# Elastic Agent + Security Onion

**URL:** <https://discuss.elastic.co/t/elastic-agent-security-onion/385187>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring, docker\
**Created:** [February 24, 2026, 4:31pm UTC](https://discuss.elastic.co/t/elastic-agent-security-onion/385187 "2026-02-24T16:31:55Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![harry22](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harry22/32/146978_2.png) [@harry22](https://discuss.elastic.co/u/harry22)\
**Post date:** [February 24, 2026, 4:31pm UTC](https://discuss.elastic.co/t/elastic-agent-security-onion/385187/1 "2026-02-24T16:31:55Z")

</div>

Hi team,

I recentely deployed Security onion lab on Vmware workstation  
Allowed allow hosts on Security Onion with my home private Subnet

Checked and verified all services showing up on VM

Checked and verified on PowerShell that Windows Endpoint machine is communicating to

SOC machine on Port 8220

Installed Downloaded Elastic Agent on Endpoint  
Checked Elastic Agent status running

As checked and found, the agent is stopped due to not enrolled properly or Enrollment issue.

After some struggle Elastic agent Enrollment was successful.  
Successfully enrolled in the Elastic Agent.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5a62b3ee3aa6262bd3b5ba0cbeb564da0a22fee.png)  
Checked again elastic agent status -up and running & healthy  
Inside SOC VM:

- sudo docker ps | grep elastic

- attacker simulation + detection testing  
**Confirm Windows logs are flowing (VERY IMPORTANT)**

## **Now filter for network scan activity**

**Added this:**

**event.category: network**

**Search by 192.168.1.5**

now Enabled **Elastic Defend  
Go in Kibana:**

**Management → Fleet → Agent policies**

Open your policy:

endpoints-initial

Added integration  
After Successfully EDR deployed  
Check and verified from kibana -Fleet- Agents-Harry Machine  
Status = Healthy

Policy revision updated recently But i need help to learn how to Search logs & events on Kibana Dashboard or next analysis If any one give me one session will be much appreciated

Thankyou
