Recently upgraded ELK cluster from 9.3.2 to 9.4.4. On older version had AWS integration of version 6.20, on new cluster upgraded it to 7.1 latest. Prior to upgrade, we had 1 Elastic agent with this integration 6.2 (agent also went from 9.3.2. to 9.4.4 before upgrading integration). After upgrade i got error in "policy" in integration, that agent is not compatible (yet agent was already 9.4.4 prior to upgrading integration)
After removing integration from policy only, and adding it again that error dissapeared but in Fleet, agent had "i" status about that policy is stuck on lower version
I tried to remove integration from policy again but got better error, that agent was unable to sync Agent policy. I did not try to setup other integration to verify if this is just UI glitch or it seriosly does not update. elastic-agent status via cli was reporting healthy.
Not sure if this is UI glitch, Bug, or am i misconfiguring something now. I tried to add AWS integration on different agent, which never had aws integration, and it got bricked too. So i added integration back to policy with nothing configured in it, just so it at least show it updates agent policy sucesfully.
For the agents running the AWS integration make sure that they are on version 9.4.4 and try the workaround of reassigning the agent to the same policy.
For example, if the policy is named aws-policy, select the agents with issues in the Fleet UI, go into Actions > Assign to new policy, and choose the same aws-policy.
This is expected to fix the outdated policy and future change should sync as well, if this do not work, then this may be a new unreported bug related to version specific agent policies.
Regarding issue "Outdated policy" after removing AWS integration from policy, reassigning policy worked.
For the issue that agent is latest as well as integration, and agent has that "i" alert about "version specific policy used" it did not fix. Will check if this is mentioned in bugs. Thank you very much.
Yeah, I don't think this was reported yet or if it was solved by the recent changes, just checked on my cluster and I have the same thing, but this is less problematic as it seems just a UI information, not related to sync.
I've just made a comment on the main issue tracking this to see if a separed issue is required.
Sorry by info-error i meant the latter:
This agent uses a version-specific policy because it doesn't meet the agent version requirements of some integrations.
After reassigning the policy it did dissapear for some time and i tought it is fixed but it reappeared. Trying it again atm. Took around minute to reappear
One more thing that Claude AI pointed out, which i used to help me troubleshoot, was that policy id had suffix #9.4
827fe189-......6fa67575cbc1#9.4
which it said it was added as version-hold suffix, possibly causing that info-alert. No idea if true, just trowing it here to inquire.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.