# Threat intelligence module

**URL:** <https://discuss.elastic.co/t/threat-intelligence-module/282766>\
**Category:** Kibana\
**Created:** [August 29, 2021, 9:13pm UTC](https://discuss.elastic.co/t/threat-intelligence-module/282766 "2021-08-29T21:13:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Servando\_Dominguez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/servando_dominguez/32/93647_2.png) [@Servando\_Dominguez](https://discuss.elastic.co/u/Servando_Dominguez)\
**Post date:** [August 29, 2021, 9:13pm UTC](https://discuss.elastic.co/t/threat-intelligence-module/282766/1 "2021-08-29T21:13:04Z")

</div>

Hi there! Alert for a maybe, a stupid question.  
I want to enable the thread intelligence module from diferent resources. I click enable in Kibana and go to the documentation:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/856524cb0d6dbc87e80d1985dfde1ca00203e637.png)  
My question is, where I put this config/modules config? in the kibana.yml file?  
I don't find the solution. I tried to put the config in diferent config files but doesn't work properly. Could you please give some light?

And sorry for the question if it is very basic :S

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [August 29, 2021, 11:15pm UTC](https://discuss.elastic.co/t/threat-intelligence-module/282766/2 "2021-08-29T23:15:44Z")

</div>

The threat intelligence module is part of Filebeat, [Threat Intel module | Filebeat Reference [7.14] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-threatintel.html#filebeat-module-threatintel). You'll need to install Filebeat and then configure the module there.

---

<div class="post-metadata">

**Author:** ![Servando\_Dominguez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/servando_dominguez/32/93647_2.png) [@Servando\_Dominguez](https://discuss.elastic.co/u/Servando_Dominguez)\
**Post date:** [August 30, 2021, 10:28am UTC](https://discuss.elastic.co/t/threat-intelligence-module/282766/3 "2021-08-30T10:28:28Z")

</div>

And it's possible to enable this threat intelligence modules in the filebeat that runs in the elastic agent?  
In the 7.14 release I migrated all the filebeats to elastic agents.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [September 2, 2021, 2:20am UTC](https://discuss.elastic.co/t/threat-intelligence-module/282766/4 "2021-09-02T02:20:57Z")

</div>

I don't think the threat Intel module had been migrated to the elastic agent yet. But it should be soon.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2021, 2:21am UTC](https://discuss.elastic.co/t/threat-intelligence-module/282766/5 "2021-09-30T02:21:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
