# ThreatIntel + module configuration

**URL:** <https://discuss.elastic.co/t/threatintel-module-configuration/276652>\
**Category:** SIEM\
**Created:** [June 22, 2021, 12:39pm UTC](https://discuss.elastic.co/t/threatintel-module-configuration/276652 "2021-06-22T12:39:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![malvivent7](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@malvivent7](https://discuss.elastic.co/u/malvivent7)\
**Post date:** [June 22, 2021, 12:39pm UTC](https://discuss.elastic.co/t/threatintel-module-configuration/276652/1 "2021-06-22T12:39:04Z")

</div>

Hi to all, i have enabled through filebeat modules the threatintel module and after that i have configured threatintel.yml activating otx and abusemalware than ` filebeat -e setup `. So far so good but till now i dont see anything in the kibana dashboard about threat (i have filebeat just configured for ingesting netflow). Someone could help me rsolving this issue? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![pcosic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pcosic/32/90827_2.png) [@pcosic](https://discuss.elastic.co/u/pcosic)\
**Post date:** [June 25, 2021, 10:18am UTC](https://discuss.elastic.co/t/threatintel-module-configuration/276652/2 "2021-06-25T10:18:18Z")

</div>

You should post you threatintel.yml configuration.  
Also you should verify if you activate it with

```auto
filebeat modules enable threatintel

```

And double check in die module.d/ directory if the filename of treatintel.yml is without .disabled

Finally you could activate the SIEM Build in Rule "Threat Intel Filebeat Module Indicator Match" this correlates the data you ingest for example via Filebeat with the blocklists and alert if there's a match.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2021, 10:19am UTC](https://discuss.elastic.co/t/threatintel-module-configuration/276652/3 "2021-07-23T10:19:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
