Hello @warkolm,
Sorry about that. Did not know.
So I'll post some text from endpoint*.log:
tp.cpp"}}},"message":"Http.cpp:38 CURL error 60: Error [SSL certificate problem: unable to get local issuer certificate]","process":{"pid":10012,"thread":{"id":3828}}}
{"@timestamp":"2020-12-11T00:44:18.5332287Z","agent":{"id":"5b05aef9-fc59-0d88-f268-461975e80fae","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"notice","origin":{"file":{"line":84,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:84 Elasticsearch connection is down","process":{"pid":10012,"thread":{"id":3828}}}
CURL error 60: Error [SSL certificate problem: unable to get local issuer certificate]","process":{"pid":592,"thread":{"id":1384}}}
{"@timestamp":"2020-12-09T14:54:55.0468446Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"notice","origin":{"file":{"line":84,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:84 Elasticsearch connection is down","process":{"pid":592,"thread":{"id":1384}}}
{"@timestamp":"2020-12-09T14:54:55.1093331Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":83,"name":"AgentConnectionInfo.cpp"}}},"message":"AgentConnectionInfo.cpp:83 Failed to find connection to validate. Is Agent listening on 127.0.0.1:6788?","process":{"pid":592,"thread":{"id":2080}}}
{"@timestamp":"2020-12-09T14:54:55.1093331Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":107,"name":"AgentConnectionInfo.cpp"}}},"message":"AgentConnectionInfo.cpp:107 Agent process is not root/admin or validation failed, disconnecting","process":{"pid":592,"thread":{"id":2080}}}
{"@timestamp":"2020-12-09T14:54:55.1093331Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"warning","origin":{"file":{"line":164,"name":"AgentConnectionInfo.cpp"}}},"message":"AgentConnectionInfo.cpp:164 Failed to established stage 1 connection to agent","process":{"pid":592,"thread":{"id":2080}}}
{"@timestamp":"2020-12-09T14:54:55.1093331Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":538,"name":"AgentComms.cpp"}}},"message":"AgentComms.cpp:538 Unable to retrieve connection info from Agent(Agent is not running as root)","process":{"pid":592,"thread":{"id":2080}}}
{"@timestamp":"2020-12-09T14:55:00.0468855Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":1442,"name":"HttpLib.cpp"}}},"message":"HttpLib.cpp:1442 Establishing GET connection to [https://192.168.224.10:9200/_cluster/health]","process":{"pid":592,"thread":{"id":1384}}}
{"@timestamp":"2020-12-09T14:55:00.0468855Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":38,"name":"Http.cpp"}}},"message":"Http.cpp:38 CURL error 60: Error [SSL certificate problem: unable to get local issuer certificate]","process":{"pid":592,"thread":{"id":1384}}}
{"@timestamp":"2020-12-09T14:55:00.0468855Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"notice","origin":{"file":{"line":84,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:84 Elasticsearch connection is down","process":{"pid":592,"thread":{"id":1384}}}
{"@timestamp":"2020-12-09T14:55:01.1094495Z","agent":{"id":"93924273-5e90-c21c-3748-ec0f2c92b9e8","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":83,"name":"AgentConnectionInfo.cpp"}}},"message":"AgentConnectionInfo.cpp:83 Failed to find connection to validate. Is Agent listening on 127.0.0.1:6788?"
Regards,
Diana