Ingesting threat data with the Threat Intel Filebeat module
ID: a1f78f2e-4a71-58de-9585-551e9c3ad1fd
STIX ID: report--a1f78f2e-4a71-58de-9585-551e9c3ad1fd
Feed Name: Elastic Security Labs
This guide explains how to ingest and operationalize open-source threat intelligence in the Elastic Stack using the Filebeat Threat Intel module. It covers configuring feeds from Abuse.ch, MalwareBazaar, AlienVault OTX, MISP, and Anomali Limo; setting up MISP, Elasticsearch, and Kibana (including Docker-based options); enabling the module; validating outputs; and leveraging prebuilt dashboards for analysis. The post focuses on setup, configuration, and workflow rather than specific threat actors or incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
