# Elastic-agent : endpoint-security.sock no such file or directory

**URL:** https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293
**Category:** Beats
**Tags:** elastic-agent
**Created:** [December 17, 2021, 10:41am UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293 "2021-12-17T10:41:42Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Lnood5](https://avatars.discourse-cdn.com/v4/letter/l/898d66/32.png) [@Lnood5](https://discuss.elastic.co/u/Lnood5)
#### Post date: [December 17, 2021, 10:41am UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293/1 "2021-12-17T10:41:42Z")

</div>

Hello,  
**I work with self-managed stack v7.16.1**  
I have a probleme with endpoint security deployment  
elastic-agent diagnostics give for endpoint this error:

```auto
elastic-agent diagnostics 
  * name: endpoint-security route_key: default
     error: Get "http://unix/": dial unix /opt/Elastic/Agent/data/tmp/default/endpoint-security/endpoint-security.sock: connect: no such file or directory

```

When i look at the path, endpoint-security folder is missing.  
I have been looking for quite a time now, and i don't know where the probleme comes from  
I also have metricbeat and filebeat deployed with elastic-agent but they are wotking well  
The status command shows everything is healthy

```auto
elastic-agent status 
Status: HEALTHY
Message: (no message)
Applications:
  * filebeat_monitoring (HEALTHY)
                           Running
  * metricbeat_monitoring (HEALTHY)
                           Running
  * endpoint-security (HEALTHY)
                           Protecting with policy {42c1253e-7dc2-42be-9189-f6542bb8fcd9}
  * filebeat (HEALTHY)
                           Running
  * metricbeat (HEALTHY)
                           Running

elastic-agent diagnostics 
elastic-agent version: 7.16.1
               build_commit: 7e56c4a053a2fe26c0cac168dd974780428a2aa6 build_time: 2021-12-11 05:09:58 +0000 UTC snapshot_build: false
Applications:
  * name: metricbeat_monitoring route_key: default
     process: metricbeat id: 36caf419-861a-4f30-88bd-db3fc7db840f ephemeral_id: c2cdc157-f319-4d5c-b1ef-23ffe08ba4c1 elastic_license: true
     version: 7.16.1 commit: 7e56c4a053a2fe26c0cac168dd974780428a2aa6 build_time: 2021-12-11 02:01:45 +0000 UTC binary_arch: amd64
     hostname: socket-server-dev-joci username: root user_id: 0 user_gid: 0
  * name: endpoint-security route_key: default
     error: Get "http://unix/": dial unix /opt/Elastic/Agent/data/tmp/default/endpoint-security/endpoint-security.sock: connect: no such file or directory
  * name: filebeat route_key: default
     process: filebeat id: f24b7fd7-9856-4a4c-8a19-6bddfee97b72 ephemeral_id: 741a6957-b853-49c4-8ff9-b757d25e61ab elastic_license: true
     version: 7.16.1 commit: 7e56c4a053a2fe26c0cac168dd974780428a2aa6 build_time: 2021-12-11 01:49:16 +0000 UTC binary_arch: amd64
     hostname: socket-server-dev-joci username: root user_id: 0 user_gid: 0
  * name: metricbeat route_key: default
     process: metricbeat id: 36caf419-861a-4f30-88bd-db3fc7db840f ephemeral_id: c2cdc157-f319-4d5c-b1ef-23ffe08ba4c1 elastic_license: true
     version: 7.16.1 commit: 7e56c4a053a2fe26c0cac168dd974780428a2aa6 build_time: 2021-12-11 02:01:45 +0000 UTC binary_arch: amd64
     hostname: socket-server-dev-joci username: root user_id: 0 user_gid: 0
  * name: filebeat_monitoring route_key: default
     process: filebeat id: f24b7fd7-9856-4a4c-8a19-6bddfee97b72 ephemeral_id: 741a6957-b853-49c4-8ff9-b757d25e61ab elastic_license: true
     version: 7.16.1 commit: 7e56c4a053a2fe26c0cac168dd974780428a2aa6 build_time: 2021-12-11 01:49:16 +0000 UTC binary_arch: amd64
     hostname: socket-server-dev-joci username: root user_id: 0 user_gid: 0

