# Elastic Agent service stops after launching but doesn't throw any error in command line

**URL:** <https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547>\
**Category:** Beats\
**Tags:** elastic-agent\
**Created:** [January 8, 2021, 1:14pm UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547 "2021-01-08T13:14:57Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![icious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icious/32/77965_2.png) [@icious](https://discuss.elastic.co/u/icious)\
**Post date:** [January 8, 2021, 1:14pm UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/1 "2021-01-08T13:14:57Z")

</div>

Hi,

I set up a Fleet environment and tested multiple integrations of Elastic Agent on Linux and Windows machines without any problem, but there is a specific Windows machine where it does not work, and I couldn't find the reason.

I downloaded and extracted Elastic Agent 7.10.1 zip for Windows and executed this Fleet enrollment command from PowerShell, finishing without errors, and the host appears as enrolling in Kibana.  
`.\elastic-agent.exe install -f --kibana-url=XXX --enrollment-token=XXX --insecure`

So far, so good. But when I go to services.msc, Elastic Agent service appears stopped, and forcing start results in "Error 1067: The process terminated unexpectedly.". In Kibana, this particular host shows as enrolling forever.

There are no logs in Elastic Agent's install folder, so I can't find what is causing this error. Starting service from PowerShell doesn't throw any error either, but the 'Get-Service' command shows it as stopped.

If I run Elastic Agent with `.\elastic-agent.exe run`, it works perfectly fine, but not as a service, so I have to manually launch it every time.

Why could this be happening?  
Thank you in advance.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 11, 2021, 10:15am UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/2 "2021-01-11T10:15:32Z")

</div>

You mentioned you don't have any logs. So there is nothing in `data/elastic-agent-*/logs/*`?

Can you think of anything special with this windows machine? Different OS? Different security software installed?

---

<div class="post-metadata">

**Author:** ![dgcapel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dgcapel/32/82063_2.png) [@dgcapel](https://discuss.elastic.co/u/dgcapel)\
**Post date:** [January 12, 2021, 9:15am UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/3 "2021-01-12T09:15:27Z")

</div>

Hi! Same problem here.

# OS

- Windows Server 2019 - 1803 (17763.1637)
- License: Standard
- Loggin with administrator domain account.

# Installation

(Powershell)

> .\elastic-agent.exe install -f --kibana-url=[https://XXX:5601](https://XXX:5601) --enrollment-token=XXX --certificate-authorities="XXX-allca.cert.pem"

# Output

> The Elastic Agent is currently in BETA and should not be used in production
> 
> 2021-01-12T10:00:18.975+0100 DEBUG [tls] tlscommon/tls.go:172 Successfully loaded CA certificate: XXX-allca.cert.pem  
> 2021-01-12T10:00:18.986+0100 DEBUG kibana/client.go:170 Request method: POST, path: /api/fleet/agents/enroll  
> Successfully enrolled the Elastic Agent.  
> Installation was successful and Elastic Agent is running.

# Logs after installation

C:\Program Files\Elastic\Agent\data\elastic-agent-1da173\logs\elastic-agent-json.log

> {"log.level":"debug","@timestamp":"2021-01-12T10:00:18.975+0100","log.logger":"tls","log.origin":{"file.name":"tlscommon/tls.go","file.line":172},"message":"Successfully loaded CA certificate: XXX-allca.cert.pem","ecs.version":"1.6.0"}  
> {"log.level":"debug","@timestamp":"2021-01-12T10:00:18.986+0100","log.origin":{"file.name":"kibana/client.go","file.line":170},"message":"Request method: POST, path: /api/fleet/agents/enroll","ecs.version":"1.6.0"}

# Service Status

(PowerShell)

> get-service elastic\*

> Status Name DisplayName
> 
> * * *
> 
> Stopped Elastic Agent Elastic Agent

# Try to start service from command line

> start-service "Elastic Agent"

C:\Program Files\Elastic\Agent\data\elastic-agent-1da173\logs\elastic-agent-json.log - No news logs

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd85b4cea62deca3853a4158b781c0aa4cc129b7.png)

# Try to start service from UI

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6c3b1003268a8cdb9d20e48acc011f64f3b2b46.png)

# Conclusions

The service don't work properly. I try to change the 'path' of the service but this doesn't seem to be the problem. If I start it manually from a terminal line it works fine. We have some workarround?

