# \#elastic-agent

**URL:** https://discuss.elastic.co/tag/elastic-agent/63.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [High CPU Usage on Elastic Defend and Kibana Processes](https://discuss.elastic.co/t/high-cpu-usage-on-elastic-defend-and-kibana-processes/386663)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 0\
**Last updated:** [June 2, 2026, 11:35pm UTC](https://discuss.elastic.co/t/high-cpu-usage-on-elastic-defend-and-kibana-processes/386663 "2026-06-02T23:35:40Z")

</div>

Hello, I have two problems related to CPU usage being very high with two ES related processes. I'm currently using 3 ES nodes on the same machine using Docker. 1 Master hot/content, 1 warm, and 1 cold. The machine has …

---

## [How to configure Elastic Agent to stream different data to different instances of ElasticSearch?](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691)

<div class="topic-metadata">

**Author:** [@starstone](https://discuss.elastic.co/u/starstone)\
**Replies:** 2\
**Last updated:** [October 14, 2024, 8:45am UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691 "2024-10-14T08:45:41Z")

</div>

Hi How do you configure Elastic Agent to stream security logs to a dedicated instance of Elasticsearch and other data to a different instance of ElsticSearch? I want two segregated instances of Elasticsearch: one dedic…

---

## [Multiple Elastic Agents on the same system](https://discuss.elastic.co/t/multiple-elastic-agents-on-the-same-system/306215)

<div class="topic-metadata">

**Author:** [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 8:38am UTC](https://discuss.elastic.co/t/multiple-elastic-agents-on-the-same-system/306215 "2024-04-04T08:38:01Z")

</div>

Is there any method by which two Elastic Agents with different Fleet&Output configurations can run simultaneously on the same server? (except for Docker Containers scenario). It looks like the installation paths cannot …

---

## [What is the best way to get AD authentication logs in ELK](https://discuss.elastic.co/t/what-is-the-best-way-to-get-ad-authentication-logs-in-elk/346482)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 3:01am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-get-ad-authentication-logs-in-elk/346482 "2023-11-06T03:01:25Z")

</div>

What is the best way to ingest AD authentication logs in ELK, through elastic agent or through audit beats .. we don’t want to impact AD server performance

---

## [Having issues parsing time in CEF](https://discuss.elastic.co/t/having-issues-parsing-time-in-cef/291072)

<div class="topic-metadata">

**Author:** [@harwinds](https://discuss.elastic.co/u/harwinds)\
**Replies:** 15\
**Last updated:** [October 24, 2023, 8:54pm UTC](https://discuss.elastic.co/t/having-issues-parsing-time-in-cef/291072 "2023-10-24T20:54:58Z")

</div>

Hi all, I'm ingesting ExtraHop Reveal X https://www.extrahop.com/products/security/ logs using Fleet Managed Elastic Agent Integration "CEF" using the SYSLOG input over UDP. Most of the fields are being extracted corre…

---

## [Add\_field processor on empty env provider fields stop ingest](https://discuss.elastic.co/t/add-field-processor-on-empty-env-provider-fields-stop-ingest/343371)

<div class="topic-metadata">

**Author:** [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 1:36pm UTC](https://discuss.elastic.co/t/add-field-processor-on-empty-env-provider-fields-stop-ingest/343371 "2023-09-19T13:36:06Z")

</div>

Hi, Our nodes have some attributes to define what asset they belong to (environment, application, component). With migrating to agent these fields got lost and we have utilized the environment provider and the add\_field…

---

## [SentinelOne integration GeoIP database error](https://discuss.elastic.co/t/sentinelone-integration-geoip-database-error/333262)

<div class="topic-metadata">

**Author:** [@Anton\_H](https://discuss.elastic.co/u/Anton_H)\
**Replies:** 2\
**Last updated:** [May 13, 2023, 2:34pm UTC](https://discuss.elastic.co/t/sentinelone-integration-geoip-database-error/333262 "2023-05-13T14:34:44Z")

