# Elastic Agent not sending Data to Elastic search From KVM but works for VMWare

**URL:** <https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012>\
**Category:** Elastic Agent\
**Created:** [October 13, 2023, 6:05pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012 "2023-10-13T18:05:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AnyThink\_A](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anythink_a/32/122141_2.png) [@AnyThink\_A](https://discuss.elastic.co/u/AnyThink_A)\
**Post date:** [October 13, 2023, 6:05pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012/1 "2023-10-13T18:05:12Z")

</div>

Hello Team,

In further lab setup. I am facing a strange issue. I have two setups

1. LAB  
Windows -\> VMware (UBUNTU)  
Windows -\> VMware (Windows)

Both guests are connected through host-only adapter.

1. SANDBOX

Windows -\> VMware (UBUNTU) -\> KVM (WINDOWS)

This setup have nested VMs. Both guests VMs are connected through host-only adapter.

* * *

ELK and Fleet is installed on UBUNTU box. I have configured proxy to access internet from both guest windows. But ELK interface IP is excluded.

output and fleet is configured as hostname.

```auto

# This section was automatically generated during setup.
elasticsearch.hosts: ['https://securelab:9200']
elasticsearch.serviceAccountToken: AAEAAWVsYXN0aWMva2liYW5hL2Vucm9sbC1wcm9jZXNzLXRva2VuLTE2OTcwOTQ5NjAzODk6MEFKV1RnNWFUbGVkeXVJQVdoY2R2QQ
elasticsearch.ssl.certificateAuthorities: [/var/lib/kibana/ca_1697094960818.crt]
xpack.fleet.outputs: [{id: fleet-default-output, name: default, is_default: true, is_default_monitoring: true, type: elasticsearch, hosts: ['https://securelab:9200'],

```

The issue is, when I installed agent in LAB setup. It is working as expected and I am getting the logs.

However, when I install it in SANDBOX setup, the agent shows healthy. I can even collect diagnostic logs , update policies from console. But not getting any logs.

Any help is appreciated.

Screenshot and diagnostics logs are attached.

desktop-2o70m2l - SANDBOX

 ![elk](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2f7731dc03be4790e48d03105c497616723e9d4e.png)  
Windows

Regards,  
Ameer Mane

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 13, 2023, 6:24pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012/2 "2023-10-13T18:24:17Z")

</div>

Hi @AnyThink_A

Perhaps take a look at this, you may have a similar issue

> [@No Data streams](https://discuss.elastic.co/t/no-data-streams/344985/2):
>
> Hi @Jean-Claude Hope This Helps Did you carefully read through this... [https://www.elastic.co/guide/en/fleet/current/secure-connections.html](https://www.elastic.co/guide/en/fleet/current/secure-connections.html) If Elasticsearch is using a self-signed cert , then the Elastic Agents need that CA or [trusted fingerprint](https://www.elastic.co/guide/en/elasticsearch/reference/8.10/configuring-stack-security.html#_use_the_ca_fingerprint_5) because Agents send Data directly to Elasticsearch See [Here](https://www.elastic.co/guide/en/fleet/current/secure-connections.html#_encrypt_traffic_between_elastic_agents_fleet_server_and_elasticsearch) To encrypt traffic between Elastic Agents, Fleet Server, and Elasticsearch: Configure Fleet settings. These settings are applied to all Fleet-managed Elastic Agents. In Kibana, op…

have tried to uninstall and re-install the agent.

It will take more information did you click on that agent and run the diagnostics?

Did you click on agent details?

Which logs are missing the system logs? or agent logs?

if you can give more details we might be able to help... it is not clear what the issue is.

---

<div class="post-metadata">

**Author:** ![AnyThink\_A](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anythink_a/32/122141_2.png) [@AnyThink\_A](https://discuss.elastic.co/u/AnyThink_A)\
**Post date:** [October 13, 2023, 7:07pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012/3 "2023-10-13T19:07:18Z")

</div>

Hi @stephenb ,

Thanks for prompt response. trusted ca fingerprint is already there.

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3ce70edf36e5c2a86296a43e3e5c43cec898f5ce.png)

On top of it, the LAB setup which is with exact same OS, proxy , ELK and elastic agent is working fine.

But for SANDBOX setup it is not. In diagnostic logs also I can see fingerprint, it picked the config randomly. It is from "beat-rendered-config.yml"

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ec293f7ee4e5a4b059013d9b32f0c081eee7caaf.png)

As for your questions:

have tried to uninstall and re-install the agent. - YES, I HAVE TRIED, BUT SAME ISSUE\> IT SHOWS HEALTHY BUT NO LOGS.

It will take more information did you click on that agent and run the diagnostics?

Did you click on agent details? - YES

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/94a2516f48561f606e579587f7447db822b4b2fa.png)

Which logs are missing the system logs? or agent logs?  
EVERYTHING IS MISSING. WINDOWS SYSTEM, APP, SECURITY as well as agent logs.

if you can give more details we might be able to help... it is not clear what the issue is.

AS MENTIONED, I CAN UPDATE POLICY AND FETCH DIAGONISTCS LOGS FROM CONSOLE, WHICH MEANS AGENT CONNECTION IS OK. LET ME KNOW ANY SPECIFIC INFORMATION IS NEEDED.

I WOULD HAVE ATTACHED DIAGONSITC LOGS BUT IT IS NOT LETTING ME. I AM NOOB IN ANALYZING THESE LOGS.

Regards,  
Ameer Mane

---

<div class="post-metadata">

**Author:** ![AnyThink\_A](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anythink_a/32/122141_2.png) [@AnyThink\_A](https://discuss.elastic.co/u/AnyThink_A)\
**Post date:** [October 14, 2023, 2:08am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012/4 "2023-10-14T02:08:28Z")

</div>

Hello ,

I found the solution. Somehow in KVM machine time was not set to correct time zone. even if everything was set correctly.

This caused agent to detect future time than the ELK and indexing was not getting written. I set time manually and it's working.

Didn't understand exact reasoning but it's working. If anyone knows let me know.

Regards,  
Ameer Mane

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 14, 2023, 3:12am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012/5 "2023-10-14T03:12:04Z")

</div>

> [@AnyThink\_A](#):
>
> This caused agent to detect future time than the ELK and indexing was not getting written. I set time manually and it's working.

@AnyThink_A Ohhh Great find!!! Nice!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2023, 3:12am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012/6 "2023-11-11T03:12:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
