# Dec 1st, 2022: \[EN\] Elastic Agent 101

**URL:** <https://discuss.elastic.co/t/dec-1st-2022-en-elastic-agent-101/316879>\
**Category:** Advent Calendar\
**Created:** [December 1, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-1st-2022-en-elastic-agent-101/316879 "2022-12-01T08:00:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndersonQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andersonq/32/112214_2.png) [@AndersonQ](https://discuss.elastic.co/u/AndersonQ)\
**Post date:** [December 1, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-1st-2022-en-elastic-agent-101/316879/1 "2022-12-01T08:00:30Z")

</div>

![day1](https://us1.discourse-cdn.com/elastic/original/3X/c/4/c4bb3472ba2467fcb235552d4d18be5cb686728a.png)

This article is also available [in portuguese](https://discuss.elastic.co/t/319992).

First things first, what is the Elastic Agent?

> Elastic Agent is a single, unified way to add monitoring for logs, metrics, and other types of data to a host. It can also protect hosts from security threats, query data from operating systems, forward data from remote services or hardware, and more.

How do the Elastic Agent does that all? It delegates, its responsibility is to run, manage and configure the needed applications to fulfil the _"tasks assigned to it"_, such as collecting logs, metrics or protecting a host.

A [policy](https://www.elastic.co/guide/en/fleet/8.5/agent-policy.html) is the Elastic Agent's configuration, in the policy several [integrations](https://www.elastic.co/guide/en/fleet/8.5/fleet-overview.html#unified-integrations) are added, then the Elastic Agent analyzes the policy to discover all the applications needed to fulfill the policy.

The Elastic Agent will take care of running, managing and configuration each of the needed applications. As an example, if we create a policy and add the APM Server, Custom Logs and System metrics integrations, the Elastic Agent will run and configure the APM server, Filebeat (to collect the logs) and Metricbeat (to collect system metrics).

[Creating a policy](https://www.elastic.co/guide/en/fleet/8.5/agent-policy.html#create-a-policy), [adding integrations](https://www.elastic.co/guide/en/fleet/8.5/add-integration-to-policy.html) and [installing the Elastic Agent](https://www.elastic.co/guide/en/fleet/8.5/elastic-agent-installation.html) are well documented process, check the links if you want to know more about them.

What is less known are all the features the Elastic Agent, as a CLI, provides to investigate and diagnose problems happening with itself or any of the applications it runs.  
We all know, sometimes things don't works as we expect and we need to discover what is happening. Here is where the CLI commands we'll discuss next come in hand.

First, the `status` command shows the status of every application the Elastic Agent is running:

```plaintext
elastic-agent status

Status: HEALTHY
Message: (no message)
Applications:
  * filebeat (HEALTHY)
                           Running
  * metricbeat (HEALTHY)
                           Running
  * filebeat_monitoring (HEALTHY)
                           Running
  * metricbeat_monitoring (HEALTHY)
                           Running

```

The `_monitoring`[Beats](https://www.elastic.co/beats/), as the name suggests, monitor the Elastic Agent and its applications collecting metrics and their logs.

