# Threat Intel MISP

**URL:** <https://discuss.elastic.co/t/threat-intel-misp/312292>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 17, 2022, 2:09pm UTC](https://discuss.elastic.co/t/threat-intel-misp/312292 "2022-08-17T14:09:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![VitorBarroso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitorbarroso/32/99187_2.png) [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Post date:** [August 17, 2022, 2:09pm UTC](https://discuss.elastic.co/t/threat-intel-misp/312292/1 "2022-08-17T14:09:42Z")

</div>

I'm trying to use Threat Intel MISP on filebeat and when i start the filebeat i have this error

Aug 17 14:11:20 ubuntuserver filebeat[18895]: {"log.level":"error","@timestamp":"2022-08-17T14:11:20.550Z","log.logger":"input.httpjson-cursor.retryablehttp","log.origin":  
{"file.name":"go-retryablehttp@v0.6.6/client.go","file.line":553},"message":"request failed","service.name":"filebeat","id":"81BF425127182E05",  
"input\_source":"[https://192.168.100.62/events/restSearch","input\_url":"https://192.168.100.62/events/restSearch](https://192.168.100.62/events/restSearch%22,%22input_url%22:%22https://192.168.100.62/events/restSearch)",  
"error":{"message":"Post "[https://192.168.100.62/events/restSearch\](https://192.168.100.62/events/restSearch%5C)": x509: certificate signed by unknown authority"},  
"method":"POST","url":"[https://192.168.100.62/events/restSearch","ecs.version":"1.6.0](https://192.168.100.62/events/restSearch%22,%22ecs.version%22:%221.6.0)"}

I did filebeat test config and filebeat test output and is all good.

Any solution for this problem?

---

<div class="post-metadata">

**Author:** ![VitorBarroso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitorbarroso/32/99187_2.png) [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Post date:** [August 17, 2022, 3:33pm UTC](https://discuss.elastic.co/t/threat-intel-misp/312292/2 "2022-08-17T15:33:56Z")

</div>

This is my configurations:

Filebeat.yml

configuration kibana: host:"192.168.100.60:5601"  
configuration elastic:  
hosts: ["192.168.100.60:9200"]  
protocol: "https"  
username: "elastic"  
password: "password"  
ssl:  
enabled: true  
ca\_trusted\_fingerprint: ""

threat Intel MISP:  
misp:  
enabled: true  
var.input: httpjson  
var.url: [https://192.168.100.62/events/restSearch](https://192.168.100.62/events/restSearch)  
var.api\_token: 2ovd1ynjIMkEzCd9oA9DvumnQLweeYnCMtKQqtZl  
var.first\_interval: 200000h  
var.interval: 5m

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 18, 2022, 1:13pm UTC](https://discuss.elastic.co/t/threat-intel-misp/312292/3 "2022-08-18T13:13:12Z")

</div>

> [@VitorBarroso](#):
>
> "error":{"message":"Post "[[https://192.168.100.62/events/restSearch\](https://192.168.100.62/events/restSearch%5C)]([https://192.168.100.62/events/restSearch\](https://192.168.100.62/events/restSearch%5C))": x509: certificate signed by unknown authority"},

Have you used self-signed certificate?

---

<div class="post-metadata">

**Author:** ![VitorBarroso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitorbarroso/32/99187_2.png) [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Post date:** [August 19, 2022, 2:36pm UTC](https://discuss.elastic.co/t/threat-intel-misp/312292/4 "2022-08-19T14:36:19Z")

</div>

I resolve this problem.  
Another problem i have is i can't receive the data for my misp instance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2022, 4:36pm UTC](https://discuss.elastic.co/t/threat-intel-misp/312292/5 "2022-09-16T16:36:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
