# Barracuda Cloudgen Integration / Agent possibly broken?

**URL:** <https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785>\
**Category:** Elastic Agent\
**Created:** [August 6, 2025, 7:38am UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785 "2025-08-06T07:38:20Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 6, 2025, 7:38am UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/1 "2025-08-06T07:38:20Z")

</div>

Good Morning Everyone,

I have the following situation:

- The Barracuda firewall is configured as described [here](https://www.elastic.co/docs/reference/integrations/barracuda_cloudgen_firewall/#:~:text=For%20a%20detailed,of%20this%20integration)
- The integration is configured as per default values
  - The agent is enrolled with the right integration policy

- I am receiving data from the firewall on the machine where the agent is installed, verified with ` sudo tcpdump -A -s 0 'dst port 5044'`
- The Agent appears to be healthy from kibana and on the agent host

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f0db0f3d8c8d31376729c2837819494d71464fe0.png)

```auto
 /opt/Elastic/Agent/elastic-agent status
┌─ fleet
│ └─ status: (HEALTHY) Connected
└─ elastic-agent
   └─ status: (HEALTHY) Running

```

- Checking with `sudo lsof -i :5044` we can see that the agent is listening on the right port

```auto
lsof -i :5044
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
agentbeat 2782 root 6u IPv4 137677 0t0 TCP localhost:5044 (LISTEN)

```

- There is communication between the agent and Elasticsearch as I can sort by `agent.id` and see its logs (but never data from the firewall)

_(there was an image here, but I cannot have more than one image per post as a new user)_

- BUT, **there are no barracuda related logs in Elasticsearch / Kibana**

I cannot undestand where it is going wrong as everything appears to be healthy and running, but very clearly is not.

Logs show no error, besides a minor warning that files that filebeat is monitoring are too small to be ingested.

For testing purposes, I configured tried configuring Logstash manually and data was being accepted and forwarded to Elasticsearch

---

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 6, 2025, 8:52am UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/2 "2025-08-06T08:52:24Z")

</div>

Agent is communicating with elasticsearch

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d50e97e6e5976b3ec9f2da6a225b8c8825e7488d.png)

---

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 6, 2025, 8:56am UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/3 "2025-08-06T08:56:58Z")

</div>

logs of the agent (set to debug)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d64d3b881d152e3c79cb3290ea51ecd61a3f8b5.png)

---

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 6, 2025, 1:25pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/4 "2025-08-06T13:25:46Z")

</div>

It seems analogous to this issue here [Elastic agent Does not receive traffic, but it reaches the Linux server - Elastic Stack / Kibana - Discuss the Elastic Stack](https://discuss.elastic.co/t/elastic-agent-does-not-receive-traffic-but-it-reaches-the-linux-server/330100/5) but it wasn't solved either

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 6, 2025, 3:13pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/5 "2025-08-06T15:13:24Z")

</div>

Can you share your integration configuration, please...

What Integration? Version? The actual Integration settings.

Can you open up the time frame on the Discover to 30 days ago to 24 Hours in the Future (yup timezone issues can cause this)

Can you go to Stack Management -\> Index Management -\> Data Streams and see if there is a barracuda data stream?

Go to Kibana -\> Dev Tools run this show results

`GET _cat/indices/*bar*?v`

You can bump up the Agent Logs to Debug on the agent logs screen

 ![Screenshot 2025-08-06 at 7.44.20 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/3/237607566e282c36255e026afea0021ac99f512d.png)

---

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 7, 2025, 7:24am UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/6 "2025-08-07T07:24:39Z")

</div>

My integration version is v1.6.0 and settings can be seen in the first screenshot (just default settings). I have tried changing the “listen address” to `0.0.0.0` and the IP of the interface / host to no avail.

Similarly putting the line `enabled: false` in the SSL yaml configuration also didn’ change anything.

Switching the time range from 30 days ago - 24 hours from now, did not make any barracuda logs surface.

