# Host an air-gapped Elastic Endpoint artifact server

**URL:** <https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870>\
**Category:** Endpoint Security\
**Created:** [July 26, 2024, 2:55pm UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870 "2024-07-26T14:55:53Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![devilman85](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devilman85/32/136330_2.png) [@devilman85](https://discuss.elastic.co/u/devilman85)\
**Post date:** [July 26, 2024, 2:55pm UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/1 "2024-07-26T14:55:53Z")

</div>

I have followed the official guide in the subject does not update the signatures despite creating the ngnix server for the files. How can I solve this?

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [July 26, 2024, 7:54pm UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/2 "2024-07-26T19:54:45Z")

</div>

Hi @devilman85.

On the hosts where Endpoint is running, are you able to download the artifacts from your nginx server using a different tool such as `curl`?

For example, a test command would look something like this. The key things to look for are `HTTP/1.1 200 OK` and the `ETag`.

```auto
C:\>curl https://artifacts.security.elastic.co/downloads/endpoint/manifest/artifacts-8.14.2.zip --verbose
* Host artifacts.security.elastic.co:443 was resolved.
* IPv6: (none)
* IPv4: 34.120.127.130
* Trying 34.120.127.130:443...
* Connected to artifacts.security.elastic.co (34.120.127.130) port 443
* schannel: disabled automatic use of client certificate
* ALPN: curl offers http/1.1
* ALPN: server accepted http/1.1
* using HTTP/1.x
> GET /downloads/endpoint/manifest/artifacts-8.14.2.zip HTTP/1.1
> Host: artifacts.security.elastic.co
> User-Agent: curl/8.7.1
> Accept: */*
>
* Request completely sent off
< HTTP/1.1 200 OK
< Content-Length: 27264
< Accept-Ranges: bytes
< Strict-Transport-Security: max-age=31536000; includeSubDomains
< Via: 1.1 google
< Date: Fri, 26 Jul 2024 19:40:17 GMT
< Cache-Control: public, max-age=60
< Age: 33
< Last-Modified: Fri, 26 Jul 2024 12:02:31 GMT
< ETag: "010364f3bfdcf4c2223716808277ec78"
< Content-Type: binary/octet-stream
< Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
<
Warning: Binary output can mess up your terminal. Use "--output -" to tell
Warning: curl to output it to your terminal anyway, or consider "--output
Warning: <FILE>" to save to a file.
* Failure writing output to destination, passed 2360 returned 4294967295
* Closing connection
* schannel: shutting down SSL/TLS connection with artifacts.security.elastic.co port 443

```

If you aren't able to reach it, then there's an issue with your network or nginx which you'll first need to debug.

If that's working as expected, then it would be good to check out Endpoint's logs in `C:\Program Files\Elastic\Endpoint\state\log`. If you're an Elastic customer, the next step would be to send those logs to your support contact at Elastic.

---

<div class="post-metadata">

**Author:** ![devilman85](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devilman85/32/136330_2.png) [@devilman85](https://discuss.elastic.co/u/devilman85)\
**Post date:** [July 26, 2024, 8:16pm UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/3 "2024-07-26T20:16:15Z")

</div>

But my environment it's full air gapped. I hosting the articifacts and the binary on the Ngnix server. I Download the artefacts from this command on online host:

export ENDPOINT\_VERSION=8.14.3 && wget -P downloads/endpoint/manifest [https://artifacts.security.elastic.co/downloads/endpoint/manifest/artifacts-$ENDPOINT\_VERSION.zip](https://artifacts.security.elastic.co/downloads/endpoint/manifest/artifacts-$ENDPOINT_VERSION.zip) && zcat -q downloads/endpoint/manifest/artifacts-$ENDPOINT\_VERSION.zip | jq -r '.artifacts | to\_entries | .value.relative\_url' | xargs -I@ curl "[https://artifacts.security.elastic.co](https://artifacts.security.elastic.co)@" --create-dirs -o ".@"

and validate che file from this command:

curl -s [https://artifacts.security.elastic.co/downloads/endpoint/manifest/artifacts-8.14.3.zip](https://artifacts.security.elastic.co/downloads/endpoint/manifest/artifacts-8.14.3.zip) | zcat -q | jq -r .manifest\_version

After updating the Elastic Endpoint configuration to read from the mirror server, use Kibana’s [Discover view](https://www.elastic.co/guide/en/kibana/8.14/discover.html) to search the `metrics-*` data view for `endpoint.policy` response documents, then check the installed version (`Endpoint.policy.applied.artifacts.global.version` ) but I don't see the updating version

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [July 26, 2024, 8:40pm UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/4 "2024-07-26T20:40:12Z")

</div>

> [@devilman85](#):
>
> But my environment it's full air gapped. I hosting the articifacts and the binary on the Ngnix server. I Download the artefacts from this command on online host

Understood. I'm asking you to test whether the host running Endpoint can reach your artifact server and download artifacts therefrom. You would run a `curl` command on your Endpoint host, replacing `artifacts.security.elastic.co` with the hostname of your nginx server.

---

<div class="post-metadata">

**Author:** ![devilman85](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devilman85/32/136330_2.png) [@devilman85](https://discuss.elastic.co/u/devilman85)\
**Post date:** [July 26, 2024, 8:53pm UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/5 "2024-07-26T20:53:41Z")

</div>

Yes. I replace the artifact link with my ngnix server But in kibana the new version don’t visualize

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [July 26, 2024, 9:12pm UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/6 "2024-07-26T21:12:46Z")

</div>

> [@devilman85](#):
>
> Yes. I replace the artifact link with my ngnix server But in kibana the new version don’t visualize

Thanks. I understand that you're not seeing `Endpoint.policy.applied.artifacts.global.version` changing in Kibana's discover view for ` metrics-*` with filter `event.dataset: "endpoint.policy"`.

The next step from here is to ensure that the host running Endpoint can successfully form and validate a TLS connection to your artifact server, that the artifacts are in the right location on the server, and that the server is configured correctly. Could you please run this command on the system where Endpoint is running, and paste the output here?

```auto
# Run this on the host where Endpoint is running
curl https://YOUR_NGINX_SERVER/downloads/endpoint/manifest/artifacts-8.14.3.zip --verbose

```

Alternatively, if you can provide Endpoint's logs from `C:\Program Files\Elastic\Endpoint\state\log\*.log`, we may be able to determine what's going on over here. I created [this secure upload link](https://upload.elastic.co/u/74124084-a25d-4b4a-9029-a12c9d4e98f6) specific to your case.

---

<div class="post-metadata">

**Author:** ![devilman85](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devilman85/32/136330_2.png) [@devilman85](https://discuss.elastic.co/u/devilman85)\
**Post date:** [July 27, 2024, 6:27am UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/7 "2024-07-27T06:27:12Z")

</div>

My ngnix server isn’t in https, it’s the problem?

---

<div class="post-metadata">

**Author:** ![devilman85](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devilman85/32/136330_2.png) [@devilman85](https://discuss.elastic.co/u/devilman85)\
**Post date:** [July 29, 2024, 6:54am UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/8 "2024-07-29T06:54:59Z")

</div>

i solved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2024, 6:55am UTC](https://discuss.elastic.co/t/host-an-air-gapped-elastic-endpoint-artifact-server/363870/9 "2024-08-26T06:55:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
