# Can't enroll agent to fleet: (Fail to enroll: fail to execute request to fleet-server)

**URL:** <https://discuss.elastic.co/t/cant-enroll-agent-to-fleet-fail-to-enroll-fail-to-execute-request-to-fleet-server/285682>\
**Category:** Elasticsearch\
**Tags:** fleet\
**Created:** [October 1, 2021, 1:14pm UTC](https://discuss.elastic.co/t/cant-enroll-agent-to-fleet-fail-to-enroll-fail-to-execute-request-to-fleet-server/285682 "2021-10-01T13:14:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![John9](https://avatars.discourse-cdn.com/v4/letter/j/f6c823/32.png) [@John9](https://discuss.elastic.co/u/John9)\
**Post date:** [October 1, 2021, 1:14pm UTC](https://discuss.elastic.co/t/cant-enroll-agent-to-fleet-fail-to-enroll-fail-to-execute-request-to-fleet-server/285682/1 "2021-10-01T13:14:34Z")

</div>

Hello,

I've been trying to setup a testing ELK stack environment for learning purposes. I am running:  
VM1 = Ubuntu Server 20.04 running Elasticsearch / Kibana with IP 172.16.0.27. Minimal Security is on.  
VM2 = Ubuntu Server 20.04 running an elastic-agent that is enrolled as fleet server with IP 172.16.0.28. This is working in Kibana and "Healthy".  
VM3 = Ubuntu Server 20.04 running Nginx with IP 172.16.0.117.

Now that the fleet server is working and displaying in Kibana I followed the instruction to extract the agent tarball on the server I want to monitor, in this instance VM3. I chose the default policy and copied the command. I added --insecure since I'm not using certificates.

```auto
~/elastic-agent-7.15.0-linux-x86_64$ sudo ./elastic-agent install -f --url=http://172.16.0.28:8220 --enrollment-token=OMITTED --insecure

```

This however gives me an error. I have checked and to be sure I don't have UFW turned on so it can't be the firewall.

```auto
2021-10-01T12:44:57.605Z WARN [tls] tlscommon/tls_config.go:98 SSL/TLS verifications disabled.
2021-10-01T12:44:57.963Z INFO cmd/enroll_cmd.go:432 Starting enrollment to URL: http://172.16.0.28:8220/
Error: fail to enroll: fail to execute request to fleet-server: fail to read original error: read tcp 172.16.0.117:47494->172.16.0.28:8220: read: connection reset by peer
For help, please see our troubleshooting guide at https://www.elastic.co/guide/en/fleet/7.15/fleet-troubleshooting.html
Error: enroll command failed with exit code: 1

```

I also tried to check the connection with curl.

```auto
curl -f http://172.16.0.28:8220/api/status

```

And i got error:

```auto
curl: (22) The requested URL returned error: 400 bad request

```

All the services are running and they can all ping each other. In Kibana the fleetserver is reported as "Healthy". I don't know what to check anymore, can someone help?

---

<div class="post-metadata">

**Author:** ![Johnny\_Cheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnny_cheng/32/77578_2.png) [@Johnny\_Cheng](https://discuss.elastic.co/u/Johnny_Cheng)\
**Post date:** [October 7, 2021, 7:32am UTC](https://discuss.elastic.co/t/cant-enroll-agent-to-fleet-fail-to-enroll-fail-to-execute-request-to-fleet-server/285682/2 "2021-10-07T07:32:17Z")

</div>

I am experiencing the same problem.

---

<div class="post-metadata">

**Author:** ![John9](https://avatars.discourse-cdn.com/v4/letter/j/f6c823/32.png) [@John9](https://discuss.elastic.co/u/John9)\
**Post date:** [October 8, 2021, 8:49am UTC](https://discuss.elastic.co/t/cant-enroll-agent-to-fleet-fail-to-enroll-fail-to-execute-request-to-fleet-server/285682/3 "2021-10-08T08:49:43Z")

</div>

I fixed it. The install link from Kibana is incorrect and you need to do httpS instead of HTTP. No idea why this is wrong and it should be fixed. In kibana fleet settings you should set the fleetserver also to HTTPS.

---

<div class="post-metadata">

**Author:** ![jesteeeves](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@jesteeeves](https://discuss.elastic.co/u/jesteeeves)\
**Post date:** [November 3, 2021, 7:18pm UTC](https://discuss.elastic.co/t/cant-enroll-agent-to-fleet-fail-to-enroll-fail-to-execute-request-to-fleet-server/285682/4 "2021-11-03T19:18:02Z")

</div>

Thanks for posting this, fixed the same problem for me.

---

<div class="post-metadata">

**Author:** ![AlphaSun](https://avatars.discourse-cdn.com/v4/letter/a/e480ec/32.png) [@AlphaSun](https://discuss.elastic.co/u/AlphaSun)\
**Post date:** [November 9, 2021, 4:29pm UTC](https://discuss.elastic.co/t/cant-enroll-agent-to-fleet-fail-to-enroll-fail-to-execute-request-to-fleet-server/285682/5 "2021-11-09T16:29:34Z")

</div>

Thank you !! Fixed it too !  
Edit in kibana fleet settings to https, edit the install link to add httpS and --insecure as well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2021, 4:30pm UTC](https://discuss.elastic.co/t/cant-enroll-agent-to-fleet-fail-to-enroll-fail-to-execute-request-to-fleet-server/285682/6 "2021-12-07T16:30:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
