/no-threat-intelligence-data/317638>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [October 27, 2022, 6:28pm UTC](https://discuss.elastic.co/t/no-threat-intelligence-data/317638 "2022-10-27T18:28:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigverm23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigverm23/32/112550_2.png) [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Post date:** [October 27, 2022, 6:28pm UTC](https://discuss.elastic.co/t/no-threat-intelligence-data/317638/1 "2022-10-27T18:28:09Z")

</div>

I have installed multiple threatintel modules through my Filebeats collector, enabled them, and can verify I can view the various assets in Elastic.

However the Security - Overview Dashboard still shows "no threat intelligence data"

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/3525548d453f3c5d1db2bfb702d2968a667ffeb0.png)

---

<div class="post-metadata">

**Author:** ![maxcold](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxcold/32/97686_2.png) [@maxcold](https://discuss.elastic.co/u/maxcold)\
**Post date:** [October 31, 2022, 10:07am UTC](https://discuss.elastic.co/t/no-threat-intelligence-data/317638/2 "2022-10-31T10:07:50Z")

</div>

Hi @bigverm23 , the Threat Intelligence part of the Overview Dashboard is currently relying on Elastic Agent TI integrations to be enabled. We will look into making it available when the data is coming from Filebeat instead of Elastic Agent integrations.  
Btw in 8.5, there will be a whole new Intelligence part of the Security Solution available in the Enterprise license [Elastic modernizes security operations by delivering SOAR and automating actionable threat intelligence | Elastic Blog](https://www.elastic.co/blog/oct-2022-launch-elastic-security) which gives a better overview of available Threat Intelligence data

---

<div class="post-metadata">

**Author:** ![maxcold](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxcold/32/97686_2.png) [@maxcold](https://discuss.elastic.co/u/maxcold)\
**Post date:** [October 31, 2022, 10:29am UTC](https://discuss.elastic.co/t/no-threat-intelligence-data/317638/3 "2022-10-31T10:29:00Z")

</div>

Actually, I was wrong in my initial answer. For the data to show up in the TI block of the Overview dashboard you need to add the index where Threat Intelligence data is stored to `securitySolution:defaultThreatIndex` in the Advanced Settings of Kibana. In the case of Filebeat, the index pattern to be added there is most likely `filebeat-*` if you didn't change it.

---

<div class="post-metadata">

**Author:** ![bigverm23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigverm23/32/112550_2.png) [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Post date:** [November 1, 2022, 8:52am UTC](https://discuss.elastic.co/t/no-threat-intelligence-data/317638/4 "2022-11-01T08:52:04Z")

</div>

it's current set as `logs-ti_*`...that is not correct?

---

<div class="post-metadata">

**Author:** ![maxcold](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxcold/32/97686_2.png) [@maxcold](https://discuss.elastic.co/u/maxcold)\
**Post date:** [November 1, 2022, 9:55am UTC](https://discuss.elastic.co/t/no-threat-intelligence-data/317638/5 "2022-11-01T09:55:39Z")

</div>

If you change it to `logs-ti_*, filebeat-*` the data should appear in the Overview dashboard.

More context: `logs-ti_*` is an index pattern used when ingesting Threat Intelligence data via Elastic Agent integration. As you are ingesting Threat Intelligence data via Filebeat, you need to add the index pattern matching the Filebeat ingestiion settings. If you don't change the defaults the Filebeat ingests data inti `filebeat-*` . You can either add this pattern to the `securitySolution:defaultThreatIndex` in addition to `logs-ti_*` or just replace `logs-ti_*` with `filebeat-*`. More information is available in the docs [Enable threat intelligence integrations | Elastic Security Solution [master] | Elastic](https://www.elastic.co/guide/en/security/master/es-threat-intel-integrations.html#ti-mod-integration)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2022, 11:55am UTC](https://discuss.elastic.co/t/no-threat-intelligence-data/317638/6 "2022-11-29T11:55:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
