# CCR KSPM Data

**URL:** <https://discuss.elastic.co/t/ccr-kspm-data/368541>\
**Category:** Kibana\
**Tags:** elastic-stack-security, ccs-cross-cluster-search\
**Created:** [October 9, 2024, 2:53pm UTC](https://discuss.elastic.co/t/ccr-kspm-data/368541 "2024-10-09T14:53:11Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [October 9, 2024, 2:53pm UTC](https://discuss.elastic.co/t/ccr-kspm-data/368541/1 "2024-10-09T14:53:11Z")

</div>

- As suggested in the past, for using the **KSPM** on the SIEM Module, we need to use the Elastic Agent integration for our k8s clusters.
- Now if in case this data is read over CCR, what changes needs to be done other than mapping the index patterns on Security Data view?
- I tried and was disappointed that it does not work. But I feel there is something which needs to be changed than obvious.
- Currently the page asks me to install the integration, but I only need to use the available data which is fetched over CCR.
- I can see this works where the data is locally stored.
