Yeah, I see the log message is complaining about not having the required privileges to do the action.
The error is:
"action [indices:admin/auto_create] is unauthorized for API key id [v5R8FoIBh-MY92CQc0UC] of user [elastic/fleet-server] on indices [logs-generic-default], this action is granted by the index privileges [auto_configure,create_index,manage,all]"
The message hints about the required privileges; TBH, this error is unexpected because the fleet server manages the agent's API keys.
The message mentions the API key belongs to the user "elastic/fleet-server"; could you please check the privileges assigned to the service account named "elastic/fleet-server"?
You can do it by visiting Dev Tools > Console and sending this request:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.