Hi @francescouk
Could you check out this thread and see if it helps you? Elastic endpoint overwrites configuration file
It looks like the Endpoint data should start flowing if you follow the steps to set the server in Ingest Manager and then have the config update propagate down to Endpoint.
I'm going to copy/paste the steps I left in the other thread at the end of this message. If this doesn't resolve you're issue please let me know.
Workaround steps:
- In ingest manager, under the main settings menu, you can update,add,change the Kibana and Elasticsearch URLs. Click save.
- Afterward, under the Configurations tab of ingest manager, click on the Configuration assigned to the endpoint you want to update.
- On the Configuration page, in the integrations tab, click the actions "..." for the Elastic Endpoint Security integration and select "Edit integration"
- On this next page, click "Save integration" in the bottom right (you do not need to make any changes).