# Does elastic Security agent replace the use of Auditbeat, packetbeat, and filebeat agents?

**URL:** https://discuss.elastic.co/t/does-elastic-security-agent-replace-the-use-of-auditbeat-packetbeat-and-filebeat-agents/266021
**Category:** Endpoint Security
**Created:** [March 2, 2021, 10:33pm UTC](https://discuss.elastic.co/t/does-elastic-security-agent-replace-the-use-of-auditbeat-packetbeat-and-filebeat-agents/266021 "2021-03-02T22:33:37Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)
#### Post date: [March 2, 2021, 10:33pm UTC](https://discuss.elastic.co/t/does-elastic-security-agent-replace-the-use-of-auditbeat-packetbeat-and-filebeat-agents/266021/1 "2021-03-02T22:33:37Z")

</div>

I was watching a [webinar](https://www.elastic.co/es/webinars/introducing-elastic-siem) of SIEM with version 7.2 of elastic, and the speaker use multiples agents (Auditbeat, packetbeat, and filebeat agents) to feed SIEM, and now with elastic 7.11 there is a new agent, Endpoint, I was wondering if this agent replace the use of the other agents.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [March 3, 2021, 12:44am UTC](https://discuss.elastic.co/t/does-elastic-security-agent-replace-the-use-of-auditbeat-packetbeat-and-filebeat-agents/266021/2 "2021-03-03T00:44:06Z")

</div>

Currently, from [Beats and Elastic Agent capabilities | Fleet and Elastic Agent Guide [8.11] | Elastic](https://www.elastic.co/guide/en/fleet/current/fleet-limitations.html);

> - Support for only Filebeat, Metricbeat, and Endpoint Security

My understanding is that we are working on rolling the other beats into the agent.

---

<div class="post-metadata">

### Author: ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)
#### Post date: [March 3, 2021, 3:43pm UTC](https://discuss.elastic.co/t/does-elastic-security-agent-replace-the-use-of-auditbeat-packetbeat-and-filebeat-agents/266021/3 "2021-03-03T15:43:00Z")

</div>

Hello. There seems to be some terminology confusion, so I capitalized proper nouns below.

At this time, the Endpoint Security integration, which includes the Elastic Endpoint, is not intended to replace the System integration, which includes various Beats. All of these integrations are orchestrated by Fleet / Elastic Agent. If you deploy an Elastic Agent with either of the aforementioned integrations enabled, Agent will deploy and manage the corresponding Endpoint/Beat.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 31, 2021, 3:43pm UTC](https://discuss.elastic.co/t/does-elastic-security-agent-replace-the-use-of-auditbeat-packetbeat-and-filebeat-agents/266021/4 "2021-03-31T15:43:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
