# Troubleshoot Elastic Endpoint Unhealthy

**URL:** <https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540>\
**Category:** Endpoint Security\
**Created:** [October 6, 2023, 3:45pm UTC](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540 "2023-10-06T15:45:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 6, 2023, 3:45pm UTC](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540/1 "2023-10-06T15:45:36Z")

</div>

Hello,

We are doing a PoC with the Elastic Agent and one of our agent host in this scenario became UNHEALTHY after an upgrade.

We have the following ingestion flow:

Elastic Agent -\> HAProxy (passthrough) -\> Logstash -\> Elasticsearch

And currently we have 3 different policies, one for Linux workstations, one for Linux servers, and one for Windows workstations and is this last one that is not working right.

I requested the `diagnostics.zip` file for this agent and looking at the endpoint service log it says that it cannot connect to the Logstash server, which does not make much sense because no change was made on the network.

The error is not helpful at all:

> {"@timestamp":"2023-10-06T14:47:30.6465521Z","agent":{"id":"03ef0b8d-2d54-4d72-94a7-70189dae65d0","type":"endpoint"},"ecs":{"version":"1.11.0"},"log":{"level":"error","origin":{"file":{"line":662,"name":"LogstashClient.cpp"}}},"message":"LogstashClient.cpp:662 SSL handshake with Logstash server at HAPROXY-IP:5046 encountered an error: (null)","process":{"pid":5172,"thread":{"id":7088}}}

It is complaining about SSL Handshake with the Logstash server and the error is (null), not sure what is happening.

This started after we upgraded the Agent from Fleet UI.

This same ingestion flow works for all the Linux machines, the difference in the policies are only the logstash port.

In the Endpoint screen in Kibana it says that the windows agent has an out-of-date policy, so I'm assuming something didn't worked as expected during the upgrade.

What path should I use to approach this troubleshoot?

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [October 9, 2023, 1:39pm UTC](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540/2 "2023-10-09T13:39:43Z")

</div>

Why don't you ingest the data directly into elasticsearch or instead of logstach and then elasticsearch? Are you using a self-signed certificate? You can try inserting the don't validate certificate tag in Elastic Agent. Another thing is to analyze, on the fleet server, whether there is also incompatibility in any integration of your policy.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 9, 2023, 2:03pm UTC](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540/3 "2023-10-09T14:03:17Z")

</div>

> [@wsouza](#):
>
> Why don't you ingest the data directly into elasticsearch or instead of logstach and then elasticsearch?

We need to use Logstash, only Logstash servers are allowed to connect to the Elasticsearch servers, this is not an issue.

Everything worked fine, the issue only happens for a single Agent, the only one on Windows, after the Upgrade to version 8.10.2.

Since we have a license, we opened a ticket with elastic, it looks like some conflict with our VPN application, as it is intermitent.

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [October 9, 2023, 2:34pm UTC](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540/4 "2023-10-09T14:34:24Z")

</div>

Another possibility is to use wireshark to analyze traffic and try to understand the behavior of this communication. When executing the `telnet iplogstash port` command, is the connection closed normally?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 9, 2023, 2:41pm UTC](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540/5 "2023-10-09T14:41:00Z")

</div>

It is not a connection issue, the connection works, a telnet works, the certificate works, only one agent running windows that has this issue after the upgrade.

It is intermitent and we are investigating a conflict with our VPN client, the agent seems to have some issue related to network.

Since I already opened a ticket I will mark this a concluded.

Thanks anyway @wsouza !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2023, 2:41pm UTC](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540/6 "2023-11-06T14:41:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
