System logs not collected on some Elastic Agent policies

Hi everyone,

We use Elastic as a SIEM. I have several Elastic Agent policies, and the same agents are assigned to multiple policies.

However, on some of the policies, system logs from the sources are not being collected, while on other policies everything works normally.

As a temporary workaround, I duplicated the working policy — and then the logs started to appear. But when I create a new policy from scratch and configure it the same way, it still does not work.

What could be causing this behavior, and how can I properly troubleshoot it?

Is there anything specific I should check in Fleet, integrations, or data streams?

Any advice would be appreciated — thank you!