# \#integrations

**URL:** https://discuss.elastic.co/tag/integrations/104.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Indices Stack Monitoring - Cannot expand \`inner\_hits\` for collapse field \`index\_stats.index\`](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205)

<div class="topic-metadata">

**Author:** [@adminunix](https://discuss.elastic.co/u/adminunix)\
**Replies:** 3\
**Last updated:** [August 12, 2026, 3:53pm UTC](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205 "2026-08-12T15:53:42Z")

</div>

Hello, We have updated to Elasticsearch 9.4.0, Kibana 9.4.0, Elastic Agent 9.4.0 and Elasticsearch monitoring integration 1.20.2. Since then, the Stack Monitong Indices tab is broken and does not load the dashboard: …

---

## [In oracle integration, The sysmetric dataset is not being populated ? Could it be because of the oracle db being a PDB instead of CDB?](https://discuss.elastic.co/t/in-oracle-integration-the-sysmetric-dataset-is-not-being-populated-could-it-be-because-of-the-oracle-db-being-a-pdb-instead-of-cdb/387344)

<div class="topic-metadata">

**Author:** [@Mansi\_Sharma1](https://discuss.elastic.co/u/Mansi_Sharma1)\
**Replies:** 0\
**Last updated:** [June 26, 2026, 9:08am UTC](https://discuss.elastic.co/t/in-oracle-integration-the-sysmetric-dataset-is-not-being-populated-could-it-be-because-of-the-oracle-db-being-a-pdb-instead-of-cdb/387344 "2026-06-26T09:08:02Z")

</div>

Hi, I integrated a oracle db using elastic agent oracle integration, the rest of the datastream\_datasets are populating all of the fields execept for the SYSMETRIC one. I even checked with the DB team and they have gra…

---

## [Crowdstrike Integration Degraded](https://discuss.elastic.co/t/crowdstrike-integration-degraded/385987)

<div class="topic-metadata">

**Author:** [@4l13v](https://discuss.elastic.co/u/4l13v)\
**Replies:** 2\
**Last updated:** [April 22, 2026, 1:23pm UTC](https://discuss.elastic.co/t/crowdstrike-integration-degraded/385987 "2026-04-22T13:23:18Z")

</div>

The problem is 3 months ago, I have integrated Crowdstrike via API. It okay, and I am getting alerts from Falcon without problems. But Fleet server came unhealthy in these days. {failed to decode discover body: EOF} . …

---

## [Qualys VMDR Integration Missing Data](https://discuss.elastic.co/t/qualys-vmdr-integration-missing-data/385834)

<div class="topic-metadata">

**Author:** [@difi80211g](https://discuss.elastic.co/u/difi80211g)\
**Replies:** 1\
**Last updated:** [April 10, 2026, 5:49am UTC](https://discuss.elastic.co/t/qualys-vmdr-integration-missing-data/385834 "2026-04-10T05:49:10Z")

</div>

I have setup the Qualys VMDR integration and all checks seem to be fine, however i am not getting any asset or KB data, but i am getting the User activity logs. I verified permissions in qualys and api logs in qualys bu…

---

## [Oracle Integration condition](https://discuss.elastic.co/t/oracle-integration-condition/385431)

<div class="topic-metadata">

**Author:** [@hubkos](https://discuss.elastic.co/u/hubkos)\
**Replies:** 4\
**Last updated:** [March 17, 2026, 9:51pm UTC](https://discuss.elastic.co/t/oracle-integration-condition/385431 "2026-03-17T21:51:49Z")

</div>

Hi all, is there a possibility to add a condition for Oracle Integration? Just like PostgreSQL has one, I’d like to “activate” Oracle Integration based on agent Providers. Thanks and greetings, Hubert

---

## [Where to find the Custom Logs (Filestream) integration?](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 6\
**Last updated:** [March 15, 2026, 12:36pm UTC](https://discuss.elastic.co/t/where-to-find-the-custom-logs-filestream-integration/385446 "2026-03-15T12:36:00Z")

