-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Logs Data for "elastic_agent" dataset not generated by Agent #26518
Comments
Pinging @elastic/agent (Team:Agent) |
@manishgupta-qasource Please review. |
Reviewed & Assigned to @EricDavisX |
@amolnater-qasource can you attach the policy the Agent was on? I don't want to make assumptions, please. It may be the expected result - but maybe not, the policy will help inform. Thank you. |
I think I have another scenario impacted by the cause of this issue: deploy an Agent and go to the Fleet 'logs' tab for the Agent and no logs are shown (because elastic_agent dataset is pre-selected, but no logs exist and it cannot then be unselected!). If you select other datasets and then also select a different time frame (to make the data pull in anew) then it will show some logs - very scary at first. The Fleet UI is acting up too, but that is follow up separately. |
The above may be the exact cause of this, too - it has additional logs if helpful. |
Hi @EricDavisX
Please find Default Fleet Server Policy attached below: Further, we have revalidated your observations and also found it reproducible on cloud environments. Build details:
Please let us know if anything else is required from our end. |
did something changed fleet/permissions side? when i change dataset from when i keep dataset to |
@afgomez Can you chime in here? My guess is that this is related to the permissions in Kibana. It might be that we miss something in the package itself? |
The permissions generated for the agent are as follows: output_permissions:
default:
_elastic_agent_checks:
cluster:
- monitor
indices:
- names:
- logs-elastic_agent.*-default
- metrics-elastic_agent.*-default
privileges:
- auto_configure
- create_doc My guess is that the |
yeah this seems incorrect, please let me know when you have a PR, this will also need to be be backported to 7.14 |
@amolnater-qasource please retest when elastic/kibana#104447 goes in |
Hi @michalpristas |
Hi @EricDavisX
Build details:
Hence we are closing this out. |
Kibana version: 7.14.0 Snapshot Kibana self-managed environment
Host OS and Browser version: All, All
Build details:
Preconditions:
Steps to reproduce:
Expected Result:
Logs data for "elastic_agent" dataset should be generated under Data Streams tab.
Logs:
logs.zip
Screenshot:
The text was updated successfully, but these errors were encountered: