Elastic Endpoint failing to communicate with Elastic Agent on host - "BulkQueueConsumer.cpp:186 No valid comms client available" #12681
Replies: 2 comments 5 replies
-
Do you have other endpoint agents installed? |
Beta Was this translation helpful? Give feedback.
1 reply
-
What OS are in the env? And especially between the failed & working ones? |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.50
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
cloud
Hardware Specs
Exceeds minimum requirements
CPU
32
RAM
16
Storage for /
500
Storage for /nsm
500
Network Traffic Collection
tap
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
Ask
I'm unable to get Elastic Agent working on a couple of hosts (~20/100) in my environment.
Firewall and Security Group rules are consistent across all hosts. The Elastic Endpoint (used by Elastic Defend Integration) is unable to communicate with the Elastic Agent on the same host. This seems to be the root cause of the issue.
Context
Logs from those with failing Elastic Agents shows the following:
I noticed that the
elastic-endpoint.yaml
configuration is unable to pull the correct configuration:Running
./elastic-endpoint diagnostics
reveals that there is an communications issue between Agent and Endpoint:Not sure where to go from here. I've tried re-installing the Agent/Endpoint, re-enrolling the Agents but nothing seems to work.
Would appreciate any help I can get. Thanks!
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions