# Elastic agent not sending data stream

**URL:** <https://discuss.elastic.co/t/elastic-agent-not-sending-data-stream/286893>\
**Category:** Beats\
**Tags:** docker, elastic-agent\
**Created:** [October 16, 2021, 2:43pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-stream/286893 "2021-10-16T14:43:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AdE\_GoD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ade_god/32/79377_2.png) [@AdE\_GoD](https://discuss.elastic.co/u/AdE_GoD)\
**Post date:** [October 16, 2021, 2:43pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-stream/286893/1 "2021-10-16T14:43:35Z")

</div>

Hi everyone,

I've been wanting to try elastic-agent for quite some time now so I booted up a machine and tried to configure everything, but I've encountered an error that for the love of me I simply cannot fix.

I have followed this guide to setup ELK in docker with TLS enabled.

> **[Running the Elastic Stack on Docker | Getting Started \[7.15\] | Elastic](https://www.elastic.co/guide/en/elastic-stack-get-started/current/get-started-docker.html#get-started-docker-tls)**

Once that was done, I could enter into Kibana without problem.  
I proceeded at checking the documentation for starting a Fleet server as described here under the "self-managed" tab.

> **[Fleet Server | Fleet and Elastic Agent Guide \[7.15\] | Elastic](https://www.elastic.co/guide/en/fleet/7.15/fleet-server.html#add-fleet-server)**

I downloaded the elastic-agent, selected the "quick start" option and run the install command, which looks something like this (from the doc):

```auto
sudo ./elastic-agent install -f \
  --fleet-server-es=https://localhost:9200 \
  --fleet-server-service-token=AAEbAWVsYXN0aWMvZmxlaXQtc2VydmVzL3Rva2VuLTE2MeIzNTY1NTQ3Mji6dERXeE9XbW5RRTZqNlJMWEdIRzAtZw \
  --fleet-server-policy=27467ed1-1bfd-11ec-9b88-a7c3d83e2897

```

Here I encountered the first issue: the elastic-agent doesn't like the certificate that was created by following the documentation on setting up ELK in docker with TLS.  
I thus looked around and changed the above command with:

```auto
sudo ./elastic-agent install -f \
  --fleet-server-es=https://localhost:9200 \
  --fleet-server-service-token=AAEbAWVsYXN0aWMvZmxlaXQtc2VydmVzL3Rva2VuLTE2MeIzNTY1NTQ3Mji6dERXeE9XbW5RRTZqNlJMWEdIRzAtZw \
  --fleet-server-policy=27467ed1-1bfd-11ec-9b88-a7c3d83e2897
--fleet-server-es-ca=/var/snap/docker/common/var-lib-docker/volumes/es_certs/_data/ca/ca.crt

```

so that the elastic-agent could validate the server certificate provided by Elasticsearch.  
(Shouldn't the documentation be updated?)

With the above command, I can see the agent popping up in Kibana however, no logs is sent to Elasticsearch and no data stream is there.  
Checking the logs of the Elasticsearch es01 container, I see a tons of

```auto
{"type": "server", "timestamp": "2021-10-16T14:36:15,343Z", "level": "WARN", "component": "o.e.h.AbstractHttpServerTransport", "cluster.name": "es-docker-cluster", "node.name": "es01", "message": "caught exception while handling client http traffic, closing connection Netty4HttpChannel{localAddress=/172.25.0.3:9200, remoteAddress=/172.25.0.1:34074}", "cluster.uuid": "T_2o0sO_SfSuwMUvKdTRmg", "node.id": "imQywT40R66wUI_khsT-Gg" ,
"stacktrace": ["io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad_certificate"

```

If I get this right, it looks like that Elasticsearch cannot validate the certificate provided by the elastic-agent? Meaning that there's a mutual authentication where Elasticsearch tries to authenticate the elastic-agent?

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [October 19, 2021, 3:11pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-stream/286893/2 "2021-10-19T15:11:18Z")

</div>

The output that the Elastic Agent uses comes from the output settings defined in Kibana. That is seperate from the settings used by Fleet Server.

> **[Fleet UI settings | Fleet and Elastic Agent Guide \[7.15\] | Elastic](https://www.elastic.co/guide/en/fleet/current/fleet-settings.html)**

See the section on `Elasticsearch output configuration (YAML)`. You can either add:

```auto
ssl:
   verfication_mode: none

```

Or you can paste the contents of the CA:

```auto
ssl:
  certificate_authorities:
    - |
    ==== CONTENT OF THE CA ===

```

---

<div class="post-metadata">

**Author:** ![AdE\_GoD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ade_god/32/79377_2.png) [@AdE\_GoD](https://discuss.elastic.co/u/AdE_GoD)\
**Post date:** [October 23, 2021, 2:58pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-stream/286893/3 "2021-10-23T14:58:31Z")

</div>

Great, didn't see that, it works like a charm. Thanks 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2021, 2:58pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-stream/286893/4 "2021-11-20T14:58:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
