# Fleet server issue in cluster

**URL:** <https://discuss.elastic.co/t/fleet-server-issue-in-cluster/381183>\
**Category:** Elasticsearch\
**Tags:** fleet\
**Created:** [August 21, 2025, 12:34am UTC](https://discuss.elastic.co/t/fleet-server-issue-in-cluster/381183 "2025-08-21T00:34:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Post date:** [August 21, 2025, 12:34am UTC](https://discuss.elastic.co/t/fleet-server-issue-in-cluster/381183/1 "2025-08-21T00:34:11Z")

</div>

Hello,

I need your assistance. I set up an Elastic cluster using the enrollment token method, including Kibana, and everything is working correctly the data nodes have their respective roles, etc.

The issue is with the Fleet Server. It is not sending information, and it seems to be a certificate problem. It should be writing to `x.x.x.x:9200`, but as a result, no logs are being ingested. How can I resolve this issue?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 21, 2025, 1:21am UTC](https://discuss.elastic.co/t/fleet-server-issue-in-cluster/381183/2 "2025-08-21T01:21:34Z")

</div>

You didn't show us how you installed the fleet server so we'd only be guessing.

You need to look at the logs...

And how you installed the fleet server

> **[Common problems | Elastic Docs](https://www.elastic.co/docs/troubleshoot/ingest/fleet/common-problems)**
>
> We have collected the most common known problems and listed them here. If your problem is not described here, review the open issues in the following...

And the default elasticsearch output if the fleet settings you probably left it as the default and you need to put the actual IP address and or HTTPs into it

Perhaps look at this

> [@Elastic-agent 8.17.7: logs are not being harvested from .log files on Windows host](https://discuss.elastic.co/t/elastic-agent-8-17-7-logs-are-not-being-harvested-from-log-files-on-windows-host/379447/8):
>
> OK So I know this sounds confusing.... but it is NOT a Remote Elastic Search Cluster... that is for something different .... so that is not the right path. Just go into the Default Output and Edit it and try putting in the correct URL to the elasticsearch host... you should not need to generate a new token etc... Try putting in https://192.168.1.113:9200 I also notice that is say http not https Then try to redeploy the Agent.... if you are using self…

---

<div class="post-metadata">

**Author:** ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Post date:** [August 21, 2025, 6:56am UTC](https://discuss.elastic.co/t/fleet-server-issue-in-cluster/381183/3 "2025-08-21T06:56:47Z")

</div>

--fleet-server-es=https://_:_….:9200 --fleet-server-service-token= --fleet-server-policy=fleet-server-policy --fleet-server-es-ca-trusted-fingerprint=\*\*\*\*\*\*\*\*\* --fleet-server-port=8220

Thank you very much for your response. When setting up the cluster with the enrollment token, the certificate handling should be taken care of automatically, correct?

I believe Fleet is not sending data to Elasticsearch because I haven’t specified a Certificate Authority. I cannot extract the password from the OpenSSL PKCS12 becauseall the nodes done automatically,by enrollment token method.

---

<div class="post-metadata">

**Author:** ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Post date:** [August 21, 2025, 7:02am UTC](https://discuss.elastic.co/t/fleet-server-issue-in-cluster/381183/4 "2025-08-21T07:02:17Z")

</div>

![Screenshot from 2025-08-21 11-01-27](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6c3920b40980c1bba7f8f4fdeb1f5188b7624b8a.png)

---

<div class="post-metadata">

**Author:** ![GiorgioS13](https://avatars.discourse-cdn.com/v4/letter/g/5fc32e/32.png) [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Post date:** [August 21, 2025, 12:13pm UTC](https://discuss.elastic.co/t/fleet-server-issue-in-cluster/381183/5 "2025-08-21T12:13:29Z")

</div>

I find solution it was role problem which one came from YAML file, thank you so much @stephenb
