# Threat intel integration

**URL:** <https://discuss.elastic.co/t/threat-intel-integration/282663>\
**Category:** SIEM\
**Created:** [August 27, 2021, 12:09pm UTC](https://discuss.elastic.co/t/threat-intel-integration/282663 "2021-08-27T12:09:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tejas.tech](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@tejas.tech](https://discuss.elastic.co/u/tejas.tech)\
**Post date:** [August 27, 2021, 12:09pm UTC](https://discuss.elastic.co/t/threat-intel-integration/282663/1 "2021-08-27T12:09:13Z")

</div>

Team,

I have installed Filebeat 7.14.X agent and have enabled the threatintel module but unable to get feeds from all the threat intel. Could you please help us out on this?

---

<div class="post-metadata">

**Author:** ![wallacepalace](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wallacepalace/32/55636_2.png) [@wallacepalace](https://discuss.elastic.co/u/wallacepalace)\
**Post date:** [September 8, 2021, 2:45am UTC](https://discuss.elastic.co/t/threat-intel-integration/282663/2 "2021-09-08T02:45:19Z")

</div>

You need to go to the filebeat modules folder and set the API keys for each info feed integration, for example: otx.alienvault. If you don't know how, I can explain this in more detail and post some pictures of where to get the API key for each feed site.

Don't forget the "filebeat setup" at the end of the process and restart the service.

---

<div class="post-metadata">

**Author:** ![tejas.tech](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@tejas.tech](https://discuss.elastic.co/u/tejas.tech)\
**Post date:** [September 14, 2021, 1:38pm UTC](https://discuss.elastic.co/t/threat-intel-integration/282663/3 "2021-09-14T13:38:30Z")

</div>

Hey @wallacepalace,

Thank you for your reply. It would be great if you could share something related to MISP.

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [September 15, 2021, 1:05pm UTC](https://discuss.elastic.co/t/threat-intel-integration/282663/4 "2021-09-15T13:05:38Z")

</div>

#MeToo - I'm struggling to get the MISP feeds working with my local MISP server.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2021, 1:06pm UTC](https://discuss.elastic.co/t/threat-intel-integration/282663/5 "2021-10-13T13:06:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