</div>

Hello, We use the SentinelOne integration through fleet in our Elastic Cloud environment. Events are being received and processed. The issue is we get "\_geoip\_database\_unavailable\_GeoLite2-City.mmdb" errors on all age…

---

## [How to work Agent policy witn APM Integration](https://discuss.elastic.co/t/how-to-work-agent-policy-witn-apm-integration/321997)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 16\
**Last updated:** [February 6, 2023, 4:05pm UTC](https://discuss.elastic.co/t/how-to-work-agent-policy-witn-apm-integration/321997 "2023-02-06T16:05:15Z")

</div>

Hello friends, I'm a bit confused, I have 2 agent policies and 2 APM integrations, the first agent policy is by default and this one has 2 integrations "Elastic APM" and "Fleet-server" and another policy that I created w…

---

## [Add Elastic APM integration manually](https://discuss.elastic.co/t/add-elastic-apm-integration-manually/321816)

<div class="topic-metadata">

**Author:** [@Hassan\_Malabeh](https://discuss.elastic.co/u/Hassan_Malabeh)\
**Replies:** 0\
**Last updated:** [December 22, 2022, 8:16am UTC](https://discuss.elastic.co/t/add-elastic-apm-integration-manually/321816 "2022-12-22T08:16:04Z")

</div>

I've created a docker-compose file with some configurations that deploy Elasticsearch, Kibana, Elastic Agent all version 8.7.0. where in the Kibana configuration files I define the police I needed under xpack.fleet.agen…

---

## [Data Stream not found in Data Views](https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222)

<div class="topic-metadata">

**Author:** [@sakib3833](https://discuss.elastic.co/u/sakib3833)\
**Replies:** 1\
**Last updated:** [October 27, 2022, 2:22pm UTC](https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222 "2022-10-27T14:22:55Z")

</div>

I use Microsoft Defender Endpoint integration to collect logs. The agent installed perfectly and the other ID and secret key put accordingly. In the Index management section it shows that it creates Data Stream. But…

---

## [Elastic Agent defunct on fleet server and clients](https://discuss.elastic.co/t/elastic-agent-defunct-on-fleet-server-and-clients/305803)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 20\
**Last updated:** [October 21, 2022, 10:09am UTC](https://discuss.elastic.co/t/elastic-agent-defunct-on-fleet-server-and-clients/305803 "2022-10-21T10:09:35Z")

</div>

Hello there, I have installed elastic-agent on a ubuntu-server box and when I list which process is running I get this: And then I realized that I got the same on the fleet server: This doesn´t look normal. Elas…

---

## [Could not communicate with fleet-server Checking API](https://discuss.elastic.co/t/could-not-communicate-with-fleet-server-checking-api/312352)

<div class="topic-metadata">

**Author:** [@nash-sprd](https://discuss.elastic.co/u/nash-sprd)\
**Replies:** 1\
**Last updated:** [September 1, 2022, 7:37pm UTC](https://discuss.elastic.co/t/could-not-communicate-with-fleet-server-checking-api/312352 "2022-09-01T19:37:11Z")

</div>

Hello there! Unfortunately, this is a very reoccurring error in Elastic Cloud, I found people have been having this error many times. I have an Elastic Cloud account. I onboard agents, and everything goes well, I can s…

---

## [Using a single Life Cycle Policy for many Index Templates](https://discuss.elastic.co/t/using-a-single-life-cycle-policy-for-many-index-templates/311236)

<div class="topic-metadata">

**Author:** [@dturner](https://discuss.elastic.co/u/dturner)\
**Replies:** 4\
**Last updated:** [August 31, 2022, 8:03pm UTC](https://discuss.elastic.co/t/using-a-single-life-cycle-policy-for-many-index-templates/311236 "2022-08-31T20:03:55Z")

</div>

Hello, We are using Elastic agent with different policies for different integrations. This has created many index templates for these different data sources. Each one of these index templates is using a different index …

