# Where can we find the data from apache integration

**URL:** https://discuss.elastic.co/t/where-can-we-find-the-data-from-apache-integration/307397
**Category:** Kibana
**Tags:** integrations
**Created:** [June 16, 2022, 11:28am UTC](https://discuss.elastic.co/t/where-can-we-find-the-data-from-apache-integration/307397 "2022-06-16T11:28:44Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![shi](https://avatars.discourse-cdn.com/v4/letter/s/f14d63/32.png) [@shi](https://discuss.elastic.co/u/shi)
#### Post date: [June 16, 2022, 11:28am UTC](https://discuss.elastic.co/t/where-can-we-find-the-data-from-apache-integration/307397/1 "2022-06-16T11:28:44Z")

</div>

We have installed elastic agent in a client system (apache server) and enrolled it in the fleet.  
We have added apache http server integration to its policy.  
We can see the data in /var/log/apache2/access.log of the apache server.  
The pipelines and templates can be seen in the Stack Management.

The Index templates are as follows:

```auto
    Name Index patterns Components

1. logs-apache.access(Managed) logs-apache.access-* logs-apache.access@settings, logs-apache.access@custom, .fleet_component_template-1		
	
2. logs-apache.error(Managed) logs-apache.error-* logs-apache.error@settings, logs-apache.error@custom, .fleet_component_template-1

3. metrics-apache.status(Managed)	metrics-apache.status-* metrics-apache.status@settings, metrics-apache.status@custom, .fleet_component_template-1

```

But we couldn't find any index matching 'apache' in the Kibana.  
(We had successfully integrated endpoint security for the same policy and we could view the logs of endpoint security from the same system)

Where can we find the data from the elastic-agent of the apache server in Kibana?

---

<div class="post-metadata">

### Author: ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)
#### Post date: [June 16, 2022, 12:55pm UTC](https://discuss.elastic.co/t/where-can-we-find-the-data-from-apache-integration/307397/2 "2022-06-16T12:55:32Z")

</div>

Guessing here - they should be within the `logs-*` data view (formerly known as index pattern) for the logs sources and the `metrics-*` index pattern for the metrics sources. there is a field in these called `event.dataset` that you can use to filter to just the specific sources of logs (and metrics respectively)...or you can make a specific data view in stack management that selects a specific index directly.

indexes managed by agent don't show in the default view for "Index management" as they're managed by a data stream so they're 'hidden' indexes as to prevent a user from removing something that's actually managed by elastic agent.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c87667f62437639811300dd0ae5a6ddee1cd564d.png)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 14, 2022, 12:55pm UTC](https://discuss.elastic.co/t/where-can-we-find-the-data-from-apache-integration/307397/3 "2022-07-14T12:55:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
