From 092fc4958d6fed8be99c2e768dfa64baf3bedcc8 Mon Sep 17 00:00:00 2001 From: Marius Iversen Date: Tue, 20 Apr 2021 19:01:09 +0200 Subject: [PATCH] mage fmt update --- filebeat/docs/modules/threatintel.asciidoc | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/filebeat/docs/modules/threatintel.asciidoc b/filebeat/docs/modules/threatintel.asciidoc index 26e5ec4e65e..08ae5066298 100644 --- a/filebeat/docs/modules/threatintel.asciidoc +++ b/filebeat/docs/modules/threatintel.asciidoc @@ -20,14 +20,15 @@ Processors]. The related threat intel attribute that is meant to be used for matching incoming source data is stored under the `threatintel.indicator.*` fields. +======= The available filesets are: + * `abuseurl`: Supports gathering URL entities from Abuse.ch. * `abusemalware`: Supports gathering Malware/Payload entities from Abuse.ch. * `misp`: Supports gathering threat intel attributes from MISP (replaces MISP module). * `malwarebazaar`: Supports gathering Malware/Payload entities from Malware Bazaar. * `otx`: Supports gathering threat intel attributes from AlientVault OTX. * `anomali`: Supports gathering threat intel attributes from Anomali. - include::../include/gs-link.asciidoc[] [float]