I need your help!
I have a self-hosted ELK (not cloud)
I've enrolled the Fleet Server for SIEM using this manual for a self-managed server with default parameters in
I need to connect hosts to my elk using elk agents.
It looks like Fleet Server works well (netstat and kibana screenshots)
It is healthy and has a connection to elastic.
But when I'm trying to connect another ELK Agent, the Fleet server refuse it
Iptables is ok (not using it because of cloud infra), the port is open
My infra hosted in the GCP
The firewall has been configured to allow connections inside the local network from target hosts to the fleet server.
If I make
curl -k https://FLEET_SERVER:8220/api/status from the target machine to fleet
So it has a connect to the fleet, I think, am I?
what is the problem? or maybe you have any advice?
Because now I have no idea at all.
Also I've made tcpdump from two different host. maybe it'll be useful (can't attach the dump file)
Thank you for any help!