</div>

We’re trying to run an Air Gapped EPR registry v.1.37.0 with a minimal set of selected integration packages, but kibana v.8.19.9 first of all shows a larger(e) set of integrations (wondering why?) to select among in th…

---

## [Tenable Security Center Integration API Issues](https://discuss.elastic.co/t/tenable-security-center-integration-api-issues/385400)

<div class="topic-metadata">

**Author:** [@AnakinWasRight](https://discuss.elastic.co/u/AnakinWasRight)\
**Replies:** 0\
**Last updated:** [March 11, 2026, 12:14am UTC](https://discuss.elastic.co/t/tenable-security-center-integration-api-issues/385400 "2026-03-11T00:14:09Z")

</div>

Self signed cert for Sec Center. The ssl side of the house seems to be fine as the agent is fully healthy. Generated the access/secret key in sec center with an administration account and enabled allow api keys in the gu…

---

## [Error when configuring Cloudflare LogPush integration for R2](https://discuss.elastic.co/t/error-when-configuring-cloudflare-logpush-integration-for-r2/380052)

<div class="topic-metadata">

**Author:** [@taprove](https://discuss.elastic.co/u/taprove)\
**Replies:** 4\
**Last updated:** [January 8, 2026, 3:18pm UTC](https://discuss.elastic.co/t/error-when-configuring-cloudflare-logpush-integration-for-r2/380052 "2026-01-08T15:18:54Z")

</div>

No matter what configurations I try with the Cloudflare Logpush integration, the following error shows in the log: \[elastic\_agent\]\[error\] Unit state changed aws-s3-default-aws-s3-cloudflare-xxxxxx-xxxx-xxx-xxx-xxxxxxxxx…

---

## [Windows and Linux Integration to collect inventory data for Defend coverage (and CMDB)](https://discuss.elastic.co/t/windows-and-linux-integration-to-collect-inventory-data-for-defend-coverage-and-cmdb/384117)

<div class="topic-metadata">

**Author:** [@pimthu](https://discuss.elastic.co/u/pimthu)\
**Replies:** 0\
**Last updated:** [December 16, 2025, 2:33pm UTC](https://discuss.elastic.co/t/windows-and-linux-integration-to-collect-inventory-data-for-defend-coverage-and-cmdb/384117 "2025-12-16T14:33:58Z")

</div>

We are an MSSP for many organisations and would like to produce Elastic Defend coverage figures. Currently, we need to collect through various cumbersome ways the AD or inventory data from Windows, Mac and Linux clients …

---

## [How to define dynamic templates for geo\_point in a custom Integration (Fleet + elastic-package)?](https://discuss.elastic.co/t/how-to-define-dynamic-templates-for-geo-point-in-a-custom-integration-fleet-elastic-package/382524)

<div class="topic-metadata">

**Author:** [@B\_Grimm](https://discuss.elastic.co/u/B_Grimm)\
**Replies:** 2\
**Last updated:** [November 11, 2025, 12:39pm UTC](https://discuss.elastic.co/t/how-to-define-dynamic-templates-for-geo-point-in-a-custom-integration-fleet-elastic-package/382524 "2025-11-11T12:39:40Z")

</div>

How to define dynamic templates for geo\_point in a custom Integration (Fleet + elastic-package)? Context I’m building a custom Elastic Integration with elastic-package (Fleet-managed data streams). Some events contain …

---

## [Extending Tomcat integration to collect additional JMX metrics (e.g., java\_lang\_OperatingSystem, oracle\_ucp\_admin)](https://discuss.elastic.co/t/extending-tomcat-integration-to-collect-additional-jmx-metrics-e-g-java-lang-operatingsystem-oracle-ucp-admin/382984)

<div class="topic-metadata">

**Author:** [@DIPTOPOL](https://discuss.elastic.co/u/DIPTOPOL)\
**Replies:** 0\
**Last updated:** [October 26, 2025, 3:07pm UTC](https://discuss.elastic.co/t/extending-tomcat-integration-to-collect-additional-jmx-metrics-e-g-java-lang-operatingsystem-oracle-ucp-admin/382984 "2025-10-26T15:07:28Z")

