# Fleet-server and filebeats in one elastic-agent

**URL:** <https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355>\
**Category:** Beats\
**Tags:** fleet, filebeat\
**Created:** [August 13, 2021, 12:51pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355 "2021-08-13T12:51:56Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![tkarczewski](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Post date:** [August 13, 2021, 12:51pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/1 "2021-08-13T12:51:56Z")

</div>

Hi,

How to use one elastic-agent on host where elastic stack is deployed to be as fleet server and filebeat collecting udp syslog messages? I red that elastic agent can be use for fleet server and data collection simultaneously.  
I added integrations to default fleet server policy but i don't see open ports listening for syslog input messages.  
Fleet server enrolled succesfully.  
Could you help me, maybe i misunderstood something?

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [August 13, 2021, 1:06pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/2 "2021-08-13T13:06:05Z")

</div>

The steps you took should have enabled that Elastic Agent to start listening for syslog input messages, if you installed the integration that adds it.

What integration did you add to the `Default Fleet Server policy`?

---

<div class="post-metadata">

**Author:** ![tkarczewski](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Post date:** [August 13, 2021, 1:32pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/3 "2021-08-13T13:32:52Z")

</div>

I added system, palo alto and juniper integration. Before i used it in 7.12.0 without fleet server and worked fine. After update to 7.14i started to have problems. I added integrations with the same settings as before update.

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [August 13, 2021, 2:51pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/4 "2021-08-13T14:51:54Z")

</div>

Can you check the logs view for that Elastic Agent, is an errors reports? Does it say the policy is out of date?

---

<div class="post-metadata">

**Author:** ![tkarczewski](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Post date:** [August 13, 2021, 3:22pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/5 "2021-08-13T15:22:15Z")

</div>

I restarted kibana process and then fleet server and integrations started to listen on port. Only palo alto integration doesnt show any logs in discovery logs-panw\* pattern. I see port is open for this integration. Docs are incementing in logs-panw index but when i create pattern and then choose it in discover section i dont see any new logs.

---

<div class="post-metadata">

**Author:** ![tkarczewski](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Post date:** [August 13, 2021, 5:13pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/6 "2021-08-13T17:13:37Z")

</div>

False alarm.  
I reinstalled elastic-agent to make clear new enrollment and have the same problem. 😕  
Where can i find this logs? Policy is up to date.

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [August 13, 2021, 6:04pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/7 "2021-08-13T18:04:10Z")

</div>

The logs should be present inside of Kibana. You can select the Elastic Agent and click the `Logs` tab. Inside that tab it should show all the logs for that agent.

---

<div class="post-metadata">

**Author:** ![tkarczewski](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Post date:** [August 13, 2021, 6:20pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/8 "2021-08-13T18:20:28Z")

</div>

## There are no log messages to display.

---

<div class="post-metadata">

**Author:** ![tkarczewski](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Post date:** [August 13, 2021, 6:21pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/9 "2021-08-13T18:21:47Z")

</div>

I noticed even i set up ip address x.x.x.x:8220 for the fleet server in netstat i see  
:::8220 :::\* LISTEN 0 613345 5610/fleet-server

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [August 16, 2021, 12:45pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/10 "2021-08-16T12:45:32Z")

</div>

Probably need to get the logs from the system to see what is going on, I think there is some other issue occurring, because you should have logs in Kibana if data is shipping.

What OS are you installing Elastic Agent on?

---

<div class="post-metadata">

**Author:** ![tkarczewski](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@tkarczewski](https://discuss.elastic.co/u/tkarczewski)\
**Post date:** [August 17, 2021, 7:21am UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/11 "2021-08-17T07:21:29Z")

</div>

I left elastic agent started and after few hours ports where opened and everything started to work. I don't know why it's working that way? My OS is Debian

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [August 17, 2021, 6:42pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/12 "2021-08-17T18:42:39Z")

</div>

No I don't know why it would take that long to get started, it should be up in a few minutes tops. That is strange behavior.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2021, 8:42pm UTC](https://discuss.elastic.co/t/fleet-server-and-filebeats-in-one-elastic-agent/281355/13 "2021-09-14T20:42:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
