# Threat Intel Problems

**URL:** <https://discuss.elastic.co/t/threat-intel-problems/312801>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 24, 2022, 11:23am UTC](https://discuss.elastic.co/t/threat-intel-problems/312801 "2022-08-24T11:23:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![VitorBarroso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitorbarroso/32/99187_2.png) [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Post date:** [August 24, 2022, 11:23am UTC](https://discuss.elastic.co/t/threat-intel-problems/312801/1 "2022-08-24T11:23:40Z")

</div>

I'm trying to know if my threatintel.yml is working right?  
Because i'm trying to use misp on threat intel but is don't display anything but the other modules are displaying information, for example, the abuseURL.

misp:  
enabled: true  
var.input: httpjson  
var.url:[https://192.168.100.122/events/restSearch](https://192.168.100.122/events/restSearch)  
var.api\_token: 8qgv...ajlbD  
var.ssl.verification\_mode: none  
var.first\_interval: 120000h  
var.interval: 10m

this is my configuration for misp

Any solution?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2022, 11:24am UTC](https://discuss.elastic.co/t/threat-intel-problems/312801/2 "2022-09-21T11:24:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
