# Elastic Defend host is not registered to the endpoint

**URL:** https://discuss.elastic.co/t/elastic-defend-host-is-not-registered-to-the-endpoint/325805
**Category:** Endpoint Security
**Created:** [February 17, 2023, 3:17am UTC](https://discuss.elastic.co/t/elastic-defend-host-is-not-registered-to-the-endpoint/325805 "2023-02-17T03:17:49Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)
#### Post date: [February 17, 2023, 3:17am UTC](https://discuss.elastic.co/t/elastic-defend-host-is-not-registered-to-the-endpoint/325805/1 "2023-02-17T03:17:49Z")

</div>

Hello everyone, I have this problem and I am looking for your help.  
I created a new policy in Fleet that includes Elastic Defend integration, but my newly registered elastic agent is not registered to the host of the endpoint, why is this? What is the solution or what is the problem if I query this?  
It's worth mentioning that I used logstash to export the data.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fbd1440f52f3fa1c54adec7222a6e50076a60015.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/4672fceb080dc6e734be4d590beea7f947585a4e.png)

---

<div class="post-metadata">

### Author: ![j0rj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/j0rj/32/100450_2.png) [@j0rj](https://discuss.elastic.co/u/j0rj)
#### Post date: [February 17, 2023, 2:35pm UTC](https://discuss.elastic.co/t/elastic-defend-host-is-not-registered-to-the-endpoint/325805/2 "2023-02-17T14:35:50Z")

</div>

Hello there,  
Can you check the followings:

**1. Is Elastic Defend package installed on the Host?**

Are the related folders & files created with proper Fleet/ES or Logstash parameters?

**On Windows:**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/3/6304b3c07c245a23bd61ab9265c5106587b9a3a0.png)

**On Linux:**

> ls -l /opt/Elastic/Endpoint/  
> sudo cat /opt/Elastic/Endpoint/elastic-endpoint.yaml

**2. Data Ingestion**

Are you receiving any events from the Elastic Defend package?

Check for the following data stream, do you have any of the following DataStreams created? (Assuming you enabled log collection within the Elastic-Defend configuration)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/e/fe8eb93163306754429c53efc895172f0ff21058.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/3/136d64e3499bedede93afcbc0f56ef81a4f820b6.png)

**3. Transform Status**

If Elastic Defend package is installed, DataStreams are created (+ validated receiving logs from this specific endpoint in of the above endpoint related DataStreams (Filtering on the **host.name** in discover), double check if the Transform jobs used to visualise endpoint status are running & healthy:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55dcb1018cdf559f52f06c53d2333710df34201d.png)

Regards

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 17, 2023, 2:35pm UTC](https://discuss.elastic.co/t/elastic-defend-host-is-not-registered-to-the-endpoint/325805/3 "2023-03-17T14:35:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