</div>

I am currently exploring the Tomcat integration using the Elastic Agent. From my observations, the default metrics collected through the JMX Prometheus exporter do not include all available data. For example, metric sets…

---

## [IIS Integration - metrics datasets (app pools and websites)](https://discuss.elastic.co/t/iis-integration-metrics-datasets-app-pools-and-websites/382464)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [October 6, 2025, 6:20pm UTC](https://discuss.elastic.co/t/iis-integration-metrics-datasets-app-pools-and-websites/382464 "2025-10-06T18:20:54Z")

</div>

Hello, We have an IIS server hosting several app pools. The IIS dataset retrieves websites, web servers, and application pools. I was wondering how I can correlate the website with its associated app pool to provide a b…

---

## [Custom File stream Integration - Network Shares](https://discuss.elastic.co/t/custom-file-stream-integration-network-shares/382288)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [September 29, 2025, 5:49pm UTC](https://discuss.elastic.co/t/custom-file-stream-integration-network-shares/382288 "2025-09-29T17:49:18Z")

</div>

Hello, I am using v1.2.0 of the Custom Logs (Filestream). Normally this integration works for collecting from a local folder, but I can’t seem to grab the logs from a network share. My first assumption is that perhaps …

---

## [Custom Filestream Integration - Adding mappings](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 5\
**Last updated:** [August 26, 2025, 5:17pm UTC](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316 "2025-08-26T17:17:16Z")

</div>

Hello, I am having trouble with adding custom mapping to my data stream built from custom filestream input. It appears that once the data comes in and build the data stream, the data stream is “managed”. It doesn’t al…

---

## [Elastic agent Windows integration issue](https://discuss.elastic.co/t/elastic-agent-windows-integration-issue/380771)

<div class="topic-metadata">

**Author:** [@f4n-1nh1b1t10n](https://discuss.elastic.co/u/f4n-1nh1b1t10n)\
**Replies:** 2\
**Last updated:** [August 11, 2025, 4:07pm UTC](https://discuss.elastic.co/t/elastic-agent-windows-integration-issue/380771 "2025-08-11T16:07:53Z")

</div>

Hello, first post here. Short description of the current environment: kibana and elasticsearch on 1 host (virtualized in a vbox) standalone elastic agent on another host (a windows laptop) with Windows (v3.1.0) & sys…

---

## [Get agent event logs via Elastic Agent Integration](https://discuss.elastic.co/t/get-agent-event-logs-via-elastic-agent-integration/372860)

<div class="topic-metadata">

**Author:** [@edemir](https://discuss.elastic.co/u/edemir)\
**Replies:** 8\
**Last updated:** [August 7, 2025, 11:47am UTC](https://discuss.elastic.co/t/get-agent-event-logs-via-elastic-agent-integration/372860 "2025-08-07T11:47:27Z")

</div>

After the 8.15.0 update, with the separation of event logs belonging to filebeat and metricbeat, we can no longer monitor the event logs belonging to the agent via Kibana with the Elastic Agent integration. There is only…

---

## [Fortigate Integration - Separation of logs datastream based on a field value](https://discuss.elastic.co/t/fortigate-integration-separation-of-logs-datastream-based-on-a-field-value/380767)

<div class="topic-metadata">

**Author:** [@Knight7](https://discuss.elastic.co/u/Knight7)\
**Replies:** 10\
**Last updated:** [August 6, 2025, 7:10pm UTC](https://discuss.elastic.co/t/fortigate-integration-separation-of-logs-datastream-based-on-a-field-value/380767 "2025-08-06T19:10:38Z")

</div>

Hello, We have integrated Fortinet Fortigate Firewall logs to our SIEM ELK using the Elastic Agent integration. We created also a custom ingest pipeline that separates the logs (for example forward) and send them to a d…

---

## [Barracuda CloudGen Integration - Agent listens on port 5044 but no data in Kibana](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-listens-on-port-5044-but-no-data-in-kibana/380668)

<div class="topic-metadata">

**Author:** [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Replies:** 1\
**Last updated:** [August 4, 2025, 12:37pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-listens-on-port-5044-but-no-data-in-kibana/380668 "2025-08-04T12:37:52Z")

