# Dec 10th, 2021: \[en\] 5 Useful Tips to Get the Most Out of Fleet

**URL:** <https://discuss.elastic.co/t/dec-10th-2021-en-5-useful-tips-to-get-the-most-out-of-fleet/290491>\
**Category:** Advent Calendar\
**Created:** [December 10, 2021, 8:00am UTC](https://discuss.elastic.co/t/dec-10th-2021-en-5-useful-tips-to-get-the-most-out-of-fleet/290491 "2021-12-10T08:00:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mark\_Hopkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_hopkin/32/92593_2.png) [@Mark\_Hopkin](https://discuss.elastic.co/u/Mark_Hopkin)\
**Post date:** [December 10, 2021, 8:00am UTC](https://discuss.elastic.co/t/dec-10th-2021-en-5-useful-tips-to-get-the-most-out-of-fleet/290491/1 "2021-12-10T08:00:17Z")

</div>

As Fleet became [generally available](https://www.elastic.co/blog/elastic-agent-and-fleet-make-it-easier-to-integrate-your-systems-with-elastic) earlier in the year, the Fleet development team and I wanted to share a few tips and tricks for getting the most out of using the Fleet app in Kibana.

If you aren't familiar with Fleet and the Elastic Agent I recommend checking out the documentation [here](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html). Fleet is a Kibana app that lets you centrally manage an entire fleet of Elastic Agents at scale, giving you a real-time view into agent status, remotely upgrade agents, execute queries on each host, and contain security threats.

_Quick note: All of these tips were gathered on Kibana version 7.16._

### 1. Easily keep your agent policies up to date

Firstly I wanted to draw attention to a really useful feature introduced in Kibana 7.16. As new versions of integrations are released, it is now really simple to keep the integrations in your agent policies up to date.

Checking the "Upgrade agent policies" checkbox when upgrading an integration will upgrade the package in all of your agent policies, rolling the change out to your agents.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/1/1/11ad8f754d183b50b3414a2e74f1a4671f3ea5ef.png)

If you uncheck this box then you can still roll out the upgraded integration to your agent policies manually as before.

### 2. Use the assets tab to quickly access integration assets

When an integration is installed, often they come bundled with useful Kibana assets such as dashboards for getting the most out of the data an integration produces. After installing an integration, head to the assets tab to see the assets that have been installed with an integration.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c0291f6d1f1c8c6e43f09465d17bac5a6fc4999.png)

The assets tab is broken down by asset type, and you can follow links for each asset to view it.

### 3. Use the data streams view to see integration data

Integrations use [data streams](https://www.elastic.co/guide/en/elasticsearch/reference/current/data-streams.html) to store their data. To get to know the data streams that are available for a given integration you can use the data streams view in Fleet.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0ec65ec2239c36ee04266ccec702d3d0ceeedd9f.png)

The data streams view allows you to filter streams by namespace (more on these in the next tip), integration, type or dataset. You can see the last time the stream received data and the size of the data stream.

### 4. Use namespaces to group integration data

A namespace is a user configured arbitrary grouping of data. Namespaces can be used to split your integration data any way you want, a popular use case we see is having separate namespaces for different environments (e.g `dev`, `staging` and `prod`) but you can have any namespaces you like.

Namespace forms the final part of the data stream naming scheme (check out Nicolas's blog post [here](https://www.elastic.co/blog/an-introduction-to-the-elastic-data-stream-naming-scheme) for a great intro) this means that you can easily search over a single namespace e.g `GET /metrics-system.cpu-production/_search` or all namespaces e.g `GET /metrics-system.cpu-*/_search`.

You can specify a namespace when adding an integration to an agent policy:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/7/070566cce6984bbb7c60d872ac8d0ae788c96b7f.png)

**Bonus tip: Specify a default namespace for an agent policy.**

To save you from specifying the namespace each time you add an integration, you can set a default namespace for the agent policy on creation (or in the policy settings menu):

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/4/f46c252892bf20026f17f021417673bcf8e2b0a8.jpeg)

### 5. Use `@custom` component templates to specify index settings

This slightly more advanced tip is really useful. The index templates created by Fleet are composed of [component templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-component-template.html). One of these component templates is the `@custom` component template, which is provided to allow users to specify custom index settings. Here I can see the `metrics-system.cpu` index template has `metrics-system.cpu@custom` component template:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/1/0115a75fc654aa5bf27015c292d3b0d172787423.jpeg)

The `@custom` component template is guaranteed to preserve your changes on integration (or Kibana) upgrade. You could use this component template to add a runtime field, or specify an index setting such as an ILM policy and the settings you specify will be applied across all namespaces.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-10th-2021-en-5-useful-tips-to-get-the-most-out-of-fleet/290491/2 "2022-01-07T08:00:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