Next command is `diagnostics`, a lot more technical than `status`, it'll also show information about the applications running under the Elastic Agent:

```plaintext
elastic-agent diagnostics

elastic-agent id: 65a5bc58-d3fe-414a-bc55-9b2bb69c85f5 version: 8.5.2
               build_commit: c13f9157c438fc60cfbb822b385ea91bc91193cc build_time: 2022-11-17 21:16:12 +0000 UTC snapshot_build: false
Applications:
  * name: filebeat route_key: default
     process: filebeat id: bdd93dd6-47b8-41cb-a5eb-a4e73ca8d205 ephemeral_id: f9e7c229-73a4-40c0-ad5e-7d751071934b elastic_license: true
     version: 8.5.2 commit: 1ebd0940bd56943642ea8d63d1fe8227f86e7435 build_time: 2022-11-15 20:38:43 +0000 UTC binary_arch: amd64
     hostname: elastic-agent username: root user_id: 0 user_gid: 0
  * name: metricbeat route_key: default
     process: metricbeat id: 6146ca43-d3dc-43fc-864c-16f7c718931f ephemeral_id: c98424db-6ba9-4dab-b656-25965c82accc elastic_license: true
     version: 8.5.2 commit: 1ebd0940bd56943642ea8d63d1fe8227f86e7435 build_time: 2022-11-15 20:38:34 +0000 UTC binary_arch: amd64
     hostname: elastic-agent username: root user_id: 0 user_gid: 0
  * name: filebeat_monitoring route_key: default
     process: filebeat id: dd6d9f4e-0fc7-413e-a829-232d8fb9222b ephemeral_id: 43d99165-49a2-41ef-9a63-358f545bd5ec elastic_license: true
     version: 8.5.2 commit: 1ebd0940bd56943642ea8d63d1fe8227f86e7435 build_time: 2022-11-15 20:38:43 +0000 UTC binary_arch: amd64
     hostname: elastic-agent username: root user_id: 0 user_gid: 0
  * name: metricbeat_monitoring route_key: default
     process: metricbeat id: 014efcdf-40c2-4aad-916d-4468dc67ad48 ephemeral_id: 0e01dae8-86d5-4717-9594-0228479ba5c8 elastic_license: true
     version: 8.5.2 commit: 1ebd0940bd56943642ea8d63d1fe8227f86e7435 build_time: 2022-11-15 20:38:34 +0000 UTC binary_arch: amd64
     hostname: elastic-agent username: root user_id: 0 user_gid: 0

```

The `diagnostics` has got the sub-command `collect`, that well, collects pretty much everything about the Elastic Agent and the programs it's running. It gathers metadata, the policy, the individual configuration the Elastic Agent generates from the policy to each program it's running and the logs. This is by far the most useful command for investigations, mainly when who is analysing the data does not have access to the host where the Elastic Agent is running. It's one of the first things we ask our customers when they reach out for support regarding a problem with the Elastic Agent or any of the integrations.

The `inspect` command will show the current configuration. The output is huge as it shows everything being collected from the host, so here is a shorter version of its output:

```plaintext
elastic-agent inspect

agent:
  download:
    source_uri: https://artifacts.elastic.co/downloads/
  monitoring:
    enabled: true
    logs: true
    metrics: true
    namespace: default
    use_output: default
fleet:
  hosts:
  - https://my.fleet-server.co:443
id: f0beede0-6f1e-11ed-aaed-9bf77350c160
inputs:
- data_stream:
    namespace: default
  id: logfile-system-17831582-e0d5-48b5-a72c-405396085de7
  meta:
    package:
      name: system
      version: 1.20.4
  name: system-1
  package_policy_id: 17831582-e0d5-48b5-a72c-405396085de7
  revision: 1
  streams:
  - data_stream:
      dataset: system.syslog
      type: logs
    exclude_files:
    - .gz$
    id: logfile-system.syslog-17831582-e0d5-48b5-a72c-405396085de7
    ignore_older: 72h
    multiline:
      match: after
      pattern: ^\s
    paths:
    - /var/log/messages*
    - /var/log/syslog*
    processors:
    - add_locale: null
  type: logfile
  use_output: default
output_permissions:
  default:
    _elastic_agent_checks:
      cluster:
      - monitor
    _elastic_agent_monitoring:
      indices:
      - names:
        - logs-elastic_agent.apm_server-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.apm_server-default
        privileges:
        - auto_configure
        - create_doc
outputs:
  default:
    api_key: <REDACTED>
    hosts:
    - https://my.ES.co:443
    type: elasticsearch
revision: 1

```

Last but not least, `elastic-agent help` will, as you probably already guessed, show you all the available commands within the Elastic Agent.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2022, 8:01am UTC](https://discuss.elastic.co/t/dec-1st-2022-en-elastic-agent-101/316879/2 "2022-12-29T08:01:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
