# Uptime monitors false positive results

**URL:** <https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976>\
**Category:** Elastic Observability\
**Created:** [January 29, 2024, 9:59am UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976 "2024-01-29T09:59:59Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [January 29, 2024, 9:59am UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/1 "2024-01-29T09:59:59Z")

</div>

Hi

I've added a monitor and its giving continuous false positive results

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a92be3ca108beff97b2a9adacc89a0a84a5e1b1.png)

I want to know why it is checking 2 times at every interval time

A first its showing correct and then againg checks and shows FP results

---

<div class="post-metadata">

**Author:** ![PaulB-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulb-elastic/32/78691_2.png) [@PaulB-Elastic](https://discuss.elastic.co/u/PaulB-Elastic)\
**Post date:** [January 30, 2024, 12:56pm UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/2 "2024-01-30T12:56:12Z")

</div>

Hi, by default Synthetics monitors will automatically retest if a test fails. This is to limit false positives because of transient issues, such that may occur over the internet.

In your screenshot, this looks like a test at 15:16:19 failed so the retest automatically ran 1 second later, and the retest was successful.

The same thing then happens 3 minutes later at 15:19:19 (suggesting a 3 minute frequency). The UI should represent this with an icon that depicts the test was run because it’s a retest (as opposed to a _natural_ scheduled test):

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4ed3f18852f7b1aef3983ebfcd4c7b3c587c2c27.png)

This does not show in your screenshot, what version of Kibana are you using?

If you don’t want this behaviour (i.e. don’t retest on failure), you can change the default.

If you have configured your monitors via the UI, toggle the _Enable retest on failure_ option:

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/e/aeebd0c090133b6052df863f73d718de1f8fe372.png)

If you are using Project Monitors, set this via the `retestOnFailure` parameter ([docs](https://www.elastic.co/guide/en/observability/current/synthetics-configuration.html#synthetics-configuration-monitor)).

One thing that stands out in your screenshot is that the failure is pretty quick (under 1 second), with the successful retest taking \> 9 seconds. Perhaps this is indicative of a problem with the endpoint you are hitting e.g. if you tried something like `curl`, does the first test fail then a second in quick succession, pass?

---

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [February 1, 2024, 10:23am UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/3 "2024-02-01T10:23:59Z")

</div>

Hi @PaulB-Elastic  
I'm using v 8.8.1 of ELK

this is all the options I have.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/0/50b5965bc5a3e90843ea5c85adae82c26db3a3a6.png)

---

<div class="post-metadata">

**Author:** ![PaulB-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulb-elastic/32/78691_2.png) [@PaulB-Elastic](https://discuss.elastic.co/u/PaulB-Elastic)\
**Post date:** [February 2, 2024, 11:47am UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/4 "2024-02-02T11:47:40Z")

</div>

The retest feature didn't come in until 8.11, so your screenshot aligns with that (you won't have the option for retest). In theory, your testing infrastructure shouldn't be retesting either (because it didn't exist as a feature in 8.8).

Are you running your monitors on Private Locations, or the Elastic Managed Testing Infrastructure?

If on Private Locations, what version of Elastic Agent are you running? In theory, if these are also on 8.8.x, they shouldn't be attempting to retest on failure.

---

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [February 6, 2024, 5:07am UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/5 "2024-02-06T05:07:36Z")

</div>

hey @PaulB-Elastic

ELK is on v8.8.1  
without location, monitors won't run.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0af33be0d6189c33c0a2854de60fe0dff65cb4b7.png)

---

<div class="post-metadata">

**Author:** ![PaulB-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulb-elastic/32/78691_2.png) [@PaulB-Elastic](https://discuss.elastic.co/u/PaulB-Elastic)\
**Post date:** [February 6, 2024, 6:42pm UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/6 "2024-02-06T18:42:09Z")

</div>

I am unclear if you are running your own agents (i.e. private locations), or Elastic provided ones?

Is your Elastic stack self-managed or on ESS ? If self-managed, then these must be private locations. Make sure you are running the elastic-agent-complete docker image to match your Elastic stack (8.8.1). Don't try and use a newer version of the Elastic Agent.

