# Agent returns access denied

**URL:** <https://discuss.elastic.co/t/agent-returns-access-denied/315310>\
**Category:** Elastic Agent\
**Created:** [September 27, 2022, 8:21pm UTC](https://discuss.elastic.co/t/agent-returns-access-denied/315310 "2022-09-27T20:21:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![simpleman](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@simpleman](https://discuss.elastic.co/u/simpleman)\
**Post date:** [September 27, 2022, 8:21pm UTC](https://discuss.elastic.co/t/agent-returns-access-denied/315310/1 "2022-09-27T20:21:34Z")

</div>

We have an air gapped network. We use Symantec Endpoint Security. We have successfully installed ELK 8.4.1 on VM. On the same VM we have the fleet server running. The registry is running on docker in another VM. I try to collect logs from Symantec using Elastic Agent. The agent is healthy and is sending correctly to the Elasticsearch all the metrics and stuff that comes with the Symantec integration.  
But......  
I can't send logs from the Symantec... I tried both UDP and log files. Nothing works. On top of that, using the agent on the Symantec VM to read dumped logs, gives an `Access Denied` on the first log file and nothing happens. Forgive me that I can't provide the exact message body, I will write it down tomorrow. Any help?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2022, 8:22pm UTC](https://discuss.elastic.co/t/agent-returns-access-denied/315310/2 "2022-10-25T20:22:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
