# Data Stream not found in Data Views

**URL:** <https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222>\
**Category:** SIEM\
**Tags:** elastic-agent\
**Created:** [October 21, 2022, 5:14pm UTC](https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222 "2022-10-21T17:14:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sakib3833](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sakib3833](https://discuss.elastic.co/u/sakib3833)\
**Post date:** [October 21, 2022, 5:14pm UTC](https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222/1 "2022-10-21T17:14:09Z")

</div>

I use Microsoft Defender Endpoint integration to collect logs. The agent installed perfectly and the other ID and secret key put accordingly.  
In the Index management section it shows that it creates Data Stream.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/5/65bf8d53e71e91a6c324216a3d2f92aa330f43f4.png)

But in Data Views section, I couldn't find the Data Stream and eventually I wasn't able to navigate any MS defender endpoint data in Discover Section.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d44d3edc909cfab58ebbcd4c5b07cb5cc0bbdca.png)

Previously I did the same process for MS365 Defender log. That works fine.  
So I am not sure what exactly the issue is. Any suggestions?  
Thank you.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 27, 2022, 2:22pm UTC](https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222/2 "2022-10-27T14:22:55Z")

</div>

If you run this in the Dev Tool console in Kibana, do you have any indices?

`GET _cat/indices/*microsoft_defender*?v`

The data stream exists when the integration is setup, but the indices are not created until some data is generated. So if there are no indices yet then I would check the logs for the Agent to see if there are any errors relating to microsoft\_defender.

You can check the logs for the Agent in Kibana with a query for `data_stream.dataset:"elastic_agent.filebeat" `.

 ![Screen Shot 2022-10-27 at 10.22.24](https://us1.discourse-cdn.com/elastic/original/3X/9/8/98f32423d0a352a4f2354eb796b20dcea4d81e93.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2022, 2:23pm UTC](https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222/3 "2022-11-24T14:23:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
