# ElasticDefend Integration is installed but API says otherwise

**URL:** https://discuss.elastic.co/t/elasticdefend-integration-is-installed-but-api-says-otherwise/363428
**Category:** Elastic Security
**Created:** [July 19, 2024, 11:37am UTC](https://discuss.elastic.co/t/elasticdefend-integration-is-installed-but-api-says-otherwise/363428 "2024-07-19T11:37:27Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![priamaiai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priamaiai/32/136169_2.png) [@priamaiai](https://discuss.elastic.co/u/priamaiai)
#### Post date: [July 19, 2024, 11:37am UTC](https://discuss.elastic.co/t/elasticdefend-integration-is-installed-but-api-says-otherwise/363428/1 "2024-07-19T11:37:27Z")

</div>

I am on Elasticsearch Free Enterprise Trial version 8.12.2

Version

I have enabled the Elastic Defend integration on the integration policy of the agent.  
I can see the agent is enabled.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1d1d45b2cb08fa80fde2eb22a039dcc4cbb7a28.png)

However when I try to issue a command via the Kibana list the processes on that agent I get this error:

["The host does not have Elastic Defend integration installed"],

---

<div class="post-metadata">

### Author: ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)
#### Post date: [July 22, 2024, 9:13am UTC](https://discuss.elastic.co/t/elasticdefend-integration-is-installed-but-api-says-otherwise/363428/2 "2024-07-22T09:13:20Z")

</div>

Can you confirm that this Policy has Defend included and is applied to the endpoint you were expecting to test? The Integration view doesn't say that.

I suggest opening Fleet view.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d5b13b6acde84a9b79b29b5114cb73ca66a5f67f.png)

Then click on the host of interest and confirm that Defend is indeed added to the policy and is healthy

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/6/168f1ecfc4b7a4f1075d65f99f4706d88e0f9ba6.png)

---

<div class="post-metadata">

### Author: ![priamaiai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priamaiai/32/136169_2.png) [@priamaiai](https://discuss.elastic.co/u/priamaiai)
#### Post date: [August 19, 2024, 6:24am UTC](https://discuss.elastic.co/t/elasticdefend-integration-is-installed-but-api-says-otherwise/363428/3 "2024-08-19T06:24:05Z")

</div>

Hi there,  
this is what I see on the host:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/e/ce6221cfdd2f20bc76ec373359fc6e6f578adf9e.png)

It seems correct no?

---

<div class="post-metadata">

### Author: ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)
#### Post date: [August 26, 2024, 2:03pm UTC](https://discuss.elastic.co/t/elasticdefend-integration-is-installed-but-api-says-otherwise/363428/4 "2024-08-26T14:03:32Z")

</div>

I can see you've also got Osquery, so I just wonder which component was used to list the processes.

Did you run the command `processes` from response console as described here [Endpoint response actions | Elastic Security Solution [8.15] | Elastic](https://www.elastic.co/guide/en/security/current/response-actions.html)

This feature requires relevant license and privileges. Maybe the error is misleading.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 23, 2024, 2:03pm UTC](https://discuss.elastic.co/t/elasticdefend-integration-is-installed-but-api-says-otherwise/363428/5 "2024-09-23T14:03:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