Currently there is no Barracuda Data stream present under Stack Management → Index Management → Data Streams. (There is under index templates, I guess verifying that the integration is installed)

Running `GET _cat/indices/*bar*?v` only returns the following line

`health status index uuid pri rep docs.count docs.deleted store.size pri.store.size dataset.size`

I've set my logs to debug, I cannot see error messages or other indications of what's going wrong. Here an extract of them [https://paste.opensuse.org/pastes/53c14d1fe99b](https://paste.opensuse.org/pastes/53c14d1fe99b)

Thank you for looking at my issue

EDIT: Here my agent policy [openSUSE Paste](https://paste.opensuse.org/pastes/88150d6f9868)

---

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 7, 2025, 12:53pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/7 "2025-08-07T12:53:32Z")

</div>

This might be of interest to the elastic team, as I just consulted with some industry peers in my area and the reply I got was "the barracuda cloudgen integration doesn't work, you need to use logstash". Weird bug.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 7, 2025, 1:45pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/8 "2025-08-07T13:45:35Z")

</div>

> [@cow\_on\_lsd](#):
>
> My integration version is v1.6.0

Perhaps you mean 1.16.0 which is the latest... looks like it when I look at the config.

You would definitely need to bind to `0.0.0.0` OR the incoming network available IP `locallhost` will not work.

Can you try that and share the logs again...

> [@cow\_on\_lsd](#):
>
> This might be of interest to the elastic team, as I just consulted with some industry peers in my area and the reply I got was "the barracuda cloudgen integration doesn't work, you need to use logstash". Weird bug.

Any more details you can provide on this?

> [@cow\_on\_lsd](#):
>
> For testing purposes, I configured tried configuring Logstash manually and data was being accepted and forwarded to Elasticsearch

@andrewkroh .... Any ideas?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 7, 2025, 2:16pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/9 "2025-08-07T14:16:31Z")

</div>

> [@cow\_on\_lsd](#):
>
> `agentbeat 2782 root 6u IPv4 137677 0t0 TCP localhost:5044 (LISTEN)`

You need to use `0.0.0.0` in the configuration or the private ip address of the VM that is reachable by other servers, localhost will not work.

> [@cow\_on\_lsd](#):
>
> For testing purposes, I configured tried configuring Logstash manually and data was being accepted and forwarded to Elasticsearch

What was the configuration pipeline that you used on Logstash? Can you also share a sample of the messages that are being received?

Can you share a screenshot of the configuration Barracuda side?

---

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 7, 2025, 2:20pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/10 "2025-08-07T14:20:47Z")

</div>

> [@stephenb](#):
>
> Perhaps you mean 1.16.0 which is the latest... looks like it when I look at the config.

Yes it was a typo.

> [@leandrojmp](#):
>
> You need to use `0.0.0.0` in the configuration or the private ip address of the VM that is reachable by other servers, localhost will not work.

It wasn't working with 0.0.0.0 either. Here an extract of the logs with 0.0.0.0 as listen address set (logs [here as text](https://paste.opensuse.org/pastes/518dc5d3e2b8) )

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/7/47333c3cb297919024bad09d530019ce72b0a7af.png)

> [@stephenb](#):
>
> Any more details you can provide on this?

Not really, it is the literal quote I got.

Again, thank you for your time on this.

---

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 7, 2025, 2:36pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/11 "2025-08-07T14:36:09Z")

</div>

> [@leandrojmp](#):
>
> You need to use `0.0.0.0` in the configuration or the private ip address of the VM that is reachable by other servers, localhost will not work.

Thank you for the suggestion, in my experimentation it was set to 0.0.0.0 most of the time, and have proceeded to put it as 0.0.0.0 again. Sadly it did not fix it.

[This](https://paste.opensuse.org/pastes/05edea82716b) was the configuration pipeline on logstash (which was working)

Firewall is configured like this (as per integration documentation)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e2dddaa990a636f0b9ab161fa1fd3d54214bc0a4.png)

> [@leandrojmp](#):
>
> Can you also share a sample of the messages that are being received?

Just the tcpdump?

Thank you as well for taking your time with this.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 7, 2025, 3:22pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/12 "2025-08-07T15:22:56Z")

</div>

> [@cow\_on\_lsd](#):
>
> Thank you for the suggestion, in my experimentation it was set to 0.0.0.0 most of the time, and have proceeded to put it as 0.0.0.0 again. Sadly it did not fix it.

