# Endpoint Security Not Working

**URL:** <https://discuss.elastic.co/t/endpoint-security-not-working/304755>\
**Category:** Endpoint Security\
**Created:** [May 15, 2022, 3:06pm UTC](https://discuss.elastic.co/t/endpoint-security-not-working/304755 "2022-05-15T15:06:38Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)\
**Post date:** [May 16, 2022, 10:48am UTC](https://discuss.elastic.co/t/endpoint-security-not-working/304755/2 "2022-05-16T10:48:16Z")

</div>

Hi Reda. Sorry to hear about this issue.

Can you please tell us how do you enrol agent on your host? Is it done through Fleet Integration as it advised in official documentation?

> **[Install and configure the Elastic Defend integration | Elastic Security...](https://www.elastic.co/guide/en/security/current/install-endpoint.html#enroll-security-agent)**

According to docs:

> To configure the Elastic Agent, Endpoint Security requires enrollment through Fleet to enable the integration.  
> Endpoint Security cannot be integrated with an Elastic Agent in standalone mode.

Also, rule execution will fail before the first alert get generated by this rule according to the warning you see

> This warning will continue to appear until a matching index is created or this rule is de-activated. If you have recently enrolled agents enabled with Endpoint Security through Fleet, this warning should stop once an alert is sent from an agent.

Here is also more details into that [Endpoint Security Rules are Failing on On-Prem usage (seen on 7.11.0 BC6 and 8.0/master) · Issue #90401 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/90401#issuecomment-774070671)  
Can you please confirm whether any alert was generated by this rule? If not, this warning should disappear after the first one.

And here is extensive list of test actions how to verify if agent is installed correctly and works as expected [ElasticSIEM unable to find [logs-endpoint.alerts - #9 by Kevin\_Logan](https://discuss.elastic.co/t/elasticsiem-unable-to-find-logs-endpoint-alerts/277681/9).  
Particularly, step with generating a new alert should fix issue you have if agent configured correctly.

Let me know if this helps. Thanks, Vitalii

---

_[View the full topic](https://discuss.elastic.co/t/endpoint-security-not-working/304755)._
