Skip to content
Integrations
Skip navigation
Integrations

Install and configure the MISP module

Upgrade the modules service to pick up the Whisper expansion module, set its four settings, and confirm enrichment is firing.

Published

View as Markdown
On this page (5)

Install and configure the MISP module Documentation

The module ships inside misp-modules, MISP's own third-party enrichment library — there is no separate package to fetch and no repository to clone.


Requirements

  • A MISP instance running the modules enrichment service (misp-modules) at v3.0.10 or later — the release that first carries the Whisper module.
  • Egress from the modules service to the Whisper graph API host.
  • A Whisper API key. The module has no keyless mode — get one in the console.

Upgrade the modules service

Update the misp-modules package running your enrichment service and restart it:

bash
pip install --upgrade misp-modules
systemctl restart misp-modules   # or however your deployment manages the service

Enable the module and set its settings

In MISP's own Administration → Server Settings → Plugin Settings, turn on the Whisper expansion module under Enrichment (and the hover module too, if you want the inline preview), then fill in its settings — the same block every misp-modules module reads from MISP's own plugin configuration:

SettingWhat to put in it
api_urlLeave it on the default unless you have a reason to point elsewhere. Changing it sends both the attribute value and your API key to that host.
api_keyYour Whisper API key. Required — without it MISP enables the module but every enrichment returns a configuration error.
max_tlpThe most sensitive TLP marking the module may send to the Whisper API. An attribute tagged above this is refused before any value leaves MISP. Defaults to tlp:amber+strict; tlp:red disables the gate. Raise it only if your sharing agreements allow it.
timeoutYour own enrichment budget for a single lookup, if the default (8 seconds) does not fit your deployment — keep it below MISP's own Plugin.Enrichment_timeout (default 10), or MISP kills the request first.

Confirm it is firing

Enrich or hover over an attribute of a supported type — ip-src, ip-dst, domain, hostname or AS — and check the misp-modules service log for a request reaching the Whisper graph API host. A successful enrichment adds an asn object, a domain-ip object, or one of the standalone attributes to the event, depending on what WhisperGraph holds for that indicator.

Nothing appears, and the log shows no outbound request. The module is not enabled, or the attribute type is not one of the five above.

The log shows a request, but nothing lands. Check api_key first — a missing or unrecognised key is why the module has nothing to add, not a sign that WhisperGraph holds nothing on the indicator.