# Threat intel Filebeat module - I don't get any data From MISP and i don't know why

**URL:** https://discuss.elastic.co/t/threat-intel-filebeat-module-i-dont-get-any-data-from-misp-and-i-dont-know-why/327986
**Category:** Beats
**Tags:** beats-module, filebeat
**Created:** [March 18, 2023, 8:48am UTC](https://discuss.elastic.co/t/threat-intel-filebeat-module-i-dont-get-any-data-from-misp-and-i-dont-know-why/327986 "2023-03-18T08:48:39Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Nicolas\_Pelletier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_pelletier/32/118570_2.png) [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)
#### Post date: [March 18, 2023, 8:48am UTC](https://discuss.elastic.co/t/threat-intel-filebeat-module-i-dont-get-any-data-from-misp-and-i-dont-know-why/327986/1 "2023-03-18T08:48:39Z")

</div>

Hello,

I'm trying to integrate MISP IOC's into Kibana via [Threat intel Filebeat Module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-threatintel.html).

When i look at the analytics dicover view in kibana, i see every `var.interval` (set in the module config) a new hit with an `event.original` field empty. (`{"response":[]}` \<-- see below picture)

**Hit view on Kibana**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1afdcb8b783c9568b54c48d226cae2bc09064f95.png)

I can't explain this result as I make the POST request on my host machine and get many events... See below:

**MISP API Rest POST /events/restSearch**

```auto
nicop@nicop-IdeaPad-5-Pro-14ARH7:~$ curl -k \                                                                                                           
 -H "Authorization: BEpdSXuPb2lRyhVjNy9nHiA7EApYdD9ajMRafBZQ" \
 -H "Accept: application/json" \
 -H "Content-type: application/json" \
 -X POST https://localhost/events/restSearch \
 -d '{"returnFormat":"json","page":"1","limit":"10","timestamp":"1678704229"}'

{"response": [{"Event":{"id":"2413","orgc_id":"9","org_id":"1","date":"2018-08-17","threat_level_id":"1","info":"Turla Outlook White Paper","published":true,"uuid":"5b773e07-e694-458b-b99c-27f30a016219","attribute_count":"57","analysis":"0","timestamp":"1679128999","distribution":"3","proposal_email_lock":false,"locked":false,"publish_timestamp":"1679129000","sharing_group_id":"0", etc...

```

I deduce from the Preview API of the Elastic agent policies (In the Integration part of Kibana) that the following fields `returnFormat | page | limit | timestamp` was put in the request made to MISP instance to retrieve the data. (See below picture to see where i found it)  
**MISP integration Elastic-Agent policy setting**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a27426bc9d22e20728c6d95ec292cb5bf4227e5.png)  
**MISP Preview Kibana API Request transformation in Kibana Console**  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f412bf12dd83e56f7e8a5c43b96b04e7d573921.png)

Can someone confirm that for filebeat the data fields above are well defined in the API request made to MISP to retrieve the data ?  
Is there a way to modify these settings ?

**Process followed to put Filebeat up**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/9497ae4d76da989da5c3ccdd2adce344f9d03b00.png)

**Filebeat Logs process events**

```auto
{"log.level":"info","@timestamp":"2023-03-18T12:43:26.185+0100","log.logger":"input.httpjson-cursor","log.origin":{"file.name":"httpjson/input.go","file.line":132},"message":"Process another repeated request.","service.name":"filebeat","id":"6F488BAA3E80B30B","input_source":"https://localhost/events/restSearch","input_url":"https://localhost/events/restSearch","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2023-03-18T12:43:26.802+0100","log.logger":"input.httpjson-cursor","log.origin":{"file.name":"httpjson/request.go","file.line":445},"message":"request finished: 1657 events published","service.name":"filebeat","id":"6F488BAA3E80B30B","input_source":"https://localhost/events/restSearch","input_url":"https://localhost/events/restSearch","ecs.version":"1.6.0"}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 15, 2023, 10:49am UTC](https://discuss.elastic.co/t/threat-intel-filebeat-module-i-dont-get-any-data-from-misp-and-i-dont-know-why/327986/2 "2023-04-15T10:49:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
