# Installed Elastic-Agent cannot be removed

**URL:** <https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [January 5, 2024, 3:28pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473 "2024-01-05T15:28:57Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ghuie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghuie/32/130569_2.png) [@ghuie](https://discuss.elastic.co/u/ghuie)\
**Post date:** [January 5, 2024, 3:28pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/1 "2024-01-05T15:28:57Z")

</div>

So, I have a self-hosted ELK Stack (v. 8.11) in which I've been working for a few weeks.  
I've configured the certificates using the _elasticsearch-certutil_ util and Elastic + Kibana are working fine.

After that I wanted to configure a Fleet server. I followed this steps given to me by my ELK instance in the _Add a Fleet Server_ page:

```auto
curl -L -O https[:]//artifacts[.]elastic[.]co/downloads/beats/elastic-agent/elastic-agent-8.11.3-linux-x86_64.tar.gz
tar xzvf elastic-agent-8.11.3-linux-x86_64.tar.gz
cd elastic-agent-8.11.3-linux-x86_64
sudo ./elastic-agent install \
  --fleet-server-es=http[:]//MY-IP-ADDRESS[:]9200 \
  --fleet-server-service-token=MY_ENROLLMENT_TOKEN \
  --fleet-server-policy=fleet-server-policy \
  --fleet-server-port=8220

```

After running this I got an error which said.

```auto
"log.origin":{"file.name":"cmd/enroll_cmd.go","file.line":807},"message":"Fleet Server - Error - f
ailed version compatibility check with elasticsearch: tls: failed to verify certificate: x509: certificate signed by unknown authority","ecs.version":"1.6.0"}

```

So I started looking to correct that by generating the certificates and prepared the following command to run the installation again (Please note that, at this point, the Fleet Server waiting for a connection from the agent was still waiting, of course). The command was:

sudo ./elastic-agent install \

--fleet-server-es=https[:]//MY-IP-ADDRESS[:]9200   
--fleet-server-service-token=MY-ENROLLMENT-TOKEN   
--fleet-server-policy=fleet-server-policy   
--fleet-server-es-ca=/etc/elasticsearch/certs/http\_ca.crt   
--certificate-authorities=/etc/ssl/fleet/ca/ca.crt   
--fleet-server-cert=/etc/ssl/fleet/fleet-server/fleet-server.crt   
--fleet-server-cert-key=/etc/ssl/fleet/fleet-server/fleet-server.key   
--fleet-server-port=8220

After running that I got this error:  
`Error: already installed at: /opt/Elastic/Agent`

So I tried to run the uninstall command:  
**./elastic-agent uninstall --uninstall-token MY-ENROLLMENT-TOKEN**  
`ERROR: Error: can only be uninstalled by executing the installed Elastic Agent at: /usr/bin/elastic-agent`

In /usr/bin/ I ran:  
**elastic-agent uninstall**  
And got this error:  
`ERROR: Error: can only be uninstalled by executing the installed Elastic Agent at: /usr/bin/elastic-agent`  
again.

At this point I'm not sure how or why this is happening. If maybe I could find a way to configure the settings on the agent I wouldn't need to go through the hassle of finding a way to uninstalling it. I've been trying to find a way to solve this but I didn't touch to much since I don't want to cause more error.

Is there a way to force uninstalling it?

Thanks!

---

<div class="post-metadata">

**Author:** ![ghuie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghuie/32/130569_2.png) [@ghuie](https://discuss.elastic.co/u/ghuie)\
**Post date:** [January 5, 2024, 3:36pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/2 "2024-01-05T15:36:06Z")

</div>

i found this:

> [@Elastic agent uninstall](https://discuss.elastic.co/t/elastic-agent-uninstall/349659/5):
>
> I did this and now it is enrolled, topic can be closed rm /etc/systemd/system/elastic-agent.service root@elk:/opt/Elastic# rm -r Agent curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.11.2-linux-x86\_64.tar.gz tar xzvf elastic-agent-8.11.2-linux-x86\_64.tar.gz cd elastic-agent-8.11.2-linux-x86\_64 sudo ./elastic-agent install --url=https://:8220 --fleet-server-es=[https://localhost:9200](https://localhost:9200) --fleet-server-service-token= --fleet-server-policy=fleet-server-…

I'll give updates.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2024, 3:41pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/3 "2024-01-05T15:41:54Z")

</div>

Hi @ghuie

The proper uninstall command [per the docs](https://www.elastic.co/guide/en/fleet/current/uninstall-elastic-agent.html) is only

`sudo /opt/Elastic/Agent/elastic-agent uninstall`

First try that...

Not running `./elastic-agent uninstall` from the original install directory that will not work.

When I see others get in this state then you need to manually clean up (clean up the /opt/Elastic/Agent directory etc. ... then reinstall and then uninstall properly

Ohh... And Welcome to the Community!

---

<div class="post-metadata">

**Author:** ![ghuie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghuie/32/130569_2.png) [@ghuie](https://discuss.elastic.co/u/ghuie)\
**Post date:** [January 5, 2024, 3:53pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/4 "2024-01-05T15:53:22Z")

</div>

Hi Stephen! Thanks for the quick reply.