</div>

Hello Everyone, I am in the process of setting up the ELK stack. I have already successfully integrated some windows server machines (through agents), some linux hosts and our switches. I am running the latest version o…

---

## [Microsoft DNS Server integration - remove dot at domainn name's end](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457)

<div class="topic-metadata">

**Author:** [@Zer0-cyber-web](https://discuss.elastic.co/u/Zer0-cyber-web)\
**Replies:** 8\
**Last updated:** [August 4, 2025, 6:15am UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457 "2025-08-04T06:15:55Z")

</div>

Hi! Could someone point me where to look: in Microsoft DNS Server index, there is a field with requested domain name - dns.question.name. It contains domain name that was requested by client. The only problem is that af…

---

## [Elastic Agent Fortinet Module 12 Hours Delay Log](https://discuss.elastic.co/t/elastic-agent-fortinet-module-12-hours-delay-log/380377)

<div class="topic-metadata">

**Author:** [@adilraad2001](https://discuss.elastic.co/u/adilraad2001)\
**Replies:** 1\
**Last updated:** [July 23, 2025, 3:08pm UTC](https://discuss.elastic.co/t/elastic-agent-fortinet-module-12-hours-delay-log/380377 "2025-07-23T15:08:19Z")

</div>

Hello, I've installed the Fleet Server, Elastic Agent, and Fortinet module with TCP (im using fortianalyzer that send logs of all my fortigate) integration in the fleet server machine. But the log from FortiGate to elast…

---

## [New Custom Logs (Filestream) integration does not create a dataset specific index template](https://discuss.elastic.co/t/new-custom-logs-filestream-integration-does-not-create-a-dataset-specific-index-template/380179)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 2\
**Last updated:** [July 17, 2025, 6:57am UTC](https://discuss.elastic.co/t/new-custom-logs-filestream-integration-does-not-create-a-dataset-specific-index-template/380179 "2025-07-17T06:57:10Z")

</div>

Hello Everyone, due to deprecation of old Custom Logs integration I'm now configuring the new Custom Logs (Filestream) integration, and I'm wondering why this integration does not create a managed dataset specific index…

---

## [Sysmon for Linux Integration not sending to data\_stream.dataset: "sysmon\_linux.log"](https://discuss.elastic.co/t/sysmon-for-linux-integration-not-sending-to-data-stream-dataset-sysmon-linux-log/380077)

<div class="topic-metadata">

**Author:** [@vector\_vulture](https://discuss.elastic.co/u/vector_vulture)\
**Replies:** 6\
**Last updated:** [July 14, 2025, 4:19pm UTC](https://discuss.elastic.co/t/sysmon-for-linux-integration-not-sending-to-data-stream-dataset-sysmon-linux-log/380077 "2025-07-14T16:19:07Z")

</div>

Hi. I am new to ELK stack, and I cannot find this problem online, so I am posting here. I have a self hosted ELK stack the newest version with the agents version 9.0.3. I also have 1 agent deployed as a fleet server via …

---

## [Missing "Service Group" Integration in Citrix ADC with Elastic](https://discuss.elastic.co/t/missing-service-group-integration-in-citrix-adc-with-elastic/377234)

<div class="topic-metadata">

**Author:** [@ghyslaindetry](https://discuss.elastic.co/u/ghyslaindetry)\
**Replies:** 1\
**Last updated:** [May 21, 2025, 11:09pm UTC](https://discuss.elastic.co/t/missing-service-group-integration-in-citrix-adc-with-elastic/377234 "2025-05-21T23:09:32Z")

</div>

Hello Elastic Community, I am currently using Citrix ADC and have integrated it with Elastic to monitor various metrics and logs. While the integration works well for interfaces, virtual servers (lbvserver), services, s…

---

## [Oracle Integration Not Sending .aud logs to Elastic](https://discuss.elastic.co/t/oracle-integration-not-sending-aud-logs-to-elastic/378102)

<div class="topic-metadata">

**Author:** [@rklee](https://discuss.elastic.co/u/rklee)\
**Replies:** 2\
**Last updated:** [May 16, 2025, 2:48pm UTC](https://discuss.elastic.co/t/oracle-integration-not-sending-aud-logs-to-elastic/378102 "2025-05-16T14:48:12Z")

</div>

In the oracle integration policy, I added the path where the oracle audit logs are located. But I am not receiving any of the logs. Any ideas? My Systems integrations logs are sending just fine.

