# Fleet Setting output remote elasticsearch Status Unhealthy issues

**URL:** <https://discuss.elastic.co/t/fleet-setting-output-remote-elasticsearch-status-unhealthy-issues/355333>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [March 13, 2024, 5:36pm UTC](https://discuss.elastic.co/t/fleet-setting-output-remote-elasticsearch-status-unhealthy-issues/355333 "2024-03-13T17:36:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fa\_dai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fa_dai/32/101061_2.png) [@fa\_dai](https://discuss.elastic.co/u/fa_dai)\
**Post date:** [March 13, 2024, 5:36pm UTC](https://discuss.elastic.co/t/fleet-setting-output-remote-elasticsearch-status-unhealthy-issues/355333/1 "2024-03-13T17:36:11Z")

</div>

Hello

I set up remote elasticsearch and want to output kibana log to another elasticsearch cluster, but there is an authentication problem.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/6/26335d377cdb2e99f28d51a0ed97d113ceb7acbe.png)

In addition to obtaining the service token from remote elasticsearch, do I need to set any parameters to the Advanced YAML configuration?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/3/23f4dc08915aabd180d19dc9fcb9ca475020d547.png)

I have set certificate\_authorities, but not work

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b569d0dbeb3029899bda6fc05f012cf00f16335b.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/3/f327c36729b6d5e0744ad690d48c23fd199d630c.png)

How should I debug it?

#The local and remote elasticsearch clusters use the same ca credentials

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [March 25, 2024, 2:02pm UTC](https://discuss.elastic.co/t/fleet-setting-output-remote-elasticsearch-status-unhealthy-issues/355333/2 "2024-03-25T14:02:18Z")

</div>

Hey, are you using self-signed certificate?  
You could try to enroll an agent with `--insecure` flag to disable certificate verification: [Troubleshoot common problems | Fleet and Elastic Agent Guide [8.12] | Elastic](https://www.elastic.co/guide/en/fleet/8.12/fleet-troubleshooting.html#agent-enrollment-certs)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2024, 2:02pm UTC](https://discuss.elastic.co/t/fleet-setting-output-remote-elasticsearch-status-unhealthy-issues/355333/3 "2024-04-22T14:02:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
