No alert in security detection dashboards after malware attack

Hello @Diana_Dragoiu,

I'm not sure if C:\Program Files\Elastic\Agent\ca.crt is the same certificate authority that is generated by the elasticsearch instance. Can you confirm that?

The ElasticEndpoint makes a direct connection to elasticsearch and according to the logs above it's failing to do so because it cannot find the proper certificate authority in the host's trusted root certificates.

Please ensure the certificate authority from elasticsearch is installed and that ElasticEndpoint service be stopped and started after doing so.

Here's a link to steps I used to get a Windows 10 ElasticEndpoint connected to elasticsearch.

Sure hope this helps.