---

## [Elasticsearch fleet error](https://discuss.elastic.co/t/elasticsearch-fleet-error/312117)

<div class="topic-metadata">

**Author:** [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Replies:** 4\
**Last updated:** [August 24, 2022, 11:23pm UTC](https://discuss.elastic.co/t/elasticsearch-fleet-error/312117 "2022-08-24T23:23:29Z")

</div>

Good evening, I use elastic 7.17.5 and fleet 7.17, on Sunday after 18:00 notifications to Microsoft 365 integration stopped coming, or rather they do, but a strictly fixed amount in a period of time, the error is as foll…

---

## [Elastic Agent Windows doesn't work](https://discuss.elastic.co/t/elastic-agent-windows-doesnt-work/312206)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 6:39pm UTC](https://discuss.elastic.co/t/elastic-agent-windows-doesnt-work/312206 "2022-08-16T18:39:04Z")

</div>

I'm trying to use the elastic Agent on windows 10 and i get this error: fail to execute request to fleet-server: dial tcp 192.168.100.60:8220: connectex: A connection attempt failed because the connected party did not p…

---

## [Elastic agent Unhealthy](https://discuss.elastic.co/t/elastic-agent-unhealthy/311426)

<div class="topic-metadata">

**Author:** [@MAPER](https://discuss.elastic.co/u/MAPER)\
**Replies:** 1\
**Last updated:** [August 12, 2022, 8:34pm UTC](https://discuss.elastic.co/t/elastic-agent-unhealthy/311426 "2022-08-12T20:34:48Z")

</div>

HI, I have my Elastic cluster , Kibana and Fleet up and running. Now I created New Agent-policy it has Endpoint and system integration. When I am Adding the agent client system the Agent installed successfully and Hea…

---

## [Adding Kibana, Fleet, Ingest node to cluster](https://discuss.elastic.co/t/adding-kibana-fleet-ingest-node-to-cluster/311958)

<div class="topic-metadata">

**Author:** [@BRosenberg](https://discuss.elastic.co/u/BRosenberg)\
**Replies:** 0\
**Last updated:** [August 11, 2022, 5:51pm UTC](https://discuss.elastic.co/t/adding-kibana-fleet-ingest-node-to-cluster/311958 "2022-08-11T17:51:39Z")

</div>

Hello. I'm attempting to add a 4th node to my cluster. Nodes: \[elastic-node-01\] \[elastic-79\] \[elastic-180\] Roles: master, data \[kibana-primary\] Roles: ingest, ml, remote\_cluster\_client, transform I'm trying to instal…

---

## [AWS CloudWatch integration with Elastic using Elastic Agent](https://discuss.elastic.co/t/aws-cloudwatch-integration-with-elastic-using-elastic-agent/308318)

<div class="topic-metadata">

**Author:** [@JypraGroup](https://discuss.elastic.co/u/JypraGroup)\
**Replies:** 27\
**Last updated:** [August 8, 2022, 2:52pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-integration-with-elastic-using-elastic-agent/308318 "2022-08-08T14:52:36Z")

</div>

Hi all, I have Elastic agent installed on the endpoint and I can see the logs coming in. The policy has AWS CloudWatch integration however I am not sure what else is required to get the logs and metrics flowing from the…

---

## [Fleet AWS Billing integration](https://discuss.elastic.co/t/fleet-aws-billing-integration/311138)

<div class="topic-metadata">

**Author:** [@aricau](https://discuss.elastic.co/u/aricau)\
**Replies:** 8\
**Last updated:** [August 8, 2022, 11:22am UTC](https://discuss.elastic.co/t/fleet-aws-billing-integration/311138 "2022-08-08T11:22:54Z")

</div>

Hello all, I'm trying to collect billing data with the AWS Billing integration using the elastic agent managed by Fleet. Running version 8.3.3 The agent appears to be running fine, with valid secret access key and perm…