Thanks you.

---

<div class="post-metadata">

**Author:** ![icious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icious/32/77965_2.png) [@icious](https://discuss.elastic.co/u/icious)\
**Post date:** [January 12, 2021, 1:55pm UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/4 "2021-01-12T13:55:51Z")

</div>

Hi,

In `data/elastic-agent-*/logs/` folder there's only a log file with 2 entries, resulting from running install command. There is no `default` folder for filebeat and metricbeat logs either.

This is the content of `elastic-agent-json.log`

```auto
{"log.level":"debug","@timestamp":"2021-01-12T14:43:26.050+0100","log.origin":{"file.name":"kibana/client.go","file.line":170},"message":"Request method: POST, path: /api/fleet/agents/enroll","ecs.version":"1.6.0"}

{"log.level":"warn","@timestamp":"2021-01-12T14:43:26.051+0100","log.logger":"tls","log.origin":{"file.name":"tlscommon/tls_config.go","file.line":93},"message":"SSL/TLS verifications disabled.","ecs.version":"1.6.0"}

```

As @dgcapel said, this file does not change at all after restarting service, nor create new log files.

I noticed in other hosts a log file is created in `C:\Program Files\Elastic\Agent\elastic-agent.log` but no matter what it is not created in this host. It only shows up when running Elastic Agent from terminal (with run option).

For additional information I'm running Windows 10 Enterprise N, but this hasn't been an issue in other hosts.

Thank you.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 13, 2021, 8:40am UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/5 "2021-01-13T08:40:36Z")

</div>

Something is off here but not sure what yet. Any chance one of you could file an issue in [https://github.com/elastic/beats](https://github.com/elastic/beats) for this issue so we can track this?

---

<div class="post-metadata">

**Author:** ![Michal\_Pristas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_pristas/32/46639_2.png) [@Michal\_Pristas](https://discuss.elastic.co/u/Michal_Pristas)\
**Post date:** [January 13, 2021, 8:46am UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/6 "2021-01-13T08:46:59Z")

</div>

can you check `C:/Program Files/Elastic/Agent/elastic-agent.exe` this should be a symlink/shrotcut, does the path it points to seems correct?

---

<div class="post-metadata">

**Author:** ![icious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icious/32/77965_2.png) [@icious](https://discuss.elastic.co/u/icious)\
**Post date:** [January 14, 2021, 2:14pm UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/7 "2021-01-14T14:14:05Z")

</div>

Will try to file this issue later

---

<div class="post-metadata">

**Author:** ![icious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icious/32/77965_2.png) [@icious](https://discuss.elastic.co/u/icious)\
**Post date:** [January 14, 2021, 2:16pm UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/8 "2021-01-14T14:16:27Z")

</div>

Yes, `C:/Program Files/Elastic/Agent/elastic-agent.exe` exists, and its a symlink to `C:/Program Files/Elastic/Agent/data/elastic-agent-1da173/elastic-agent.exe`.  
Executing Elastic Agent from command line / powershell works fine, it seems an issue with the Windows service.

---

<div class="post-metadata">

**Author:** ![Michal\_Pristas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_pristas/32/46639_2.png) [@Michal\_Pristas](https://discuss.elastic.co/u/Michal_Pristas)\
**Post date:** [January 14, 2021, 2:20pm UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/9 "2021-01-14T14:20:51Z")

</div>

if you could include logs into an issue, even from event log if that is possible this would be extremely helpful

---

<div class="post-metadata">

**Author:** ![icious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icious/32/77965_2.png) [@icious](https://discuss.elastic.co/u/icious)\
**Post date:** [January 20, 2021, 11:48am UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/10 "2021-01-20T11:48:27Z")

</div>

Hi,

@Michal_Pristas, there is nothing in Windows event log related to Elastic Agent process, only reporting it failed but no more information provided.

I forgot to file the issue, but I found a little bit more about this problem.

Looks like the issue is related to the service permissions, since I was able to start it by setting Elastic Agent service's login option to the administrator user I registered it with. If this option is set to local system, it won't start. This only happens in my local machine, some View clients are working fine with local system account.

Do you know any Windows domain account option that could be producing this behaviour?

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2021, 1:48pm UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547/11 "2021-02-17T13:48:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
