Security administration unable to detect any host despite able to enroll the host with elastic agent (Status: Healthy).
Installed version 7.13.2 ELK stack with self signed certificates. Setup fleet server and able to enroll agent with security endpoint integration. Able to receive endpoint security logs. Enrolled multiple instances produce the same result.
Following are logs from the hosts security endpoints
{"@timestamp":"2021-06-24T06:16:16.6015902Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":112,"name":"MetadataThread.cpp"}}},"message":"MetadataThread.cpp:112 Operating System is: Windows 10 Enterprise Evaluation 2009 (10.0.19042.1052)","process":{"pid":3456,"thread":{"id":4060}}}
{"@timestamp":"2021-06-24T06:16:16.6015902Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":519,"name":"MetadataThread.cpp"}}},"message":"MetadataThread.cpp:519 Sending endpoint metadata","process":{"pid":3456,"thread":{"id":4060}}}
{"@timestamp":"2021-06-24T06:16:16.6024135Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":523,"name":"MetadataThread.cpp"}}},"message":"MetadataThread.cpp:523 Sending endpoint metric","process":{"pid":3456,"thread":{"id":4060}}}
{"@timestamp":"2021-06-24T06:16:16.6385318Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":224,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:224 Sent 1 documents to Elasticsearch","process":{"pid":3456,"thread":{"id":4564}}}
{"@timestamp":"2021-06-24T06:16:16.6994065Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":224,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:224 Sent 1 documents to Elasticsearch","process":{"pid":3456,"thread":{"id":4564}}}
{"@timestamp":"2021-06-24T06:16:16.9289913Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":224,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:224 Sent 74 documents to Elasticsearch","process":{"pid":3456,"thread":{"id":4564}}}
{"@timestamp":"2021-06-24T06:16:46.8817119Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":224,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:224 Sent 5 documents to Elasticsearch","process":{"pid":3456,"thread":{"id":4564}}}
{"@timestamp":"2021-06-24T06:16:47.1436673Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":224,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:224 Sent 63 documents to Elasticsearch","process":{"pid":3456,"thread":{"id":4564}}}
{"@timestamp":"2021-06-24T06:17:16.9967916Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":224,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:224 Sent 1 documents to Elasticsearch","process":{"pid":3456,"thread":{"id":4564}}}
{"@timestamp":"2021-06-24T06:17:17.297292Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":224,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:224 Sent 147 documents to Elasticsearch","process":{"pid":3456,"thread":{"id":4564}}}
{"@timestamp":"2021-06-24T06:17:46.9998973Z","agent":{"id":"360f4a95-776e-12fa-7d00-a4382423d8c9","type":"endpoint"},"ecs":{"version":"1.6.0"},"log":{"level":"info","origin":{"file":{"line":224,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:224 Sent 1 documents to Elasticsearch","process":{"pid":3456,"thread":{"id":4564}}}