---

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [February 8, 2024, 10:23am UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/7 "2024-02-08T10:23:52Z")

</div>

@PaulB-Elastic  
Running own elastic agents and Elastic stack self-managed.  
elastic agent are also same version as elk

---

<div class="post-metadata">

**Author:** ![PaulB-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulb-elastic/32/78691_2.png) [@PaulB-Elastic](https://discuss.elastic.co/u/PaulB-Elastic)\
**Post date:** [February 9, 2024, 3:58pm UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/8 "2024-02-09T15:58:30Z")

</div>

I have to admit I am a little unsure what's happening here.

I have tested an Elastic 8.8.1 stack with 8.8.1 Elastic Agent, and it's behaving as I would expect (a DOWN result does not automatically run another test).

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9bc58a8f0581012df4dab03ab2d9679a89c0c66e.png)

As you can see here, my 3 minute monitor runs every 3 minutes (whether up or down).

Can you confirm you using the `elastic-agent-complete` docker image for your private location?

As I understand, you have set up an HTTP monitor to run every 3 minutes. Does every initial test (at the 3 minute mark) fail and then there is a (pretty much immediate) second test that is successful?

I wonder if for some reason Heartbeat is restarting during the failure, which results in another immediate test (which happens to be up)? Is your docker container continually running throughout this?

---

<div class="post-metadata">

**Author:** ![emilioalvap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emilioalvap/32/99310_2.png) [@emilioalvap](https://discuss.elastic.co/u/emilioalvap)\
**Post date:** [February 9, 2024, 4:29pm UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/9 "2024-02-09T16:29:59Z")

</div>

Hi @theacodes,

Are the IPs pinged in the duplicate tests different?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37241f9968487a3aca28c54897b95bb1837ea42f.jpeg)

If so, you might have enabled ping-all mode and your endpoint might resolve to multiple IPs. You'll find it inside **Edit Monitor** -\> **Advanced options** :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e771d2e0a278ffff46c0c432dc8c531d1957cf61.png)

If that's not the case, can you make sure that there's only one agent enrolled in the private location policy? Having more than one agent enrolled in a private location policy can lead to duplicate runs. You'll find that in **Fleet -\> Agent Policies** :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/46150026b105f1357b51c7e3a93cb336a1b7d39b.png)

---

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [February 12, 2024, 12:45pm UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/10 "2024-02-12T12:45:21Z")

</div>

Hi @emilioalvap @PaulB-Elastic  
I'm confused as well. I've set up a new instance on 8.12 on my local machine VM. (_Not installed heartbeat only added the monitor in Synthetics app_)  
and it's working fine, Just like you showed @PaulB-Elastic

For my current installation of ELK v8.8.1  
I've added monitors in Uptime and then later managed it under synthetics.

I have enabled ping-all mode and the endpoint resolves to single IPs.

> Can you confirm you using the elastic-agent-complete docker image for your private location?  
> No. I've installed it via the deb package. No docker was used. both for my new VM instance & current v8.8.1 instance.

---

<div class="post-metadata">

**Author:** ![emilioalvap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emilioalvap/32/99310_2.png) [@emilioalvap](https://discuss.elastic.co/u/emilioalvap)\
**Post date:** [February 19, 2024, 6:20pm UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/11 "2024-02-19T18:20:58Z")

</div>

Hi @theacodes,

Can you please confirm that only one agent is running under the private location policy? You can find the instructions on how to find that information in my comment above:

> If that's not the case, can you make sure that there's only one agent enrolled in the private location policy? Having more than one agent enrolled in a private location policy can lead to duplicate runs. You'll find that in **Fleet -\> Agent Policies** :

---

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [February 26, 2024, 6:57am UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/12 "2024-02-26T06:57:55Z")

</div>

there are 2 agents enrolled in fleet server policy @emilioalvap

---

<div class="post-metadata">

**Author:** ![emilioalvap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emilioalvap/32/99310_2.png) [@emilioalvap](https://discuss.elastic.co/u/emilioalvap)\
**Post date:** [February 26, 2024, 12:17pm UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976/13 "2024-02-26T12:17:01Z")

</div>

Hi @theacodes,

Each agent enrolled in the private location policy will execute the configured checks independently. If you have two agents enrolled, you'll get duplicate checks.

Edit: Please read through our docs on private location scaling:

> Do _not_ run the same agent policy on multiple agents being used for Private Locations, as you may end up with duplicate or missing tests. Private Locations do not currently load balance tests across multiple Elastic Agents. See [Scaling Private Locations](https://www.elastic.co/guide/en/observability/current/synthetics-private-location.html#synthetics-private-location-scaling) for information on increasing the capacity within a Private Location.
