# ElasticAgent enrolled with Fleet server - Connection failure Elastic Defend

**URL:** <https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219>\
**Category:** Elastic Agent\
**Created:** [October 22, 2024, 12:22pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219 "2024-10-22T12:22:10Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fasertio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fasertio/32/138569_2.png) [@Fasertio](https://discuss.elastic.co/u/Fasertio)\
**Post date:** [October 22, 2024, 12:22pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/1 "2024-10-22T12:22:10Z")

</div>

Dear all,

I've installed Elasticsearch, kibana and a Fleet server on a Ubuntu machine for Security testing. The main goal is to install the elastic agent with the Defend integration for XDR on a Windows machine.

The installation of Elastic, Kibana and Fleet were successful, but when I tried to install the agent, it seems not working for a "connection failure" (based in the agent from Fleet section on Kibana portal.

 ![firefox_kVpssOeSuB](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4cff276d484487908ea254860d4038509b64af30.png)

Trying to troubleshoot I found this information running the elastic-agent test output command:

Elasticsearch server: https://\<IP\_address\>:9200  
Status: SSL peer certificate or SSH remote key was not OK [SSL certificate problem: unable to get local issuer certificate]  
Help: Host needs to trust server cert or server cert needs to be added to Elasticsearch/Fleet config

When I enrolled the elastic agent I've used the --insecure flag because I have SSL certificate selfsigned, what I'm missing?

Thanks.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 22, 2024, 12:26pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/2 "2024-10-22T12:26:24Z")

</div>

Hello and welcome,

How did you install it? Did you change the defaul installation path?

---

<div class="post-metadata">

**Author:** ![Fasertio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fasertio/32/138569_2.png) [@Fasertio](https://discuss.elastic.co/u/Fasertio)\
**Post date:** [October 22, 2024, 12:36pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/3 "2024-10-22T12:36:25Z")

</div>

Hi,

no, is the default one, but at the same time others integration are not sending logs:

1. For the installation I've installed first elasticsearch, then kibana on the same host, creating the different ssl certificate (self-signed) and I can connect and elastic can reach Kibana as well.
2. The installation of the fleet server is healty, but I cannot see any logs coming from system integration. The path where Kibana and ES are installed are the default (/etc/..., /usr/share/....)

 ![immagine](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f658961f82dd721976736f47287faf161e1dd2c.png)

When I try to check the winlog from System integration is empty....

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 22, 2024, 12:41pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/4 "2024-10-22T12:41:34Z")

</div>

> [@Fasertio](#):
>
> but at the same time others integration are not sending logs

So, no integrations are sending any log?

What does output looks like? In the Fleet UI go to Settings and share a screenshot.

---

<div class="post-metadata">

**Author:** ![Fasertio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fasertio/32/138569_2.png) [@Fasertio](https://discuss.elastic.co/u/Fasertio)\
**Post date:** [October 22, 2024, 12:45pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/5 "2024-10-22T12:45:12Z")

</div>

Hi,

I can post only a screenshot for post 😃 , btw this is what I see, no one are sending logs but are configured only 2 agent:

- Ubuntu-siem-2 (healthy) is the Fleet server, where is implemented System integration (is healthy, but I don't see any log)
- cb-web-01: windows server 2016 with System + Defend (no one are sending logs)

 ![immagine](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b3feff06e58db149f79a694d2f1d1fffa5aeedb8.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 22, 2024, 12:51pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/6 "2024-10-22T12:51:45Z")

</div>

Are those hosts able to reach the Elasticsearch IP?

If they are able to reach the destination ip you will need to check the logs of the agents for any errors.

They will be in the default folder on a path like this: `Agent/data/elastic-agent-someHash/logs`

---

<div class="post-metadata">

**Author:** ![Fasertio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fasertio/32/138569_2.png) [@Fasertio](https://discuss.elastic.co/u/Fasertio)\
**Post date:** [October 22, 2024, 12:55pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/7 "2024-10-22T12:55:25Z")

</div>

Hi,

the fleet-server gives healthy status, instead of windows machine.  
I've checked the logs and for the windows machine, the "system" folder under logs is empty, the only files that I have for logs are base don this error:

{"log.level":"error","@timestamp":"2024-10-22T12:53:56.139Z","message":"Error dialing x509: certificate signed by unknown authority","component":{"binary":"filebeat","dataset":"elastic\_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"esclientleg","service.name":"filebeat","network":"tcp","address":"172.16.205.11:9200","log.origin":{"file.line":39,"file.name":"transport/logging.go","function":"[github.com/elastic/elastic-agent-libs/transport/httpcommon.(\*HTTPTransportSettings).RoundTripper.LoggingDialer.func2"},"ecs.version":"1.6.0","ecs.version":"1.6.0](http://github.com/elastic/elastic-agent-libs/transport/httpcommon.(*HTTPTransportSettings).RoundTripper.LoggingDialer.func2%22%7D,%22ecs.version%22:%221.6.0%22,%22ecs.version%22:%221.6.0)"}

I've used the --insecure for the installation of the agent 🤔 for bypass this point....

---

<div class="post-metadata">

**Author:** ![Fasertio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fasertio/32/138569_2.png) [@Fasertio](https://discuss.elastic.co/u/Fasertio)\
**Post date:** [October 22, 2024, 2:54pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/8 "2024-10-22T14:54:15Z")

</div>

Edit:

I tried to reinstall the Elastic-agent with the fleet enroll and passing again the --insecure flag, but nothing changed:

in the logs is present the same error and from the portal the incoming data still pending:

 ![immagine](https://us1.discourse-cdn.com/elastic/original/3X/4/5/4510f3b3ff8de6975e39935dafc4b35f388e12e8.png)

Command used:

.\elastic-agent.exe install --url=https://\<IP\_ADDRESS\>:8220 --enrollment-token=\<ENROLLMENT\_TOKEN\> --insecure

Should I add something related to certificate for connect to elasticsearch?  
Any suggestions?

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [October 22, 2024, 3:05pm UTC](https://discuss.elastic.co/t/elasticagent-enrolled-with-fleet-server-connection-failure-elastic-defend/369219/9 "2024-10-22T15:05:37Z")

</div>

Since you needed to use `--insecure`, I wonder if you also need to disable certificate validation for the output connection. `--insecure` controls validation of the connection from Agent/Beats/Endpoint to Fleet Server, the output configuration controls the connection to Elasticsearch.

What I mean is to go to Fleet -\> Settings then Edit the configuration for the Elasticsearch output your Agent's are using. In the [Advanced YAML configuration](https://www.elastic.co/guide/en/fleet/8.16/es-output-settings.html) see if the below [verification\_mode](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#client-verification-mode) YAML solves your problem. If it does, then of course make a decision for yourself if that's acceptable long term or it has just proven you will be in good shape once you update your certificate.

```yaml
ssl:
  verification_mode: none

```
