# Elastic Agent is Healthy, but no data streams

**URL:** <https://discuss.elastic.co/t/elastic-agent-is-healthy-but-no-data-streams/294224>\
**Category:** Beats\
**Tags:** fleet, elastic-agent\
**Created:** [January 13, 2022, 1:53am UTC](https://discuss.elastic.co/t/elastic-agent-is-healthy-but-no-data-streams/294224 "2022-01-13T01:53:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![harwinds](https://avatars.discourse-cdn.com/v4/letter/h/34f0e0/32.png) [@harwinds](https://discuss.elastic.co/u/harwinds)\
**Post date:** [January 13, 2022, 1:53am UTC](https://discuss.elastic.co/t/elastic-agent-is-healthy-but-no-data-streams/294224/1 "2022-01-13T01:53:40Z")

</div>

Hi, I'm running fleet managed elastic agent on Elastic 7.15.1. I've multiple agents running on Linux and Windows endpoints. All agents are showing healthy. On both Linux and Windows, custom certificate is added to system's trusted CA repository.

For encrypting traffic, followed the documentation: [https://www.elastic.co/guide/en/fleet/current/secure-connections.html](https://www.elastic.co/guide/en/fleet/current/secure-connections.html)

**Scenario 1**. No certificate added using "ssl.certificate\_authorities" under "Fleet Settings" in Kibana

- Elastic Agents running on Linux are successfully ingesting data, but not the Windows one.

**Scenario 2**. Following this post: [https://discuss.elastic.co/t/possible-bug-with-elastic-agent-ca-certificate-checks/267253](https://discuss.elastic.co/t/possible-bug-with-elastic-agent-ca-certificate-checks/267253), added the certificate under "ssl.certificate\_authorities" in "Fleet Settings".

- After doing so, started receiving the logs from Windows Endpoints as well, but ingestion rate for Linux dropped to less than half. For the Elastic Agent running on Linux, it is using the Palo Alto (syslog) Integration.

Can someone please help me understand what could be the potential cause behind this behavior? Second, I recently rotated the custom cert on all nodes, before rotation of certs all Elastic Agents (Windows and Linux) all were healthy and sending logs without providing the certificate under Fleet Settings "ssl.certificate\_authorities".

---

<div class="post-metadata">

**Author:** ![harwinds](https://avatars.discourse-cdn.com/v4/letter/h/34f0e0/32.png) [@harwinds](https://discuss.elastic.co/u/harwinds)\
**Post date:** [January 13, 2022, 10:06pm UTC](https://discuss.elastic.co/t/elastic-agent-is-healthy-but-no-data-streams/294224/2 "2022-01-13T22:06:34Z")

</div>

Issue has been resolved. It was due to the fact, that I enabled almost 15+ Endpoints at once, which spiked the CPU to 100%, no resources left to process high volume of incoming data from SYSLOG.

Overall, it seems like a requirement to add the certificate under "Fleet Settings" in Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2022, 12:07am UTC](https://discuss.elastic.co/t/elastic-agent-is-healthy-but-no-data-streams/294224/3 "2022-02-11T00:07:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
