# \[threatintel Filebeat module\] MISP configuration errors with filebeat threatintel module

**URL:** https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448
**Category:** Beats
**Tags:** beats-module, filebeat
**Created:** [June 30, 2021, 10:36am UTC](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448 "2021-06-30T10:36:50Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Balor](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@Balor](https://discuss.elastic.co/u/Balor)
#### Post date: [June 30, 2021, 10:36am UTC](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448/1 "2021-06-30T10:36:50Z")

</div>

Hello All,

A question about the **Filebeat** module " **threatintel**". On the **MISP configuration**. Using Filebeat 7.13.2.The below are the settings that I have tested but shows with errors in the filebeat logs. The config is from the [Elastic Filebeat docs](https://www.elastic.co/guide/en/beats/filebeat/7.13/filebeat-module-threatintel.html#_misp_fileset_settings).

**Config:**

```auto
  misp:
    enabled: true
    var.url: https://<MISP-SERVER>/events/restSearch
    var.api_token: <API-KEY>
    var.first_interval: 24h
    var.interval: 10m

```

**Shows the below error:**

`ERROR [input.httpjson-cursor] v2/input.go:129 Error while processing http request: failed to execute http client.Do: failed to execute http client.Do: Post "https://<MISP-SERVER>/events/restSearch": POST https://<MISP-SERVER>/events/restSearch giving up after 6 attempts {"input_source": "https://<MISP-SERVER>/events/restSearch", "input_url": "https://<MISP-SERVER>/events/restSearch"}`

Am I missing something here? Am able to perform calls using postman when testing. everything seems to be talking to each other but it seems to not make it that last step from Filebeat.

Thank you very much in advance!

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [June 30, 2021, 10:57am UTC](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448/2 "2021-06-30T10:57:31Z")

</div>

Can u curl misp from the same system that filebeat is running on?

---

<div class="post-metadata">

### Author: ![Balor](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@Balor](https://discuss.elastic.co/u/Balor)
#### Post date: [June 30, 2021, 12:15pm UTC](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448/3 "2021-06-30T12:15:24Z")

</div>

Hey @legoguy1000,

I am able to curl to MISP from the machine Filebeat is running from.

However, when using the **"/events/restSearch"** after the MISP address I keep getting back **error 500's**. Where I am able to get Status codes 200 when sending a GET request to just the MISP server URL and other requests.

I have also tried both in the Filebeat module config and with Curl requests the use of **"/attributes/restSearch/last:1d"**. From the curl request I am able to get the intended response body. But in the Filebeat output in the Filebeat logs I am getting the below:

```auto
ERROR [input.httpjson-cursor] v2/request.go:186 error processing response: split was expecting field to be an array {"input_source": "https://<MISP-SERVER>/attributes/restSearch/last:1d", "input_url": "https://<MISP-SERVER>/attributes/restSearch/last:1d"}

```

Thank you for your help!

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [June 30, 2021, 12:35pm UTC](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448/4 "2021-06-30T12:35:42Z")

</div>

I'd check your MISP logs.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 28, 2021, 2:36pm UTC](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-configuration-errors-with-filebeat-threatintel-module/277448/5 "2021-07-28T14:36:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
