# Elastic Agent Not Sending Logs FIN ACK after changing a cipher

**URL:** <https://discuss.elastic.co/t/elastic-agent-not-sending-logs-fin-ack-after-changing-a-cipher/365861>\
**Category:** Elastic Agent\
**Created:** [September 1, 2024, 9:22am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-fin-ack-after-changing-a-cipher/365861 "2024-09-01T09:22:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ahmed\_fetoh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_fetoh/32/126695_2.png) [@ahmed\_fetoh](https://discuss.elastic.co/u/ahmed_fetoh)\
**Post date:** [September 1, 2024, 9:22am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-fin-ack-after-changing-a-cipher/365861/1 "2024-09-01T09:22:46Z")

</div>

**Description:**  
I have deployed a setup on the cloud with two VMs:

1. One VM running Elasticsearch.
2. Another VM running Kibana and Fleet Server.

**Issue:**  
When I try to install an agent to collect logs from an endpoint, Elastic only receives the status and health information, but no logs are sent.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/4/844065ac294e7b1f7d801ea3779ae3a3279ecaf4.jpeg)

**Question:**  
Is this issue related to a cloud configuration, or is there something missing in the ELK configuration? What steps can I take to resolve this issue and ensure that logs are correctly collected from endpoints outside the network using a certificate?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 2, 2024, 3:14pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-fin-ack-after-changing-a-cipher/365861/2 "2024-09-02T15:14:56Z")

</div>

Hi @ahmed_fetoh

Looks like you have self-signed certs which can be a bit tricky...

Are you sure the Fleet is running properly?

Are you sure the agent enrolled properly?

Have you looked at the troubleshooting guide

> **[Troubleshoot common problems | Fleet and Elastic Agent Guide \[8.15\] | Elastic](https://www.elastic.co/guide/en/fleet/current/fleet-troubleshooting.html#agent-enrollment-certs)**

Have you run the status commands for the agent?

Did you note here...

> **[Install Fleet-managed Elastic Agents | Fleet and Elastic Agent Guide \[8.15\] |...](https://www.elastic.co/guide/en/fleet/current/install-fleet-managed-elastic-agent.html)**

> - If you encounter an "x509: certificate signed by unknown authority" error, you might be trying to enroll in a Fleet Server that uses self-signed certs. To fix this problem in a non-production environment, pass the `--insecure` flag. For more information, refer to the [troubleshooting guide](https://www.elastic.co/guide/en/fleet/8.15/fleet-troubleshooting.html#agent-enrollment-certs).

You can absolutely use self signed certs you just need to be very careful when setting up ...
