# No Host events Endpoint Security

**URL:** https://discuss.elastic.co/t/no-host-events-endpoint-security/316046
**Category:** Endpoint Security
**Created:** [October 7, 2022, 8:54am UTC](https://discuss.elastic.co/t/no-host-events-endpoint-security/316046 "2022-10-07T08:54:30Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![shellcode](https://avatars.discourse-cdn.com/v4/letter/s/3be4f8/32.png) [@shellcode](https://discuss.elastic.co/u/shellcode)
#### Post date: [October 7, 2022, 8:54am UTC](https://discuss.elastic.co/t/no-host-events-endpoint-security/316046/1 "2022-10-07T08:54:30Z")

</div>

Hi all,

I have installed Elastic Agent (enrolled with fleet and healthy) and Endpoint Security on a couple of hosts. All seems to work, except I am missing host events in the overview. There are events, but the messages don't seem right and there is no `event.module` (the column is missing in pic 2). What did I do wrong?

I am using elastic 8.2.2, the agent is installed only on windows hosts (windows 10 and server 2019). I can confirm that elastic endpoint is installed, because there is a folder in the Elastic directory, although I would expect at least events from Elastic Agent show up.  
The default output is pointing to the correct es instances.

 ![hosts_screenshot](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bdfa1129a8d976627f024e63f31f4f403d5cfb43.png)  
 ![hosts_screenshot2](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2f2c2738743752688f857fc8653401a6bb590291.png)

Thanks!  
Adrian

---

<div class="post-metadata">

### Author: ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)
#### Post date: [October 10, 2022, 2:35pm UTC](https://discuss.elastic.co/t/no-host-events-endpoint-security/316046/2 "2022-10-10T14:35:09Z")

</div>

Hi @shellcode . Those messages you screenshotted (thanks!) are Endpoint log messages. They're saved to the local disk by Endpoint and then written into Elasticsearch by Filebeat. Your screenshot shows that Agent/Filebeat.Endpoint are running on the host and Filebeat is able to write to Elasticsearch (since you're seeing that data!). I also see that Endpoint seems to be writing data it is collecting into Elasticsearch (via the log `Sent 28 documents to Elasticsearch`).

Do you see any documents from the host with `event.module=endpoint` in any `logs-*` (Endpoint' collected events and alerts) or `metrics-*` (Endpoint state management documents) indices? Those documents would be ones written by Endpoint itself. From the information you've shared I expect you'll see data in those indices if you search via Discover or Dev Tools. Also you should see Endpoint data in the Security App in Kibana, it seems you might be using in the Observability App so far?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 7, 2022, 2:35pm UTC](https://discuss.elastic.co/t/no-host-events-endpoint-security/316046/3 "2022-11-07T14:35:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
