I have enrolled windows serves through fleet and installed elastic-agent on them with malware-protction enabled in detect mode. However not a single log is being shipped hence wondering how do I troubleshoot the issue? What logs should I refer to?
I see all those under fleet and those shows as Healthy status but no security logs are appearing.
Yes the agent shows Healthy and no logs at all. The only integration in Endpoint security and I believe that should collect windows security logs right?
Try enabling the System integration on your agents. That will get you Windows Event logs. You should start to see events when you do that. From there, you can expand your event collection to custom windows event logs to get defender and other events.
Just enabling Endpoint security will pull Elastic EDR logs if there's a detection - but if Windows Defender beats Elastic to the detection, you get a race condition and you would not see any logs.
Dang!! Just a small typo - I made and been troubleshooting for almost 7 days
The stupidity I made was in the fleet setting I typed Elasticsearch port was 920 instead of 9200.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.