# Elastic Endpoint stuck "STARTING"

**URL:** <https://discuss.elastic.co/t/elastic-endpoint-stuck-starting/374437>\
**Category:** Endpoint Security\
**Created:** [February 12, 2025, 3:41pm UTC](https://discuss.elastic.co/t/elastic-endpoint-stuck-starting/374437 "2025-02-12T15:41:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pok\_lehbim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pok_lehbim/32/140579_2.png) [@pok\_lehbim](https://discuss.elastic.co/u/pok_lehbim)\
**Post date:** [February 12, 2025, 3:41pm UTC](https://discuss.elastic.co/t/elastic-endpoint-stuck-starting/374437/1 "2025-02-12T15:41:55Z")

</div>

I set up an agent policy with a few other integrations that work fine, the only one that is causing trouble is Elastic Defend. Despite using the default configuration it is not working.

Here is all I've been able to gather so far:

```powershell
PS C:\Program Files\Elastic\Endpoint> & 'C:\Program Files\Elastic\Agent\elastic-agent.exe' status
┌─ fleet
│ └─ status: (STOPPED) Not enrolled into Fleet
└─ elastic-agent
	├─ status: (HEALTHY) Running
	└─ endpoint-default
		├─ status: (HEALTHY) Healthy: communicating with endpoint service
		├─ endpoint-default
		│ └─ status: (STARTING)
		└─ endpoint-default-6db8a8d2-f76a-490d-a535-67e47ce26202
		└─ status: (STARTING)       

```

Yet the executable seems to tell another story...  
There is an issue applying the policy to it for some reason.

```powershell
PS C:\Program Files\Elastic\Endpoint> .\elastic-endpoint.exe status
	- elastic-agent
		- status: (HEALTHY) Connected
	- elastic-endpoint
		- status: (HEALTHY) Running (no policy)

```

Logs don't seem to be very helpful either:

```json
{"@timestamp":"2025-02-12T14:40:36.499633Z","agent":{"id":"","type":"endpoint"},"ecs":{"version":"8.10.0"},"log":{"level":"warning","origin":{"file":{"line":485,"name":"AgentContext.cpp"}}},"message":"AgentContext.cpp:485 Endpoint is setting status to STARTING, reason: Policy Application Status","process":{"pid":20384,"thread":{"id":23152}}}

{"@timestamp":"2025-02-12T15:16:59.9940254Z","agent":{"id":"","type":"endpoint"},"ecs":{"version":"8.10.0"},"log":{"level":"notice","origin":{"file":{"line":182,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:182 No valid comms client available","process":{"pid":20384,"thread":{"id":12520}}}

```

Does anyone know what might be causing this or how to get to the root of the issue?

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [February 12, 2025, 5:38pm UTC](https://discuss.elastic.co/t/elastic-endpoint-stuck-starting/374437/2 "2025-02-12T17:38:59Z")

</div>

Elastic Defend is not supported in standalone Agent mode

---

<div class="post-metadata">

**Author:** ![pok\_lehbim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pok_lehbim/32/140579_2.png) [@pok\_lehbim](https://discuss.elastic.co/u/pok_lehbim)\
**Post date:** [February 13, 2025, 8:05am UTC](https://discuss.elastic.co/t/elastic-endpoint-stuck-starting/374437/3 "2025-02-13T08:05:37Z")

</div>

Thank you, that explains it!

Is this mentioned anywhere in the docs?

---

<div class="post-metadata">

**Author:** ![Chris\_Owens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_owens/32/57329_2.png) [@Chris\_Owens](https://discuss.elastic.co/u/Chris_Owens)\
**Post date:** [February 13, 2025, 3:31pm UTC](https://discuss.elastic.co/t/elastic-endpoint-stuck-starting/374437/4 "2025-02-13T15:31:42Z")

</div>

It is mentioned here in the docs: [Install the Elastic Defend integration | Elastic Security Solution [8.17] | Elastic](https://www.elastic.co/guide/en/security/current/install-endpoint.html#enroll-security-agent)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2025, 3:31pm UTC](https://discuss.elastic.co/t/elastic-endpoint-stuck-starting/374437/5 "2025-03-13T15:31:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