---

## [Error: fail to enroll : connection timed out](https://discuss.elastic.co/t/error-fail-to-enroll-connection-timed-out/310036)

<div class="topic-metadata">

**Author:** [@koubach](https://discuss.elastic.co/u/koubach)\
**Replies:** 1\
**Last updated:** [August 3, 2022, 12:49pm UTC](https://discuss.elastic.co/t/error-fail-to-enroll-connection-timed-out/310036 "2022-08-03T12:49:57Z")

</div>

Hi, I'm using Elastic Cloud and I'm can't seem to be able to install the elastic agent, and I get the error : Error: fail to enroll: fail to execute request to fleet-server: dial tcp IP-adress:443: connect: connection …

---

## [Stop elasticsearch\_dsl from sending events to Elastic when server is down](https://discuss.elastic.co/t/stop-elasticsearch-dsl-from-sending-events-to-elastic-when-server-is-down/310977)

<div class="topic-metadata">

**Author:** [@Adso\_4](https://discuss.elastic.co/u/Adso_4)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 10:36am UTC](https://discuss.elastic.co/t/stop-elasticsearch-dsl-from-sending-events-to-elastic-when-server-is-down/310977 "2022-07-29T10:36:07Z")

</div>

We have a django web application that sends user data with elasticsearch\_dsl library to an APM server. Our Elastic Stack is mounted with docker-compose, with Kibana, Elasticsearch and APM nodes. For every user interacti…

---

## [Is standalone APM server required with Elastic APM Integration?](https://discuss.elastic.co/t/is-standalone-apm-server-required-with-elastic-apm-integration/310620)

<div class="topic-metadata">

**Author:** [@pokaleshrey](https://discuss.elastic.co/u/pokaleshrey)\
**Replies:** 16\
**Last updated:** [July 28, 2022, 9:36am UTC](https://discuss.elastic.co/t/is-standalone-apm-server-required-with-elastic-apm-integration/310620 "2022-07-28T09:36:53Z")

</div>

Hi, I have installed ES, Kibana. And its up and running. Further, i have added Elastic APM Integration into Kibana, and have setup Fleet server, Elastic Agent. (note i did not setup any APM server yet) I am trying to…

---

## [Deploy Elastic Agent 8.3.2 via Windows GPO](https://discuss.elastic.co/t/deploy-elastic-agent-8-3-2-via-windows-gpo/310689)

<div class="topic-metadata">

**Author:** [@bbs2web](https://discuss.elastic.co/u/bbs2web)\
**Replies:** 1\
**Last updated:** [July 26, 2022, 9:35pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-8-3-2-via-windows-gpo/310689 "2022-07-26T21:35:41Z")

</div>

Hi, The following is a working PowerShell script to deploy Elastic Agent to Windows workstations via Group Policy 'Startup Script'. Group Policy service by default does not include the permission for it to create SymLin…

---

## [Add query timeout in Elastic native query - springboot](https://discuss.elastic.co/t/add-query-timeout-in-elastic-native-query-springboot/310651)

<div class="topic-metadata">

**Author:** [@painless\_elastic](https://discuss.elastic.co/u/painless_elastic)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 2:11pm UTC](https://discuss.elastic.co/t/add-query-timeout-in-elastic-native-query-springboot/310651 "2022-07-26T14:11:45Z")

</div>

How can I add query timeout in the below Native Seach Query? final QueryBuilder contentTagQuery = QueryBuilders.boolQuery() .filter( QueryBuilders.termQuery("tenantId" , "en")); NativeSearchQuery query =…

---

## [Elastic-agent status Error: failed to communicate with Elastic Agent daemon](https://discuss.elastic.co/t/elastic-agent-status-error-failed-to-communicate-with-elastic-agent-daemon/308023)

