# Elastic agent offline after upgrade

**URL:** <https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade/311531>\
**Category:** Elastic Agent\
**Created:** [August 5, 2022, 1:01pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade/311531 "2022-08-05T13:01:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Leandre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandre/32/78183_2.png) [@Leandre](https://discuss.elastic.co/u/Leandre)\
**Post date:** [August 5, 2022, 1:01pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade/311531/1 "2022-08-05T13:01:38Z")

</div>

Same issue than [this one](https://discuss.elastic.co/t/elastic-agent-upgrade-error/308250) when upgrading agent from 8.3.2 to 8.3.3. The service fails because the symlink to the executable elastic-agent.exe points on a deleted elastic-agent.exe (or the old .exe, wich causes an error like `Error: could not read overwrites: fail to read configuration C:\Program Files\Elastic\Agent\fleet.enc for the elastic-agent: fail to decode bytes: cipher: message authentication failed`).  
I think that this is caused by the folder `data/elastic-agent-xxxxx` changing his name after the upgrade, and the symlink not being updated.  
For exemple, my previous agent exe was in `data/elastic-agent-16c55b` and the symlink points on this, but the new one is in `data/elastic-agent-0ffbed`.

This occured on at least this OS : Ubuntu 20.04.4 LTS and Windows Server 2019 Standard.

The workaround is to manually recreate the symlink, but this become quite painful with a lot of agent, and Fleet is supposed to avoid this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2022, 1:02pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade/311531/2 "2022-09-02T13:02:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
