I am trying to use ingest management and elastic agent on Windows Server 2012 against elastic cloud instance. Unfortunately, I am ending with the error bellow and no data is sent to elastic.
Can someone please help me with this?
Thank you very much.
Pavel
2020-06-29T22:28:44+02:00 INFO stateresolver.go:47 New State ID is _-m5mkG0
2020-06-29T22:28:44+02:00 INFO stateresolver.go:48 Converging state requires execution of 3 step(s)
2020-06-29T22:28:44+02:00 DEBUG operator.go:236 operator is looking for filebeat--7.8.0 in app collection: map[]
2020-06-29T22:28:44+02:00 INFO operation_fetch.go:65 filebeat.7.8.0 already exists in C:\Program Files\Elastic-Agent\
data\downloads\filebeat-7.8.0-windows-x86_64.zip. Skipping operation operation-fetch
2020-06-29T22:28:44+02:00 INFO operator.go:217 operation 'operation-fetch' skipped for filebeat.7.8.0
2020-06-29T22:28:44+02:00 INFO operator.go:217 operation 'operation-verify' skipped for filebeat.7.8.0
2020-06-29T22:28:44+02:00 DEBUG operator.go:221 running operation 'operation-install' for filebeat.7.8.0
2020-06-29T22:28:45+02:00 ERROR reporter.go:47 2020-06-29T22:28:45+02:00: type: 'ERROR': sub_type: 'CONFIG' message: Ap
plication: filebeat[e1c9a6cf-852d-477e-b17e-e19fc6da241e]: operation-install: exit status 1
2020-06-29T22:28:45+02:00 DEBUG action_dispatcher.go:93 Failed to dispatch action 'action_id: a46ce0db-9abc-440d-9f39-95
d1eaf01826, type: CONFIG_CHANGE', error: operator: failed to execute step sc-run, error: operation-install: exit status
1: operation-install: exit status 1
operator: failed to execute step sc-run, error: operation-install: exit status 1: operation-install: exit status
1
operation-install: exit status 1
exit status 1
2020-06-29T22:28:45+02:00 ERROR fleet_gateway.go:163 failed to dispatch actions, error: operator: failed to execute s
tep sc-run, error: operation-install: exit status 1: operation-install: exit status 1
operator: failed to execute step sc-run, error: operation-install: exit status 1: operation-install: exit status
1
operation-install: exit status 1
exit status 1
2020-06-29T22:28:45+02:00 DEBUG fleet_gateway.go:166 FleetGateway is sleeping, next update in 30s
Hello! I'm new to SDH issues, and new-ish to the ingest product but wanted to give some minimal help if I could. I'm sure others on the team will join in soon.
It is possible this is the same issue I've logged here:
We are prioritizing and hoping to make progress shortly.
is it possible for the immediate term for you to evaluate Ingest Manager and fleet with a different flavor of Windows? Win 7, Win 10, Win 8.1, Win 2019 are among the os versions we explicitly confirmed, per our support matrix listing for 7.8.
While I ask that.. I can ask more about the issue at hand, too:
One of the first things we would seek to trouble shoot is whether or not the host can communicate with Kibana. Can you confirm that using a 'ping' command or curl or similar returns successfully? If not the problem is in the networking / communication there.
If that works, perhaps you could post the configuration you are using when starting the Agent (are you trying to follow 'stand-alone' agent mode usage) or you can post the configuration yaml from the Ingest Manager UI in Kibana if you are following the Fleet-controlled Agent usage.
Thank you for your answer, the issue you sent looks the same as the one I have. I am looking for the version 7.9.x where it should be fixed. Is there any chance to get the fixed version before? For the other questions, I could give it a try on WIn 2019, maybe Win 10.
To the issue, host can definitely communicate with Kibana, it is listed in fleet as online/error and has the activity log with items in it. The configuration is the fleet mode one, yaml attached.
Hello - we're reviewing the issue in depth on our end and when fixed we can share the 7.9 build, I cannot provide any time estimate on that. Thank you for the patience and for asking! Best regards.
Hello Pavel_Penka, hope you are well. We found the issue to be that our test version of Win 2012 had a very old version of Powershell, and the commands we were using were not compatible with it. We've updated the Agent and successfully tested on Win 2012, so I hope the 7.9 release will work for you as well. If there is anything that doesn't work further, please do report a ticket in the elastic/beats repo for us (or here again if you desire). Recommend using this location to try it out, or wait for the 7.9 GA - https://staging.elastic.co/7.9.0-aed29770/summary-7.9.0.html
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.