<div class="topic-metadata">

**Author:** [@tidenhub](https://discuss.elastic.co/u/tidenhub)\
**Replies:** 2\
**Last updated:** [July 24, 2022, 9:52am UTC](https://discuss.elastic.co/t/elastic-agent-status-error-failed-to-communicate-with-elastic-agent-daemon/308023 "2022-07-24T09:52:35Z")

</div>

I have installed Elastic Agent 8.2.2 at my Windows 10 host. I can see the service running in the Management tools. But the command to get the status throws an error. PS is running in admin mode. PS C:\\Program Files\\El…

---

## [Elastic Agent Start Failure: Pipe Access Denied](https://discuss.elastic.co/t/elastic-agent-start-failure-pipe-access-denied/310421)

<div class="topic-metadata">

**Author:** [@Molly\_S\_17](https://discuss.elastic.co/u/Molly_S_17)\
**Replies:** 0\
**Last updated:** [July 22, 2022, 5:43pm UTC](https://discuss.elastic.co/t/elastic-agent-start-failure-pipe-access-denied/310421 "2022-07-22T17:43:47Z")

</div>

I'm attempting to start a standalone Elastic Agent on a Windows 10 machine (which has Winlogbeat working successfully on it) and have all of the proper files on my machine, along with an elastic-agent.yml file with the u…

---

## [SentinelOne Integration](https://discuss.elastic.co/t/sentinelone-integration/310378)

<div class="topic-metadata">

**Author:** [@Medel](https://discuss.elastic.co/u/Medel)\
**Replies:** 3\
**Last updated:** [July 22, 2022, 11:20am UTC](https://discuss.elastic.co/t/sentinelone-integration/310378 "2022-07-22T11:20:21Z")

</div>

Hello , I'm trying to integrate SentinelOne API to Elastic for the purpose of collecting logs but unfortunatly i can't find any tutorial or information on how to use the API token generated from the used and integrate i…

---

## [Parsing custom log timestamps, how?](https://discuss.elastic.co/t/parsing-custom-log-timestamps-how/310205)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 3\
**Last updated:** [July 21, 2022, 5:41pm UTC](https://discuss.elastic.co/t/parsing-custom-log-timestamps-how/310205 "2022-07-21T17:41:58Z")

</div>

I'm having issues figuring out how to get a timestamp out of a custom log. I've been trying to use the dissect and timestamp processors via the Custom configurations field in the fleet policy -\> custom log screen. Here…

---

## [JSON ingestion for logs picked up elastic fleet agent ECK operator](https://discuss.elastic.co/t/json-ingestion-for-logs-picked-up-elastic-fleet-agent-eck-operator/310160)

<div class="topic-metadata">

**Author:** [@Sagar\_Gulabani](https://discuss.elastic.co/u/Sagar_Gulabani)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 1:54pm UTC](https://discuss.elastic.co/t/json-ingestion-for-logs-picked-up-elastic-fleet-agent-eck-operator/310160 "2022-07-20T13:54:22Z")

</div>

Hi, We are using the elastic operator for Kubernetes. We are using the fleet managed elastic agent We are giving the fleet agent configuration using the kibana CRD as show below. Our logs from our applications are JSO…

---

## [Elastic Agent Kubernetes integration doesn't send container logs](https://discuss.elastic.co/t/elastic-agent-kubernetes-integration-doesnt-send-container-logs/309983)

<div class="topic-metadata">

**Author:** [@bucknerm](https://discuss.elastic.co/u/bucknerm)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 7:04am UTC](https://discuss.elastic.co/t/elastic-agent-kubernetes-integration-doesnt-send-container-logs/309983 "2022-07-19T07:04:24Z")

</div>

I'm running into an issue where I can't collect any of my custom Kubernetes container logs using the Kubernetes integration with the elastic agent. Elastic provided containers appear to ship logs correctly. I'm looking …

[Next page](https://discuss.elastic.co/tag/elastic-agent/63.md?match_all_tags=true&page=1&tags%5B%5D=elastic-agent)
