# Changing fleet settings installs two endpoint security instances

**URL:** <https://discuss.elastic.co/t/changing-fleet-settings-installs-two-endpoint-security-instances/310404>\
**Category:** Beats\
**Tags:** fleet\
**Created:** [July 22, 2022, 1:16pm UTC](https://discuss.elastic.co/t/changing-fleet-settings-installs-two-endpoint-security-instances/310404 "2022-07-22T13:16:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tmahany419](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmahany419/32/102898_2.png) [@tmahany419](https://discuss.elastic.co/u/tmahany419)\
**Post date:** [July 22, 2022, 1:16pm UTC](https://discuss.elastic.co/t/changing-fleet-settings-installs-two-endpoint-security-instances/310404/1 "2022-07-22T13:16:09Z")

</div>

Here's a vm I have running endpoint security:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d420093d6149d47f2470cec76971d61b50137116.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15557e1bfd86fc17b4194f9f7940bea32582b842.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95f77a5f3c2d9afed9e7961b806858f05ff3d62c.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c83cb6287871d088008e62479ae3107a671ecc64.png)

I changed the Default output for Agent integrations and for Agent monitoring , which should not affect this policy. It even gave me a warning that the change would affect 0 agents and 0 agent policies. However, every agent was updated.

This is the same vm now:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3d1ea74e7928634e02bb1aeb5f0b2a97a9e2600f.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/3/43d2f9e21a47f99f01b2ae552798c52233606b8a.png)

I get this issue on 8.2.2 and 8.2.3, this was from a cloud instance running 8.2.2. I have also triggered it other ways than changing fleet's default output. I think it will occur if you change the agent policy's output. The vm in the screenshot is running ubuntu 20, but I have also seen it on windows 10.

The only work around I have found is putting the agent on a policy without endpoint security and then putting it back on its original policy with endpoint security.

This seems like a bug to me, is it being tracked somewhere already?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2022, 3:16pm UTC](https://discuss.elastic.co/t/changing-fleet-settings-installs-two-endpoint-security-instances/310404/2 "2022-08-19T15:16:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
