Log Collector - Network Connection

Windows Network Connection Issues

On Windows, network problems frequently involve firewall rules, service refusals, or integration degradations that prevent agents from connecting to remote services like Fleet Server or Elasticsearch.

Common Problems

Symptoms

Fixes

Sources:
Not able to start standalone Elastic Agent in my windows machine - Elastic Stack / Elastic Agent - Discuss the Elastic Stack
Elastic-agent.exe not running on target - Elastic Security - Discuss the Elastic Stack
Elastic Agents Unhealthy Elasticsearch connection failure · Security-Onion-Solutions/securityonion · Discussion #13416 · GitHub
Elastic Agent causing VM connectivity issues - Elastic Stack / Elastic Agent - Discuss the Elastic Stack
Elastic Agent Not Sending Logs from Endpoint Outside the Network (AWS Cloud deployemnt on VM) : r/elasticsearch
Common problems with Fleet and Elastic Agent | Elastic Docs
Elastic Agent causing VM connectivity issues - Elastic Stack / Elastic Agent - Discuss the Elastic Stack
External NIC Blocked by Elastic Agent - Elastic Security / Endpoint Security - Discuss the Elastic Stack
Elastic Agent - Filebeat still tries to connect to localhost:9200 despite different host being configured : r/elasticsearch
Elastic Agent not sending Data - Elastic Security - Discuss the Elastic Stack
Common problems with Fleet and Elastic Agent | Elastic Docs
Unable to Connect Filebeat to Elasticsearch - Elastic Stack / Beats - Discuss the Elastic Stack

Linux Network Connection Issues

Linux issues often stem from system-level security (e.g., SELinux) or firewalls blocking outbound/inbound traffic, especially in containerized environments like Kubernetes.

Common Problems

Symptoms

Fixes

Sources
Elastic agent unhealthy because of elastic defend integration - Elastic Security - Discuss the Elastic Stack
Elastic-agent.exe not running on target - Elastic Security - Discuss the Elastic Stack
Elastic Endpoint cannot connect to agent - Elastic Security / Endpoint Security - Discuss the Elastic Stack
Network Disruption on Kubernetes Node with Elastic Security Integration on Debian - Elastic Stack / Elastic Agent - Discuss the Elastic Stack
Connection issues between Elastic Agent (Filebeat) and Logstash: connection reset by peer - Elastic Stack / Beats - Discuss the Elastic Stack
Elastic agent goes offline & healthy every 5 minutes - Elastic Stack / Elastic Agent - Discuss the Elastic Stack
Elastic-agent with system module does not send any data to elasticsearch - Elastic Stack / Kibana - Discuss the Elastic Stack
elasticsearch - elastic-agent is not collecting data - Stack Overflow
Elastic agent unhealthy because of elastic defend integration - Elastic Security - Discuss the Elastic Stack

macOS Network Connection Issues

macOS issues are less common but often involve network extensions or privacy controls that disrupt connections, especially with security integrations like Elastic Defend.

Common Problems

Symptoms

Fixes

Sources:
External NIC Blocked by Elastic Agent - Elastic Security / Endpoint Security - Discuss the Elastic Stack
Elastic Agent not sending Data - Elastic Security - Discuss the Elastic Stack
Elastic Endpoint in a degraded state - Elastic Security - Discuss the Elastic Stack
Elastic Agent known issues | Elastic Agent
External NIC Blocked by Elastic Agent - Elastic Security / Endpoint Security - Discuss the Elastic Stack
Elastic Endpoint in a degraded state - Elastic Security - Discuss the Elastic Stack
Guide for Using the Elastic Agent


Revision #6
Created 27 November 2025 09:08:56 by Richmond Abella
Updated 4 December 2025 02:08:17