# Problem with Kubernetes agent status showing as offline

**URL:** <https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351>\
**Category:** Elastic Agent\
**Created:** [May 13, 2023, 3:33pm UTC](https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351 "2023-05-13T15:33:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dbstjdghks25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dbstjdghks25/32/120884_2.png) [@dbstjdghks25](https://discuss.elastic.co/u/dbstjdghks25)\
**Post date:** [May 13, 2023, 3:33pm UTC](https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351/1 "2023-05-13T15:33:34Z")

</div>

I checked the health of a specific pod in Kubernetes by accessing it, and the fleet appears to be healthy, but the logs are not being sent to the agents and they appear as offline. However, when I check the Elasticsearch dashboard, it shows that everything is working properly. What could be causing this issue

```bash
root@master20-3:/home/server/kube# kubectl get all
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
service/kubernetes ClusterIP 10.233.0.1 <none> 443/TCP 3h43m

```

```bash
root@master20-3:/home/server/kube# kubectl -n kube-system get pods -o wide | grep elastic
elastic-agent-4kqd8 1/1 Running 0 42m 10.10.1.2 node10-2 <none> <none>
elastic-agent-dmllr 1/1 Running 0 42m 10.40.1.2 node40-2 <none> <none>
elastic-agent-jcl2g 1/1 Running 0 42m 10.20.1.2 node20-2 <none> <none>
elastic-agent-kghhq 1/1 Running 0 42m 10.20.1.3 master20-3 <none> <none>
elastic-agent-tpklq 1/1 Running 0 42m 10.11.1.2 node11-2 <none> <none>
elastic-agent-vdh6j 1/1 Running 0 42m 10.11.1.3 node11-3 <none> <none>
elastic-agent-zl55x 1/1 Running 0 42m 10.10.1.3 node10-3 <none> <none>

```

I have manually checked the health of specific pods and they appear to be functioning properly, which makes it even more confusing as to why the agent status is showing as offline.

```bash
kubectl -n kube-system exec -it elastic-agent-4kqd8 -- curl -f https://10.60.1.2:8220/api/status --insecure
{"name":"fleet-server","status":"HEALTHY"}

```

The network is configured as follows, and the SIEM at 10.60.1.2 is used as the FLEET to send agent cluster logs there.  
Also, the SIEM monitors traffic from other LANs using SPAN.

 ![forum](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e270797c9ea7ac39f19440ab222cb74307212fd.png)

---

<div class="post-metadata">

**Author:** ![dbstjdghks25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dbstjdghks25/32/120884_2.png) [@dbstjdghks25](https://discuss.elastic.co/u/dbstjdghks25)\
**Post date:** [May 15, 2023, 10:56am UTC](https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351/2 "2023-05-15T10:56:32Z")

</div>

Although there is no response, I have resolved the issue. If you encounter a similar problem, try removing the integration that logs audits from the agent policy. It appears that the health check logs were lost in the middle due to this integration.

 ![화면 캡처 2023-05-15 195552](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7fd8cc985fd122e1f5a9ce8c71e459ee65565152.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2023, 10:57am UTC](https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351/3 "2023-06-12T10:57:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
