# Sample Threat Intel Module Filebeat.YML File that you can share?

**URL:** <https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071>\
**Category:** Elastic Security\
**Created:** [September 1, 2021, 3:57pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071 "2021-09-01T15:57:23Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![tanner8302](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanner8302/32/94038_2.png) [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Post date:** [September 1, 2021, 3:57pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/1 "2021-09-01T15:57:23Z")

</div>

Has anyone got the Threat Feed in elastic working? If so could you share your filebeat.yml sample so that I can refer to it. I cannot get filebeat to start using the module samples provided by elastic.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [September 2, 2021, 2:22am UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/2 "2021-09-02T02:22:12Z")

</div>

What errors do u get? Can u post ur config and logs?

---

<div class="post-metadata">

**Author:** ![tanner8302](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanner8302/32/94038_2.png) [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Post date:** [September 2, 2021, 12:01pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/3 "2021-09-02T12:01:40Z")

</div>

I am using the default filebeat.yml and trying to add the following modules to it, like this

- module: threatintel  
abuseurl:  
enabled: true  
var.input: httpjson  
var.url: [https://urlhaus-api.abuse.ch/v1/urls/recent/](https://urlhaus-api.abuse.ch/v1/urls/recent/)  
var.interval: 60m

When I try to start the filebeat service it fails.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [September 2, 2021, 12:14pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/4 "2021-09-02T12:14:32Z")

</div>

When u post code use the code tags for formatting. I assume the indentation is correct in ur yaml file? If u run filebeat from the cli and add `-e` to run in debug, can u post the output so we can see where it's failing?

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [September 2, 2021, 6:39pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/5 "2021-09-02T18:39:19Z")

</div>

Hi Tanner,  
The reason this isn't working is because you don't put those entries in the `filebeat.yml` file, they go in the `threatintel.yml` file which lives in the modules.d sub-folder.

Remove those entries from your filebeat.yml file, and put them in the `/etc/filebeat/modules.d/threatintel.yml` and you should be fine.

When you examine that file, you'll probably discover the entries are already present.

---

<div class="post-metadata">

**Author:** ![tanner8302](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanner8302/32/94038_2.png) [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Post date:** [September 2, 2021, 8:23pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/6 "2021-09-02T20:23:08Z")

</div>

Thank you so much we will try that. So no modifications needed for filebeat except in output section for our cloud I’d and cloud auth information. And then making sure that the threat feed modules are listed and enabled as true in the modules yml. Did I state that right?

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [September 3, 2021, 11:20am UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/7 "2021-09-03T11:20:20Z")

</div>

It sounds right, but I'm not expert - I'm still trying to get my Misp feed to work!  
Also, I'm doing everything on-prem, so I have no clue about cloud based environments.

Good luck!

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [September 3, 2021, 1:00pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/8 "2021-09-03T13:00:02Z")

</div>

The module configs can go in either file if I. The filebeat.yml, they need to be nested under

```auto
filebeat.modules:

```

or they can be in their respective module file. If u run `filebeat modules list`, does the threat Intel module show as enabled?

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [September 3, 2021, 1:39pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/9 "2021-09-03T13:39:51Z")

</div>

Pretty sure it's enabled by default.

---

<div class="post-metadata">

**Author:** ![tanner8302](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanner8302/32/94038_2.png) [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Post date:** [September 3, 2021, 1:41pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/10 "2021-09-03T13:41:39Z")

</div>

Yes that is where we initially nested them but could not get filebeat to start as a service. We will check the modules yml to see if that works for us.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [September 3, 2021, 1:53pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/11 "2021-09-03T13:53:36Z")

</div>

Modules are not enabled by default. You have to enable them by running `filebeat modules enable <module>` or by manually updating the module files/filebeat.yml with the module config.

> [@tanner8302](#):
>
> could not get filebeat to start as a service.

run `filebeat -e` to see what the output in debug mode to see why it's crashing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2021, 1:53pm UTC](https://discuss.elastic.co/t/sample-threat-intel-module-filebeat-yml-file-that-you-can-share/283071/12 "2021-10-01T13:53:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
