# Elastic defend with elastic instance in hetzner

**URL:** <https://discuss.elastic.co/t/elastic-defend-with-elastic-instance-in-hetzner/370442>\
**Category:** Endpoint Security\
**Tags:** elastic-stack-security\
**Created:** [November 12, 2024, 11:15pm UTC](https://discuss.elastic.co/t/elastic-defend-with-elastic-instance-in-hetzner/370442 "2024-11-12T23:15:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Issam\_Zgybi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/issam_zgybi/32/139173_2.png) [@Issam\_Zgybi](https://discuss.elastic.co/u/Issam_Zgybi)\
**Post date:** [November 12, 2024, 11:15pm UTC](https://discuss.elastic.co/t/elastic-defend-with-elastic-instance-in-hetzner/370442/1 "2024-11-12T23:15:09Z")

</div>

hello team,

i have an elastic + kibana in a hetzner server behind pfsense, my problem is with elastic defend integration, the integration is not working! the agent apear as unhealthy, my setup is the elastic is accesible via a public ip, i believe that the defend integration is trying to access the instance using privat ip! how i can make it work?

thanks in advance

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [November 13, 2024, 9:00am UTC](https://discuss.elastic.co/t/elastic-defend-with-elastic-instance-in-hetzner/370442/2 "2024-11-13T09:00:47Z")

</div>

Let me elaborate some thoughts, hopefully it'll help. Obviously I can't be more specific with such limited information.

First of all talking about Elastic Defend, it always goes in tandem with Elastic Agent on the target machine. The Agent is not the EDR service, it's kind of universal coordinator of all Elastic integrations. The service behind Elastic Defend is called Elastic Endpoint.

When you see `unhealthy` status of Agent in Kibana, it can be unhealthy for reasons other than Defend integration, or indeed the unhealthy status is bubbling up from Endpoint service being unhealthy.

Both services have command line interface for troubleshooting

> **[Elastic Agent command reference | Fleet and Elastic Agent Guide \[8.16\] | Elastic](https://www.elastic.co/guide/en/fleet/current/elastic-agent-cmd-options.html#elastic-agent-global-flags)**

> **[Elastic Endpoint command reference | Serverless | Elastic](https://www.elastic.co/guide/en/serverless/current/security-endpoint-command-ref.html)**

I'd suggest to start from the end, with Elastic Endpoint service.  
The `test` command is designed specifically to verify accessibility of necessary external resources:  
`[os dependent path]\elastic-endpoint test output`

Resolve any error indicated here. The `inspect` command might be helpful to verify current policy content vs expected one.

The problem can be also caused by issues with local Agent \<-\> Endpoint communication. The `status` command will help here.

Lastly, you can also generate the `diagnostics` bundle. It gathers fairly comprehensive overview of the Endpoint/Agent state, which is usually sufficient for Elastic support to pin-point any issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2024, 9:01am UTC](https://discuss.elastic.co/t/elastic-defend-with-elastic-instance-in-hetzner/370442/3 "2024-12-11T09:01:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
