Get agent event logs via Elastic Agent Integration

After the 8.15.0 update, with the separation of event logs belonging to filebeat and metricbeat, we can no longer monitor the event logs belonging to the agent via Kibana with the Elastic Agent integration. There is only a notification saying "Cannot index event (status=400): dropping event! Look at the event log to view the event and cause."

Is there a chance to monitor the main reason for the errors we receive (event logs) via Kibana without connecting to the server the agent is connected to? As far as I understand, the separated event logs are not currently indexed to Elasticsearch with this integration. Is there a solution for this? Or will there be an update in the near future where we can see all the logs belonging to the agent in this integration?

Hi @edemir, Welcome to the community!

Yes, this has changed due to security concerns.

The design for the long-term fix is still being worked on.

So, at this time, unfortunately, the current approach of logging into the agent host is the temporary solution.

EDIT : See below for another option

1 Like

@edemir, the event logs are in the diagnostics bundle, you can request them via Kibana, download onto your machine and look at the logs. If you prefer you can eve upload them on Kibana to analyse.

2 Likes