You need to leave it as `0.0.0.0` to even be able to troubleshoot, if you set it as localhost it will only receive requests generated locally, so it needs to be set as `0.0.0.0`.

What does your input configuration looks like, specially the SSL configuration? Can you share a screenshot of your configuration like this?

 ![Screenshot from 2025-08-07 12-18-36](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8df2bff1fe2e07e4aa488dec245b4e07929ed4bf.png)

I do not have Barracuda, but it looks like that it will send logs using SSL, so if your input SSL configuration is not correct it may not listen for SSL connections and just discard it.

> [@cow\_on\_lsd](#):
>
> Just the tcpdump?

No, a sample message from the Logstash output if you have a stdout output configured, it will be present on the log file.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 7, 2025, 5:50pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/13 "2025-08-07T17:50:48Z")

</div>

Ahhhh Now looking at the docs / sample yes looks like it is definitely SSL so you need to enable SSL and Provide Cert

> **[Configure SSL | Beats](https://www.elastic.co/docs/reference/beats/filebeat/configuration-ssl#ssl-client-config)**
>
> You can specify SSL options when you configure: outputs that support SSL, the Kibana endpoint. Example output config with SSL enabled: Also see Secure...

```auto
enabled: true
certificate: |
  -----BEGIN CERTIFICATE-----
  MIIF2jCCA8KgAwIBAgIBAjANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEW
  MBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEcMBoGA1UECRMTV2VzdCBFbCBDYW1pbm8g
  UmVhbDEOMAwGA1UEERMFOTQwNDAxEDAOBgNVBAoTB0VsYXN0aWMwHhcNMjMxMDMw
  MTkyMzU4WhcNMjMxMDMxMTkyMzU4WjB2MQswCQYDVQQGEwJVUzEWMBQGA1UEBxMN
  U2FuIEZyYW5jaXNjbzEcMBoGA1UECRMTV2VzdCBFbCBDYW
....
  -----END CERTIFICATE-----
key: |
    -----BEGIN PRIVATE KEY-----
    MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDXHufGPycpCOfI
    sjl6cRn8NP4DLxdIVEAHFK0jMRDup32UQOPW+DleEsFpgN9/ebi9ngdjQfMvKnUP
    Zrl1HTwVhOJfazGeoJn7vdDeQebhJfeDXHwX2DiotXyUPYu1ioU45UZDAoAZFj5F
    KJLwWRUbfEbRe8yO+wUhKKxxkApPbfw+wUtBicn1RIX7W1nBRABt1UXKDIRe5FM2
    MKfqhEq
...
    -----END PRIVATE KEY-----

```

 ![Screenshot 2025-08-07 at 10.58.55 AM](https://us1.discourse-cdn.com/elastic/original/3X/3/4/34af37789caff5ff4e07190e40e85321e7352d04.png)

---

<div class="post-metadata">

**Author:** ![cow\_on\_lsd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cow_on_lsd/32/144438_2.png) [@cow\_on\_lsd](https://discuss.elastic.co/u/cow_on_lsd)\
**Post date:** [August 8, 2025, 7:51am UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/14 "2025-08-08T07:51:22Z")

</div>

Oha. This was the solution. As I am not the only one experiencing this problem, I think it might be smart to explicit it on the integrations page. I would have not found this configuration option without your help.

Thanks to everyone involved in this thread.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 8, 2025, 1:13pm UTC](https://discuss.elastic.co/t/barracuda-cloudgen-integration-agent-possibly-broken/380785/15 "2025-08-08T13:13:06Z")

</div>

Yeah, unfortunately this is a long time issue regarding documentation, a lot of things do not have enough examples, some have none.

Regarding integrations, I think there are zero examples on how to configure the integrations, some are pretty straigh forward, but there are some integrations that have some requirements in the configuration that is not clear in the documentation.

As a user with a support contract I've been mentioning this on every interation I have with Elastic, that the lack of documentation is a big problem.