```

I'm managing everything from Kibana

Elastic config output:

```auto
 api_key: "api_key"
  ssl:
    certificate_authorities: ["/etc/ssl/es/ca.crt"]
    certificate: "/etc/ssl/es/beats.crt"
    key: "/etc/ssl/es/beats.key"

```

Thanks in advance,

---

<div class="post-metadata">

### Author: ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)
#### Post date: [December 20, 2021, 2:13pm UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293/2 "2021-12-20T14:13:07Z")

</div>

Hi,

is the problem persistent also after restart? did you try to reinstall the agent?

---

<div class="post-metadata">

### Author: ![Lnood5](https://avatars.discourse-cdn.com/v4/letter/l/898d66/32.png) [@Lnood5](https://discuss.elastic.co/u/Lnood5)
#### Post date: [December 22, 2021, 2:56pm UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293/3 "2021-12-22T14:56:00Z")

</div>

Hello, I reinstalled it many times but the problem is persistent.  
I had two problems, first one, I didn’t correctly pass my certificates to my elastic-agents  
I solved it by passing my certificates to the fleet settings, so now I have logs comming from filebeat and metribeat (I also use system integration).

The problem come from :

```auto
[elastic_agent.endpoint_security][error] Http.cpp:327 CURL error 60: SSL peer certificate or SSH remote key was not OK [SSL certificate problem: unable to get local issuer certificate]

```

I have this error on both Windows and Linux  
Its still a certificate problem, I saw a thread with the same error.

> [@No alert in security detection dashboards after malware attack](https://discuss.elastic.co/t/no-alert-in-security-detection-dashboards-after-malware-attack/258380):
>
> Hello ES team, After installing and enrolling Elastic Agent 7.10 we launched an Mimikatz.exe on our Win10 machine and received an ES Malware Alert but we do not receive an alert in Security Detections tab in Kibana. The rule: Malware - Detected - Endpoint Security was activated and can't be edited. In Security-\>Administration tab there are no Endpoints enrolled. In Data streams tab the elastic\_agent.endpoint-security is not integrated to endpoint.

But I give all my certificates through my fleet settings.

```auto
  api_key: ""
  hosts: ["https://myserver:9200"]
  protocol: https
  ssl.certificate_authorities: |
    -----BEGIN CERTIFICATE-----

    -----END CERTIFICATE-----
  ssl.certificate: |
    -----BEGIN CERTIFICATE-----

    -----END CERTIFICATE-----

  ssl.key: |
    -----BEGIN RSA PRIVATE KEY-----

    -----END RSA PRIVATE KEY-----

```

So I don't know why I still have this problem, I must have missed a parameter.  
Thank you for your time

---

<div class="post-metadata">

### Author: ![Lnood5](https://avatars.discourse-cdn.com/v4/letter/l/898d66/32.png) [@Lnood5](https://discuss.elastic.co/u/Lnood5)
#### Post date: [December 22, 2021, 4:08pm UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293/4 "2021-12-22T16:08:41Z")

</div>

Endpoint security seems to not use fleet Elasticsearch output settings , so I had to add my Elasticsearch certificate as root ca.

elastic-agent sends events, but i still have the error message

```auto
elastic-agent diagnostics 
  * name: endpoint-security route_key: default
     error: Get "http://unix/": dial unix /opt/Elastic/Agent/data/tmp/default/endpoint-security/endpoint-security.sock: connect: no such file or directory

```

Thank you

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 19, 2022, 6:09pm UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-security-sock-no-such-file-or-directory/292293/5 "2022-01-19T18:09:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
