# Does Elastic Agent support kafka as an input?

**URL:** <https://discuss.elastic.co/t/does-elastic-agent-support-kafka-as-an-input/372878>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [January 7, 2025, 5:33am UTC](https://discuss.elastic.co/t/does-elastic-agent-support-kafka-as-an-input/372878 "2025-01-07T05:33:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Priyanka\_chauhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyanka_chauhan/32/86146_2.png) [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Post date:** [January 7, 2025, 5:33am UTC](https://discuss.elastic.co/t/does-elastic-agent-support-kafka-as-an-input/372878/1 "2025-01-07T05:33:06Z")

</div>

If I have to send logs data from kafka topic of cisco ise logs for using CISO integration using elastic agent . how to setup that . As I am getting that kafka input is not supporting in elastic agent yaml .

---

<div class="post-metadata">

**Author:** ![Adrian\_Beaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrian_beaudin/32/133052_2.png) [@Adrian\_Beaudin](https://discuss.elastic.co/u/Adrian_Beaudin)\
**Post date:** [January 7, 2025, 6:53am UTC](https://discuss.elastic.co/t/does-elastic-agent-support-kafka-as-an-input/372878/2 "2025-01-07T06:53:24Z")

</div>

Hi Priyanka,

Elastic agent supports ingesting kafka metrics/logs - that is data instrumenting the kafka cluster/service and it also supports kafka custom logs - that is, topic data from a kafka cluster.

Details are here:

> **[Kafka | Elastic integrations | Elastic](https://www.elastic.co/guide/en/integrations/current/kafka-intro.html)**

Effectively, you'd have to add the desired kafka integration to your cluster, then go add that to the policy for your Agent.

Barring using the agent, logstash is an option as well.

Hope this helps,  
-a

---

<div class="post-metadata">

**Author:** ![chaison](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chaison/32/139495_2.png) [@chaison](https://discuss.elastic.co/u/chaison)\
**Post date:** [January 7, 2025, 6:57pm UTC](https://discuss.elastic.co/t/does-elastic-agent-support-kafka-as-an-input/372878/3 "2025-01-07T18:57:59Z")

</div>

The short answer is no. Elastic Agent doesn't support reading Kafka topics as an input.

You would need to use Logstash to read the topic and forward to elasticsearch.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 7, 2025, 7:55pm UTC](https://discuss.elastic.co/t/does-elastic-agent-support-kafka-as-an-input/372878/4 "2025-01-07T19:55:36Z")

</div>

> [@chaison](#):
>
> The short answer is no. Elastic Agent doesn't support reading Kafka topics as an input.

It does, it is the [Custom Kafka Logs integration](https://www.elastic.co/guide/en/integrations/current/kafka_log.html).

You can use this integration to read logs from Kafka Topics and by changing the dataset name it will reroute the events to the correct ingest pipeline.

> [@Priyanka\_chauhan](#):
>
> If I have to send logs data from kafka topic of cisco ise logs for using CISO integration using elastic agent . how to setup that . As I am getting that kafka input is not supporting in elastic agent yaml .

Which version are you using? I'm on 8.15.2 and I have a couple of Elastic Agent running with Custom Kafka Logs integration getting some logs from Kafka topics, one of them is from Cisco ISE.

You would need first to install the assets of the Cisco ISE integration.

 ![Screenshot from 2025-01-07 16-44-27](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10b9b87138c2eda05c0394848f619d8fea5a6a5d.png)

This will load the required templates and ingest pipelines.

Then you need to add a Custom Kafka Logs integration into an agent, point to your Kafka topic with ISE logs and then change the dataset to be `cisco_ise.log`.

I'm not sure how you do that on standalone agents as I use Fleet managed agents, but the configuration is something like this.

 ![Screenshot from 2025-01-07 16-46-48](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2f9b8826b1366e9ad31d3ee3c5900d979d49404d.png)

This will get the logs from the Kafka topic and send them to the correct ingest pipeline to parse it.

---

<div class="post-metadata">

**Author:** ![chaison](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chaison/32/139495_2.png) [@chaison](https://discuss.elastic.co/u/chaison)\
**Post date:** [January 7, 2025, 8:12pm UTC](https://discuss.elastic.co/t/does-elastic-agent-support-kafka-as-an-input/372878/5 "2025-01-07T20:12:31Z")

</div>

@leandrojmp thanks for keeping me straight. I missed the release of that integration.
