# Endpoint Security agents online but not sending any logs

**URL:** <https://discuss.elastic.co/t/endpoint-security-agents-online-but-not-sending-any-logs/260618>\
**Category:** Elastic Security\
**Created:** [January 9, 2021, 8:05pm UTC](https://discuss.elastic.co/t/endpoint-security-agents-online-but-not-sending-any-logs/260618 "2021-01-09T20:05:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [January 9, 2021, 8:05pm UTC](https://discuss.elastic.co/t/endpoint-security-agents-online-but-not-sending-any-logs/260618/1 "2021-01-09T20:05:14Z")

</div>

Hello,

I hope this message finds you healthy and safe.

I am trying to gather logs through Elastic Endpoint Security. I can see the agents online and heartbeats with payload:

``  
{  
"endpoint-security": {  
"@timestamp": "2021-01-09T00:03:34.0428499Z",  
"Endpoint": {  
"configuration": {  
"inputs": [  
{  
"id": "b74b1a70-e523-11ea-bd03-bb1e8c6c445d",  
"policy": {  
"linux": {  
"events": {  
"file": true,  
"network": true,  
"process": true  
},  
"logging": {  
"file": "info"  
}  
},  
"mac": {  
"events": {  
"file": true,  
"network": true,  
"process": true  
},  
"logging": {  
"file": "info"  
},  
"malware": {  
"mode": "prevent"  
}  
},

``

I am however not getting any alerts or telemetry data from the systems using the security endpoint. Am I missing something? For example: I tested with eicar test malware, this was successfully detected by the agent, however there is no log entry or alert. The datastream shows last update in August 2020, when I did the first installation. What can I do to diagnose and fix this?

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [January 11, 2021, 2:29pm UTC](https://discuss.elastic.co/t/endpoint-security-agents-online-but-not-sending-any-logs/260618/2 "2021-01-11T14:29:51Z")

</div>

Hi @parthmaniar

It looks like you found the document that specifies what Elastic Endpoint should do on the host (it's "policy"), not a document sent by Elastic Endpoint to Elasticsearch.

1. Do you see any documents from Elastic Agent? What is Agent's status in the Management-\>Fleet-\>Agents tab?
2. Are you using a self-signed certificate?
3. Have you changed the namespace for the data stream from the default value?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:21am UTC](https://discuss.elastic.co/t/endpoint-security-agents-online-but-not-sending-any-logs/260618/3 "2022-11-04T08:21:14Z")

</div>


