# Sensor endgame WebSocket validation

**URL:** <https://discuss.elastic.co/t/sensor-endgame-websocket-validation/385836>\
**Category:** Elastic Security\
**Created:** [April 9, 2026, 11:39pm UTC](https://discuss.elastic.co/t/sensor-endgame-websocket-validation/385836 "2026-04-09T23:39:35Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Omar\_Tawfik\_kandil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/omar_tawfik_kandil/32/143039_2.png) [@Omar\_Tawfik\_kandil](https://discuss.elastic.co/u/Omar_Tawfik_kandil)\
**Post date:** [April 9, 2026, 11:39pm UTC](https://discuss.elastic.co/t/sensor-endgame-websocket-validation/385836/1 "2026-04-09T23:39:35Z")

</div>

Hi all,

I’m troubleshooting an Elastic Endgame / SMP issue and wanted to check whether anyone has seen this before.

Environment:

- SMP Platform 3.52.3

- Generated Windows sensor version 3.65.2

- Windows 10 fresh VM and also an older test VM

- Transceiver set to `https://smp-platform`

What happens:

- Sensor package downloads successfully from SMP

- Sensor installs successfully

- `esensor` service starts and stays running

- But during check-in, the sensor repeatedly sends:

- SMP/nginx responds with:

What we already tested:

- Reproduced on two different Windows machines, including a brand-new VM

- Hosts file and name resolution are correct

- SMP certificate imported and HTTPS browsing to SMP works

- Sensor binary download from SMP works

- Nginx websocket proxy configuration was verified

- We even temporarily relaxed `/websocket` validation in nginx for testing, including:

- Result still remained `400`

Important observation:

- The issue is not machine-specific, because the same behavior happens on a fresh VM with a fresh sensor profile

- It looks like the sensor is not completing a valid websocket upgrade handshake, or there is some protocol mismatch between SMP 3.52.3 and the generated 3.65.2 sensor

Question:  
Has anyone seen Endgame sensor installs succeed, but websocket check-in fail with repeated `GET /websocket` -\> `400` on SMP 3.52.3?  
Is there any known compatibility issue, required patch, or specific configuration for this scenario?

Thanks.
