No alerts from Elastic agent #11937
-
Hello,I just wanted to know if I'm the only one having this problem: When I go into the Elastic Fleet manager and click on an agent to click on "View more agent metrics" The links on the left in the "Agent Health" section such as "Overview", "Agent Information", "Agent Metrics" or "Integrations" lead to a page that contains no data. Thank you. |
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 3 replies
-
What do you mean by alerts? We recommend reviewing alerts inside of SOC Alerts. The Elastic Agent dashboards haven't been tested extensively. I don't think we collect metrics by default because of the potential immense volume and requirement for storage, so there may not be data to populate the Metrics dashboard. I have data on the Integrations page. |
Beta Was this translation helpful? Give feedback.
-
It's just that we don't have alerts in SOC, but we have data on the Integration page too. |
Beta Was this translation helpful? Give feedback.
-
From the picture it looks like you have data from Suricata, so you should have alert data provided that you are not using Suricata for metadata and have Zeek data. Do you see any data is you use the following query in SOC Hunt? event.module:suricata |
Beta Was this translation helpful? Give feedback.
-
Have you tried going to Playbook and activating plays for alerts that you would want to see? |
Beta Was this translation helpful? Give feedback.
Have you tried going to Playbook and activating plays for alerts that you would want to see?
https://docs.securityonion.net/en/2.4/playbook.html