# Where to find the Custom Logs (Filestream) integration?

**URL:** <https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [March 13, 2026, 9:35pm UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446 "2026-03-13T21:35:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [March 13, 2026, 9:35pm UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446/1 "2026-03-13T21:35:03Z")

</div>

We’re trying to run an Air Gapped EPR registry v.1.37.0 with a minimal set of selected integration packages, but kibana v.8.19.9 first of all shows a larger(e) set of integrations (wondering why?) to select among in the UI Kibana→Fleet→Policy-Add integration and even with below listed EPR packages, we don’t seem to be able to find ‘Custom Logs (Filestream)’ which we’ll like to be able to migrate from current local filebeat filestream inputs to Agent Policies.

Hints are much appreciated, TIA.

Our Air gapped EPR holds these:

```auto
$ curl -s http://localhost/search | jq .[].name
"log"
"filestream"
"elastic_agent"
"endpoint"
"synthetics"
"synthetics_dashboards"
"elasticsearch"
"fleet_server"
"kibana"
"osquery"
"osquery_manager"
"system"

```

Offical EPR registry seems to have these matching ‘file|cust’:

```auto
$ curl -s -X GET https://epr.elastic.co/search | jq .[].name | egrep -i 'file|cust'
"filestream"
"ti_custom"
"filelog_otel"
"profiler_agent"
"profiler_collector"
"profiler_symbolizer"

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 13, 2026, 10:05pm UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446/2 "2026-03-13T22:05:04Z")

</div>

I'm not sure how Air Gapped EPR works, but the _Custom Logs (Filestream)_ is the `filestream` package.

From the manifest in [github](https://github.com/elastic/integrations/blob/main/packages/filestream/manifest.yml).

```auto
format_version: 3.1.5
name: filestream
title: Custom Logs (Filestream)
description: Collect log data using filestream with Elastic Agent.
type: input

```

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [March 14, 2026, 8:25am UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446/3 "2026-03-14T08:25:17Z")

</div>

Thanks, but we got filestream in our EPR, only it does show up in our v.8.19 kibana fleet integrations UI to able selection for adding into an Agent Policy. ChatGPT says it’s maybe because:

- The filestream package you see is **just the low-level input type provider** , not a Kibana-visible integration

Wondering why ‘Custom Logs (Filestream)’ does show up?

Also any clues on how to have Kibana only show packages in our air gapped EPR registry rather than what seems a random default selection?

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [March 14, 2026, 9:11am UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446/4 "2026-03-14T09:11:32Z")

</div>

😕 seems filestream v.2.3.0 isn’t compatible with v.8 but requires +v.9.2:

```auto
$ curl -s http://localhost/search?package=filestream | jq .
[
  {
    "name": "filestream",
    "title": "Custom Logs (Filestream)",
    "version": "2.3.0",
    "release": "ga",
    "description": "Collect log data using filestream with Elastic Agent.",
    "type": "input",
    "download": "/epr/filestream/filestream-2.3.0.zip",
    "path": "/package/filestream/2.3.0",
    "icons": [
      {
        "src": "/img/icon.svg",
        "path": "/package/filestream/2.3.0/img/icon.svg",
        "type": "image/svg+xml"
      }
    ],
    "policy_templates": [
      {
        "name": "filestream",
        "title": "Custom Filestream Logs",
        "description": "Collect log data from filestream with Elastic Agent."
      }
    ],
    "conditions": {
      "kibana": {
        "version": "^9.2.0"
      }
    },
    "owner": {
      "type": "elastic",
      "github": "elastic/elastic-agent-data-plane"
    },
    "categories": [
      "custom",
      "custom_logs"
    ],
    "signature_path": "/epr/filestream/filestream-2.3.0.zip.sig"
  }
]

```

is there a version of filestream package that is compatible with v.8.19?

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [March 14, 2026, 9:21am UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446/5 "2026-03-14T09:21:01Z")

</div>

Yeap way back 🙂

```auto
$ curl -s 'https://epr.elastic.co/search?package=filestream&all=true' | jq -r '.[] | " \(.version) \(.conditions)"'
 0.0.1 {"kibana":{"version":"^8.15.0"}}
 0.1.0 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.0.1 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.1.0 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.1.1 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.1.2 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.1.3 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.1.4 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.1.5 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.2.0 {"kibana":{"version":"^8.15.0 || ^9.0.0"}}
 1.3.0 {"kibana":{"version":"^9.2.0"}}
 2.0.1 {"kibana":{"version":"^9.2.0"}}
 2.1.0 {"kibana":{"version":"^9.2.0"}}
 2.1.1 {"kibana":{"version":"^9.2.0"}}
 2.1.2 {"kibana":{"version":"^9.2.0"}}
 2.2.0 {"kibana":{"version":"^9.2.0"}}
 2.3.0 {"kibana":{"version":"^9.2.0"}}
 2.3.1 {"kibana":{"version":"^9.2.0"}}
 2.3.2 {"kibana":{"version":"^9.2.0"}}
 2.3.3 {"kibana":{"version":"^9.2.0"}}

```

Installing v.1.2.0 now shows up in our v.8.19 Kibana UI 👀

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 14, 2026, 2:09pm UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446/6 "2026-03-14T14:09:06Z")

</div>

Yeah, some integration versions will have a Kibana minimum requirement, if you keep only the last version on EPR, not sure how it works, they may not show up.

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [March 15, 2026, 12:36pm UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446/7 "2026-03-15T12:36:00Z")

</div>

Yeap, UI only shows compatible integrations, which makes sense.
