# ES security entitlements v8.18 onwards

**URL:** https://discuss.elastic.co/t/es-security-entitlements-v8-18-onwards/380418
**Category:** Elasticsearch
**Created:** [July 24, 2025, 9:09am UTC](https://discuss.elastic.co/t/es-security-entitlements-v8-18-onwards/380418 "2025-07-24T09:09:24Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![a2dahiya](https://avatars.discourse-cdn.com/v4/letter/a/ebca7d/32.png) [@a2dahiya](https://discuss.elastic.co/u/a2dahiya)
#### Post date: [July 24, 2025, 9:09am UTC](https://discuss.elastic.co/t/es-security-entitlements-v8-18-onwards/380418/1 "2025-07-24T09:09:24Z")

</div>

# I'm a developer for a observability tool and we are able to monitor upto es v8.17.1. There have been some new security entitlements added for version 8.18+ which are causing problems for our agent to attach to the jvm to collect metrics. Attaching the logs here, any help would really be appreciated, Thanks in advance!

> Exception in thread "Attach Listener" \*\*\* java.lang.instrument ASSERTION FAILED \*\*\*: "!errorOutstanding" with message Outstanding error when calling method in invokeJavaAgentMainMethod at open/src/java.instrument/share/native/libinstrument/JPLISAgent.c line: 627

> \*\*\* java.lang.instrument ASSERTION FAILED \*\*\*: "success" with message invokeJavaAgentMainMethod failed at open/src/java.instrument/share/native/libinstrument/JPLISAgent.c line: 466

> \*\*\* java.lang.instrument ASSERTION FAILED \*\*\*: "success" with message startJavaAgent failed at open/src/java.instrument/share/native/libinstrument/InvocationAdapter.c line: 444

> Agent failed to start!

> Not entitled: component [(unknown)], module [ALL-UNNAMED], class [class com.instana.agent.loader.v1\_3\_69.HttpUtil], entitlement [outbound\_network]org.elasticsearch.entitlement.runtime.api.NotEntitledException: component [(unknown)], module [ALL-UNNAMED], class [class com.instana.agent.loader.v1\_3\_69.HttpUtil], entitlement [outbound\_network]at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.policy.PolicyManager.notEntitled(PolicyManager.java:690)at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.policy.PolicyManager.checkFlagEntitlement(PolicyManager.java:632)at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.policy.PolicyManager.checkEntitlementPresent(PolicyManager.java:722)at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.policy.PolicyManager.checkOutboundNetworkAccess(PolicyManager.java:607)at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.api.ElasticsearchEntitlementChecker.handleNetworkOrFileUrlCheck(ElasticsearchEntitlementChecker.java:658)

> Not entitled: component [(unknown)], module [ALL-UNNAMED], class [class com.instana.agent.loader.v1\_3\_69.OssAwareTempDir], entitlement [file], operation [read], path [/tmp/.instana]org.elasticsearch.entitlement.runtime.api.NotEntitledException: component [(unknown)], module [ALL-UNNAMED], class [class com.instana.agent.loader.v1\_3\_69.OssAwareTempDir], entitlement [file], operation [read], path [/tmp/.instana]at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.policy.PolicyManager.notEntitled(PolicyManager.java:690)at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.policy.PolicyManager.checkFileRead(PolicyManager.java:511)at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.policy.PolicyManager.checkFileRead(PolicyManager.java:475)at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.policy.PolicyManager.checkFileRead(PolicyManager.java:454)at org.elasticsearch.entitlement@8.18.1/org.elasticsearch.entitlement.runtime.api.ElasticsearchEntitlementChecker.check$java\_io\_File$exists(ElasticsearchEntitlementChecker.java:1451)
