# Elastic agent showing unhealthy with windows system

**URL:** <https://discuss.elastic.co/t/elastic-agent-showing-unhealthy-with-windows-system/265341>\
**Category:** Endpoint Security\
**Created:** [February 24, 2021, 12:58pm UTC](https://discuss.elastic.co/t/elastic-agent-showing-unhealthy-with-windows-system/265341 "2021-02-24T12:58:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaykansagara](https://avatars.discourse-cdn.com/v4/letter/j/e95f7d/32.png) [@jaykansagara](https://discuss.elastic.co/u/jaykansagara)\
**Post date:** [February 24, 2021, 12:58pm UTC](https://discuss.elastic.co/t/elastic-agent-showing-unhealthy-with-windows-system/265341/1 "2021-02-24T12:58:35Z")

</div>

hi,

I have install Elastic Agent 7.11.1 on windows server 2012 and enroll it with Fleet.  
Agent policy has 2 different integration as bellow:

1. System
2. Endpoint security

Elastic agent write the logs in windows server as bellow:

```
2021-02-24T13:02:52.483Z	ERROR	application/fleet_gateway.go:168	failed to dispatch actions, error: operator: failed to execute step sc-run, error: operation 'Exec' failed: : operation 'Exec' failed: 

```

This agent also shown as unhealthy in kibana UI as like bellow:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62feccb5a31fb560371d6205725f01f0518f7541.png)

Same elastic agent configuration is working fine with centos.  
I am using ELK stack v7.11.1

Please help me, to out from this situation.

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [February 24, 2021, 5:29pm UTC](https://discuss.elastic.co/t/elastic-agent-showing-unhealthy-with-windows-system/265341/2 "2021-02-24T17:29:14Z")

</div>

Hi @jaykansagara thanks for checking out Endpoint Security!

I assume when you remove the Endpoint integration this issue goes away?

To help narrow down why Endpoint Security is failing to install can you do the following and share the install logs. One possible issue you might be hitting is if you installed a 32bit Agent (`x86` download) on a 64bit machine. That is a known issue we're working to address. The solution to that is to install the `x86_64` Agent in place of the `x86` one.

1. In the elastic-agent download zip, enter the directory `data/elastic-agent-9b2fec/downloads` (the `elastic-agent-*` directory might have a different hash in its name)
2. Unzip endpoint security (`unzip endpoint-security-7.11.1-windows-x86_64.zip`)
3. Try to install Endpoint directly and see what its log output is. To do this run `cd endpoint-security-7.12.0-windows-x86_64 & endpoint-security.exe install --resources endpoint-security-resources.zip --log stdout --log-level trace`

Make sure to install Endpoint from a Administrator `cmd.exe` prompt. Endpoint running without Agent is not supported, so after you install to check the logs, please uninstall with the command `endpoint-security.exe uninstall`.

A github issue to track automating the presentation of these logs in the UI is [here](https://github.com/elastic/beats/issues/23760)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2021, 5:29pm UTC](https://discuss.elastic.co/t/elastic-agent-showing-unhealthy-with-windows-system/265341/3 "2021-03-24T17:29:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