I've tried that also just after I posted the problem, but to no effect. It keeps insisting that I do this: `elastic-agent uninstall` from `/usr/bin/`

What I did was delete the process at _systemd/system_ and the agent from _/opt/_.  
To be honest, it's not the way I like to do things but I could not find any other way. After I did that, I ran: `sudo ./elastic-agent install` from the original installation directory just to see if I get an error or the interactive questions to configure the Agent, I got the questions. That makes me think that maybe now the installation will continue.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2024, 3:56pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/5 "2024-01-05T15:56:47Z")

</div>

I agree, it's not a great way.... but it is _ **key** _ to run _ **the correct** _ uninstall command because the Agent Gets installed in `/opt/Elastic/Agent`, so the uninstall needs to run from there... hopefully that makes sense...

if you try to run it from the directory that you untarred into that will not work for sure and leave you in an inconsistent state...

Similar situation here

> [@Elastic agent uninstall](https://discuss.elastic.co/t/elastic-agent-uninstall/349659/5):
>
> I did this and now it is enrolled, topic can be closed rm /etc/systemd/system/elastic-agent.service root@elk:/opt/Elastic# rm -r Agent curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.11.2-linux-x86\_64.tar.gz tar xzvf elastic-agent-8.11.2-linux-x86\_64.tar.gz cd elastic-agent-8.11.2-linux-x86\_64 sudo ./elastic-agent install --url=https://:8220 --fleet-server-es=[https://localhost:9200](https://localhost:9200) --fleet-server-service-token= --fleet-server-policy=fleet-server-…

---

<div class="post-metadata">

**Author:** ![ghuie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghuie/32/130569_2.png) [@ghuie](https://discuss.elastic.co/u/ghuie)\
**Post date:** [January 5, 2024, 4:01pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/6 "2024-01-05T16:01:35Z")

</div>

Oh sorry; what I meant to say is that I did try to run the uninstall command from both, `/usr/bin/` and `/opt/Elastic/Agent`, but it didn't matter the locations from which I was trying to run the command, the error was the same: `Error: can only be uninstalled by executing the installed Elastic Agent at: /usr/bin/elastic-agent`.

If I understand correctly that was what you were suggesting.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2024, 4:05pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/7 "2024-01-05T16:05:34Z")

</div>

> [@ghuie](#):
>
> `Error: can only be uninstalled by executing the installed Elastic Agent at: /usr/bin/elastic-agent`.

Right! but that happens typically when the wrong command is run the first...  
once you do that the agent is left in an inconsistent state then trying to run `/opt/Elastic/Agent/elastic-agent unistall` will not work either

I speak of this from 1st hand experience 😉

If you run the correct command 1st on a correctly installed agent, you should find that uninstall works....

So what I would do ... get a proper installation (or maybe it fails on connection or something) then uninstall correctly see if that works.

From the docs

> To uninstall Elastic Agent, run the `uninstall` command from the directory where Elastic Agent is running:
> 
> You must run this command as the root user.
> 
> `sudo /opt/Elastic/Agent/elastic-agent uninstall`

---

<div class="post-metadata">

**Author:** ![ghuie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghuie/32/130569_2.png) [@ghuie](https://discuss.elastic.co/u/ghuie)\
**Post date:** [January 5, 2024, 4:10pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/8 "2024-01-05T16:10:57Z")

</div>

Oh ok, I get it now. I'll install the agent just to uninstall it to see of it's all OK then.

I'll keep you posted, thanks so much!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2024, 4:11pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/9 "2024-01-05T16:11:31Z")

</div>

@ghuie You are not the first ... nor the last to run into this... 🙂

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2024, 6:50pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/10 "2024-01-05T18:50:54Z")

</div>

BTW PR to get docs fixed

> <https://github.com/elastic/ingest-docs/pull/796>
>
> Users sometimes run the agent uninstall command from the wrong location, causing… instability, so we need clear warnings in the docs.
> 
> Closes: #795 
> 
> \---
> 
> \*\*Update to agent \[uninstall instructions\](https://www.elastic.co/guide/en/fleet/current/uninstall-elastic-agent.html#uninstall-elastic-agent):\*\*
> 
> !\[Screenshot 2024-01-05 at 1 26 33 PM\](https://github.com/elastic/ingest-docs/assets/41695641/efed0670-d59b-4dea-8015-0bf320e1d958)
> 
> \---
> 
> \*\*Update to the agent \[\`uninstall\` command\](https://www.elastic.co/guide/en/fleet/current/elastic-agent-cmd-options.html#elastic-agent-uninstall-command):\*\*
> !\[Screenshot 2024-01-05 at 1 22 00 PM\](https://github.com/elastic/ingest-docs/assets/41695641/f8162d77-452b-4e62-9109-70c09da4fba6)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2024, 6:51pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473/11 "2024-02-02T18:51:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
