# Elastic Agent is not getting configured properly

**URL:** <https://discuss.elastic.co/t/elastic-agent-is-not-getting-configured-properly/372034>\
**Category:** Elastic Agent\
**Created:** [December 16, 2024, 4:48pm UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-configured-properly/372034 "2024-12-16T16:48:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ErGeek](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Post date:** [December 16, 2024, 4:48pm UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-configured-properly/372034/1 "2024-12-16T16:48:41Z")

</div>

Hi Team,

We have installed a standalone Elastic Agent on our machine to capture logs from the ForgeRock API. The logs are expected to be sent to a Kafka topic. While the Elastic Agent installation was successful , these logs are not being sent to the Kafka topic as expected.  
There is not connectivity issue because we are able to CURL the ForgeRock logs locally on the same machine.

Below is the configuration used in the `elastic-agent.yml` file.  
"inputs:

- type: httpjson  
schedule: '@every 30m'  
config:  
url: "https://------.com/monitoring/logs?source=am-everything"  
method: GET  
headers:  
Authorization: "Bearer 2---:c1-----1"  
response\_format: json  
processors:
  - decode\_json\_fields:  
fields: ["message"]  
target: ""  
overwrite\_keys: true  
add\_error\_key: true  
use\_output: kafka

outputs:  
kafka:  
type: kafka  
hosts:  
- "b-1.-----:9094"  
- "b-2.-----:9094"  
- "b-3.-----:9094"  
topic: "test\_app\_topic"  
ssl:  
enabled: true  
truststore\_location: "/etc/pki/tls/certs/kafka.client.truststore.jks"  
truststore\_password: "----"

elasticsearch:  
type: elasticsearch  
hosts:  
- "https://-----:9243/"  
username: "elastic"  
password: "-----"  
ssl:  
enabled: true  
certificate\_authorities: ["/etc/pki/tls/certs/ca-bundle.crt"]

monitoring:  
enabled: true  
logs: true  
metrics: true  
use\_output: kafka

agent:  
logging:  
level: info  
to\_files: true  
files:  
path: "/var/log/elastic-agent/"  
name: "elastic-agent"  
keepfiles: 7  
permissions: 0644  
"

Additionally, we are encountering the following error logs in the `elastic-agent.log` file.

_"{"log.level":"error","@timestamp":"2024-12-16T12:15:44.523Z","log.origin":{"function":"[github.com/elastic/elastic-agent/internal/pkg/agent/application/coordinator.(\*Coordinator).processVars","file.name":"coordinator/coordinator.go","file.line":1222},"message":"updating](http://github.com/elastic/elastic-agent/internal/pkg/agent/application/coordinator.(*Coordinator).processVars%22,%22file.name%22:%22coordinator/coordinator.go%22,%22file.line%22:1222%7D,%22message%22:%22updating) Coordinator variables: generating component model: failed to render components: failed to inject monitoring: failed to inject monitoring output: output "default" used for monitoring not found","log":{"source":"elastic-agent"},"ecs.version":"1.6.0"}  
"._

Could anyone help on this?

Regards

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 16, 2024, 5:17pm UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-configured-properly/372034/2 "2024-12-16T17:17:47Z")

</div>

have you run the

`/opt/Elastic/Agent/elastic-agent status`

`/opt/Elastic/Agent/elastic-agent inspect`

and taken a look?

> **[Elastic Agent command reference | Fleet and Elastic Agent Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/fleet/current/elastic-agent-cmd-options.html)**

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 16, 2024, 5:29pm UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-configured-properly/372034/3 "2024-12-16T17:29:36Z")

</div>

I do not use Elastic Agent in standalone mode, but from the docs you need to have a output named `default`.

This is mentioned [here](https://www.elastic.co/guide/en/fleet/current/elastic-agent-output-configuration.html).

Try to change the name of the kafka output from `kafka` to `default`.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 16, 2024, 5:38pm UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-configured-properly/372034/4 "2024-12-16T17:38:32Z")

</div>

Yes @leandrojmp great catch

> A default output configuration is required.

---

<div class="post-metadata">

**Author:** ![ErGeek](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Post date:** [December 17, 2024, 11:33am UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-configured-properly/372034/5 "2024-12-17T11:33:53Z")

</div>

Thank you so much @leandrojmp . It worked once we changed the output to default. But we are receiving the filebeat and metricbeat logs instead of the API logs.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 20, 2024, 4:47am UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-configured-properly/372034/7 "2024-12-20T04:47:27Z")

</div>

It looks like your issue was resolved in the other thread [API logs not coming after setting up Elastic Agent , Beats logs are coming - #14 by strawgate](https://discuss.elastic.co/t/api-logs-not-coming-after-setting-up-elastic-agent-beats-logs-are-coming/372081/14)
