# Issue with Endpoint agent

**URL:** <https://discuss.elastic.co/t/issue-with-endpoint-agent/261610>\
**Category:** Elastic Security\
**Tags:** elastic-stack-monitoring, elastic-stack-security\
**Created:** [January 20, 2021, 4:07am UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610 "2021-01-20T04:07:12Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![trixrahbit](https://avatars.discourse-cdn.com/v4/letter/t/7c8e57/32.png) [@trixrahbit](https://discuss.elastic.co/u/trixrahbit)\
**Post date:** [January 20, 2021, 4:07am UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610/1 "2021-01-20T04:07:12Z")

</div>

I finally got everything setup for my stack but the endpoints are generating a

"Failed to download or validate user artifacts error. "

I cant seem to find anything on this. Could anyone point me in the right direction?

---

<div class="post-metadata">

**Author:** ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Post date:** [January 20, 2021, 5:25pm UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610/2 "2021-01-20T17:25:54Z")

</div>

Known issue. Do you have some successful and some failed events on the same machine?

---

<div class="post-metadata">

**Author:** ![trixrahbit](https://avatars.discourse-cdn.com/v4/letter/t/7c8e57/32.png) [@trixrahbit](https://discuss.elastic.co/u/trixrahbit)\
**Post date:** [January 21, 2021, 1:18pm UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610/3 "2021-01-21T13:18:15Z")

</div>

Nope every machine it fails on.

---

<div class="post-metadata">

**Author:** ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Post date:** [January 21, 2021, 5:38pm UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610/4 "2021-01-21T17:38:52Z")

</div>

Can you look back for the past 24 hours. I get the same thing but it will work every 8 to 12 hours or so.

---

<div class="post-metadata">

**Author:** ![trixrahbit](https://avatars.discourse-cdn.com/v4/letter/t/7c8e57/32.png) [@trixrahbit](https://discuss.elastic.co/u/trixrahbit)\
**Post date:** [January 21, 2021, 11:14pm UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610/5 "2021-01-21T23:14:34Z")

</div>

Its been like it for three days. Doesnt download user artifacts and says the policy failed.

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [January 27, 2021, 10:47pm UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610/6 "2021-01-27T22:47:37Z")

</div>

Do you see the Endpoint in the Security App -\> Administration tab? My understanding from your comment is that you do.

Can you look in Endpoint's logs? They are located in `c:\Program Files\Elastic\Endpoint\state\log\endpoint-*.log` (Windows) `/Library/Elastic/Endpoint/state/log/endpoint-*.log` (macOS) `/opt/Elastic/Endpoint/state/log/endpoint-*.log` (Linux)

When Endpoint applies its configuration (for instance on start up) it will attempt to download, if needed, the user artifacts (for example alert exceptions) then load them into memory. If it fails to download the artifacts or it fails to extract and use them that message will appear in Kibana. My hunch is there is a network issue preventing Endpoint from downloading the user artifacts.

You should see `Failed to download or validate user artifacts` in the Endpoint logs, looking above that in the logs should help shed light on what failed. If you're overwhelmed by the logs feel free to share them (be careful to review them to make sure there is no sensitive data in them).

---

<div class="post-metadata">

**Author:** ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Post date:** [February 10, 2021, 12:30am UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610/7 "2021-02-10T00:30:18Z")

</div>

@ferullo

This is likely what he see:

{"@timestamp":"2021-02-07T05:31:52.6586202Z","agent":{"id":"","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":1446,"name":"HttpLib.cpp"}}},"message":"HttpLib.cpp:1446 Establishing HEAD connection to [[https://artifacts.security.elastic.co/downloads/endpoint/manifest/artifacts-7.10.2.zip](https://artifacts.security.elastic.co/downloads/endpoint/manifest/artifacts-7.10.2.zip)]","process":{"pid":2800,"thread":{"id":5668}}}  
{"@timestamp":"2021-02-07T05:31:52.6898733Z","agent":{"id":","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":38,"name":"Http.cpp"}}},"message":"Http.cpp:38 CURL error 60: Error [SSL certificate problem: unable to get local issuer certificate]","process":{"pid":2800,"thread":{"id":5668}}}  
{"@timestamp":"2021-02-07T05:31:52.6898733Z","agent":{"id":"","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":1637,"name":"Artifacts.cpp"}}},"message":"Artifacts.cpp:1637 Checking if installed global artifacts are valid","process":{"pid":2800,"thread":{"id":5668}}}  
{"@timestamp":"2021-02-07T05:31:52.6898733Z","agent":{"id":"","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":1001,"name":"Crypto.cpp"}}},"message":"Crypto.cpp:1001 RSA signature verified","process":{"pid":2800,"thread":{"id":5668}}}  
{"@timestamp":"2021-02-07T05:31:54.4793928Z","agent":{"id":"","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":125,"name":"AgentContext.cpp"}}},"message":"AgentContext.cpp:125 Agent check-in returned status Success","process":{"pid":2800,"thread":{"id":12848}}}

This wonderful little error lines up with the failed messages on all attempts to get the artifacts from [https://artifacts.security.elastic.co/downloads/endpoint/manifest/](https://artifacts.security.elastic.co/downloads/endpoint/manifest/)"insert version here". Yet on the machine you test you can get to the site just fine.

If a site has user/machine based web filtering turned on and didn't add the exemption directly for download's I would fully expect this to fail.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:22am UTC](https://discuss.elastic.co/t/issue-with-endpoint-agent/261610/8 "2022-11-04T08:22:02Z")

</div>


