-
Notifications
You must be signed in to change notification settings - Fork 143
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Question]: Standalone agent support with Endpoint Integration. #2525
Comments
Secondary review for this ticket is Done. FYI @cmacknz |
Was this a Fleet managed agent that was converted to standalone? Was the agent policy here generated with Fleet? Is endpoint healthy or just sending data? Can you attach agent diagnostics from the standalone agent that is running endpoint security? I think if you created a policy in Fleet with Elastic Defend installed and then copied it to a standalone agent, then agent would start the endpoint security process. I don't expect that endpoint security would work properly in this case without a connection back to Fleet though. |
Hi @cmacknz Thanks for looking into this issue. We have directly installed the standalone agent without converting Fleet based agent. We have followed Steps to reproduce
Agent Diagnostics reports 8.7.1 Logs: elastic-agent-diagnostics-8.7.1.zip 8.2.3 elastic-agent-diagnostics-8.2.3.zip We also revalidated this issue on 8.2.3 release build and we found that the issue is not occurring on the 8.2.3 release build.
Screenshot Please let us know if anything else is required from our end. Thanks! |
I believe that running an Elastic Agent in standalone mode should not even allow endpoint to run. I think we need to add something to the runtime protections for endpoint so it cannot run on a standalone Elastic Agent. Let me know if they use case has changed and I am unaware. |
Correct, we shouldn't allow it to run. The use case is the same, endpoint should only run when the agent is Fleet managed. Possibly we lost this in 8.6 when the elastic-agent/internal/spec/endpoint.yml Line 71 in 0e1a739
|
@harshitgupta-qasource @amolnater-qasource is this issue still happening? If not, I think we can close it. |
Hi Team, We have re-validated this issue on the latest 8.14.0 BC5 Kibana cloud environment and found it fixed now. Observations:
Build details: Hence, we are closing this issue and marking as QA: Validated. Thanks. |
Query Description
Install the standalone agent of Windows and Linux OS with endpoint integration in the policy.
As per the last information, the standalone agents don't support endpoint integration.
However, we are getting data for endpoint integration for an installed standalone agent.
Could you please confirm if there are any changes in standalone agents?
Screenshot
Windows Standalone Agent Datastream.
Linux Standalone Agent Datastream.
Build Details
Agent Policy:
Policy.zip
The text was updated successfully, but these errors were encountered: