# Can Elastic Security read existing non default pre-existing indices?

**URL:** <https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935>\
**Category:** Elastic Security\
**Created:** [August 10, 2021, 2:04pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935 "2021-08-10T14:04:58Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![rconroy](https://avatars.discourse-cdn.com/v4/letter/r/ea666f/32.png) [@rconroy](https://discuss.elastic.co/u/rconroy)\
**Post date:** [August 10, 2021, 2:04pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/1 "2021-08-10T14:04:58Z")

</div>

Hello  
We've been using ES for some time and have a number of indices that contain all the data we want to capture from windows hosts and other data sources such as firewalls etc... The reality is that I've already captured everything so i would like to bypass the agents and such entirely if possible since i already have to data in existing indices.  
Is this possible? If so how?  
Thanks

Added, i should mention that I've already tried adding the indices to the Elastic Security advanced settings, but no data ever populated the portal site.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2021, 11:03pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/2 "2021-08-10T23:03:39Z")

</div>

Yep, but they need to be in the ECS format to be usable.

---

<div class="post-metadata">

**Author:** ![rconroy](https://avatars.discourse-cdn.com/v4/letter/r/ea666f/32.png) [@rconroy](https://discuss.elastic.co/u/rconroy)\
**Post date:** [August 10, 2021, 11:15pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/3 "2021-08-10T23:15:10Z")

</div>

And how would i know that they were or were not, or set it to use that format or convert them? Forgive me if that's a dumb question I'm still learning

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2021, 11:27pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/4 "2021-08-10T23:27:23Z")

</div>

No worries!

Were these sources captured through modules in the various Beats, or via custom configs?

---

<div class="post-metadata">

**Author:** ![rconroy](https://avatars.discourse-cdn.com/v4/letter/r/ea666f/32.png) [@rconroy](https://discuss.elastic.co/u/rconroy)\
**Post date:** [August 10, 2021, 11:39pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/5 "2021-08-10T23:39:45Z")

</div>

This was received thru syslog TCP transports using nxlog agent as the source agent on windows hosts to be precise.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2021, 11:42pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/6 "2021-08-10T23:42:19Z")

</div>

Ahh ok, then it's probably not in the ECS format unfortunately ☹

I am not super knowledgable on ECS and getting data into that format, so I am not going to be much use there sorry to say.

---

<div class="post-metadata">

**Author:** ![rconroy](https://avatars.discourse-cdn.com/v4/letter/r/ea666f/32.png) [@rconroy](https://discuss.elastic.co/u/rconroy)\
**Post date:** [August 10, 2021, 11:46pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/7 "2021-08-10T23:46:31Z")

</div>

OK, ill look into seeing if thats something i can convert or take other actions. thanks for the input.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2021, 11:49pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/8 "2021-08-10T23:49:22Z")

</div>

Definitely start another topic on that question!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2021, 11:50pm UTC](https://discuss.elastic.co/t/can-elastic-security-read-existing-non-default-pre-existing-indices/280935/9 "2021-09-07T23:50:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