---

## [Office 365 Integration Issue](https://discuss.elastic.co/t/office-365-integration-issue/378103)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 5\
**Last updated:** [May 15, 2025, 2:49pm UTC](https://discuss.elastic.co/t/office-365-integration-issue/378103 "2025-05-15T14:49:35Z")

</div>

Hello, Anyone experiencing similar issues with the Office 365 integration? It was working fine for months and then it error out today

---

## [Elastic-agent ingest interval](https://discuss.elastic.co/t/elastic-agent-ingest-interval/357921)

<div class="topic-metadata">

**Author:** [@nml1988](https://discuss.elastic.co/u/nml1988)\
**Replies:** 2\
**Last updated:** [May 14, 2025, 8:42pm UTC](https://discuss.elastic.co/t/elastic-agent-ingest-interval/357921 "2025-05-14T20:42:46Z")

</div>

Hi people! I need your help with a requirement. I installed an elastic-agent 8.11.4 on a windows server to read and send data from .csv files by integrating fleet 'custom logs'. The agent was installed by default. Cu…

---

## [ESXI Logs integration request](https://discuss.elastic.co/t/esxi-logs-integration-request/377946)

<div class="topic-metadata">

**Author:** [@Knight7](https://discuss.elastic.co/u/Knight7)\
**Replies:** 4\
**Last updated:** [May 8, 2025, 5:27pm UTC](https://discuss.elastic.co/t/esxi-logs-integration-request/377946 "2025-05-08T17:27:27Z")

</div>

Hello, It would be nice if there is a custom integration for the Vmware ESXI logs.

---

## [Integration Development - CEL State Tracking Questions](https://discuss.elastic.co/t/integration-development-cel-state-tracking-questions/377528)

<div class="topic-metadata">

**Author:** [@logalicious](https://discuss.elastic.co/u/logalicious)\
**Replies:** 1\
**Last updated:** [April 27, 2025, 9:49pm UTC](https://discuss.elastic.co/t/integration-development-cel-state-tracking-questions/377528 "2025-04-27T21:49:33Z")

</div>

Hello, I have a question about tracking state in CEL programs. Why do I need to publish my state values at the end of my program or wrap the program with state.with() to reuse values defined in my state? State.with() E…

---

## [Integration Error - OpenCTI](https://discuss.elastic.co/t/integration-error-opencti/376591)

<div class="topic-metadata">

**Author:** [@deathgame](https://discuss.elastic.co/u/deathgame)\
**Replies:** 1\
**Last updated:** [March 31, 2025, 3:20pm UTC](https://discuss.elastic.co/t/integration-error-opencti/376591 "2025-03-31T15:20:51Z")

</div>

Hello, After installing Opencti in a docker environment, I want to get the threat indicators to Elasticsearch. For that, I used the Elastic Agent integration for OpenCTI. However, this integration always shows me this …

---

## [DNS Integration stopped working](https://discuss.elastic.co/t/dns-integration-stopped-working/376214)

<div class="topic-metadata">

**Author:** [@ben-sec](https://discuss.elastic.co/u/ben-sec)\
**Replies:** 1\
**Last updated:** [March 24, 2025, 7:19am UTC](https://discuss.elastic.co/t/dns-integration-stopped-working/376214 "2025-03-24T07:19:23Z")

</div>

Hi! I'm running the Windows DNS integration and was successfully ingesting DNS logs from three different servers using Elastic Agent 8.14.3. After upgrading to 8.17.3, I no longer receive DNS logs from these servers. Ho…

[Next page](https://discuss.elastic.co/tag/integrations/104.md?match_all_tags=true&page=1&tags%5B%5D=integrations)
