# How do I troubleshoot elastic agent not sending any logs to siem app

**URL:** <https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311>\
**Category:** SIEM\
**Created:** [October 10, 2021, 1:36pm UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311 "2021-10-10T13:36:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [October 10, 2021, 1:36pm UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311/1 "2021-10-10T13:36:03Z")

</div>

Hi Team,

I have enrolled windows serves through fleet and installed elastic-agent on them with malware-protction enabled in detect mode. However not a single log is being shipped hence wondering how do I troubleshoot the issue? What logs should I refer to?

I see all those under fleet and those shows as Healthy status but no security logs are appearing.

TIA  
Blason R

---

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [October 11, 2021, 1:44am UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311/2 "2021-10-11T01:44:06Z")

</div>

How are your agent policies set up, and what integrations have you enabled?

If you go into an agent that shows healthy, and then go to the logs tab within the agent - do you have any logs there?

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [October 11, 2021, 3:07am UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311/3 "2021-10-11T03:07:46Z")

</div>

Yes the agent shows Healthy and no logs at all. The only integration in Endpoint security and I believe that should collect windows security logs right?

---

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [October 12, 2021, 1:07am UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311/4 "2021-10-12T01:07:42Z")

</div>

Try enabling the System integration on your agents. That will get you Windows Event logs. You should start to see events when you do that. From there, you can expand your event collection to custom windows event logs to get defender and other events.

Just enabling Endpoint security will pull Elastic EDR logs if there's a detection - but if Windows Defender beats Elastic to the detection, you get a race condition and you would not see any logs.

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [October 12, 2021, 3:33am UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311/5 "2021-10-12T03:33:07Z")

</div>

Dang!! Just a small typo - I made and been troubleshooting for almost 7 days ☹  
The stupidity I made was in the fleet setting I typed Elasticsearch port was 920 instead of 9200.

---

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [October 12, 2021, 11:39am UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311/6 "2021-10-12T11:39:55Z")

</div>

Glad you caught it!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2021, 11:40am UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311/7 "2021-11-09T11:40:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
