3.3 Fleet Server & Elastic Agent Integration Management
Key Takeaways
Elastic Agent replaces individual standalone Beats with a single unified binary that provides endpoint security, log ingestion, and metric telemetry.
Fleet Server provides a centralized, scalable control plane that manages agent configurations, policy revisions, and enrollment over secure outbound HTTPS connections.
Agent policies declaratively configure integrations, automatically routing ingested telemetry into granular data streams adhering to 'type-dataset-namespace' naming.
The Elastic Defend integration adds malware, ransomware, memory threat and malicious behavior protections plus endpoint telemetry, configured through presets from Data Collection to Complete EDR.
Fleet continuously monitors agent statuses (Healthy, Unhealthy, Updating, Offline, Inactive, Unenrolled) and supports remote diagnostic collection and rolling binary upgrades.
Centralized Fleet Architecture vs. Standalone Beats
In legacy Elastic Stack deployments, monitoring an enterprise estate required deploying, configuring, and updating multiple standalone Beats on every server: Filebeat for logs, Metricbeat for host performance, Packetbeat for network flows, Auditbeat for Linux audit trails, and standalone Endpoint Security agents. Each Beat required its own local YAML configuration file, separate binary updates, and independent service management. Across thousands of enterprise endpoints, configuration drift and update management became major operational bottlenecks.
The Elastic Agent unifies all telemetry collection capabilities into a single binary. Rather than manually managing local configuration files on endpoints, Elastic Agents are centrally governed through Fleet in Kibana and coordinated by Fleet Server.
Fleet Architecture and Communication Model
The Fleet architecture consists of four interconnected components:
- Kibana Fleet UI: The centralized administrative console where SOC teams configure agent policies, add integration packages, monitor agent health, and trigger remote diagnostics.
- Fleet Server: A scalable backend control plane (deployed as an Elastic Agent process with the Fleet Server integration enabled) that brokers communication between thousands of managed Elastic Agents and Elasticsearch.
- Elasticsearch: The central datastore that houses agent policies, enrollment tokens, integration packages, and the ingested telemetry data streams.
- Elastic Agent: The endpoint binary installed on servers, workstations, and cloud instances. It establishes an outbound HTTPS connection to Fleet Server (default port
8220), retrieves policy revisions, executes configured integrations, and ships normalized telemetry directly to Elasticsearch (default port9200).
Because Elastic Agents initiate outbound connections to Fleet Server, managed endpoints located in protected enclaves, branch offices, or cloud VPCs do not require inbound firewall openings.
Enrollment Tokens and Agent Policies
To onboard an Elastic Agent into Fleet, the endpoint must be registered using an Enrollment Token associated with an Agent Policy.
Declarative Agent Policies
An Agent Policy is a centralized configuration document that dictates an agent's runtime behavior:
- Enabled Integrations: Specific modules configured for the host (e.g., Windows Event Logs, Linux System, Elastic Defend, AWS, Zeek).
- Collection Settings: Polling intervals, target log file paths, and parsing pipelines.
- Output Destination: The target Elasticsearch cluster and credentials used for data shipping.
Policies use automated revision versioning. When an administrator modifies an integration in the Fleet UI, Fleet increments the policy revision number. Connected Elastic Agents receive the update via long-polling, validate the new specification, and apply it atomically without restarting the host or dropping active telemetry streams.
Enrollment Tokens
Enrollment tokens authenticate agents during initial onboarding:
- Each token is permanently bound to a designated Agent Policy.
- Tokens can be scoped by environment (e.g.,
Production-Linux-Token,DMZ-Firewall-Token). - If an enrollment token is compromised or a deployment campaign completes, administrators can revoke the token in the Fleet UI without affecting already-enrolled agents.
To install and enroll an Elastic Agent via the command line:
sudo ./elastic-agent install \
--url=https://fleet-server.corp.internal:8220 \
--enrollment-token=QUJjMTIzWHl6... \
--certificate-authorities=/etc/pki/ca.crt
Integrations and Data Stream Architecture
Integrations are modular software packages downloaded from the Elastic Package Registry (EPR) that provide input configuration, ingest pipelines, index mappings and, often, Kibana dashboards.
The Elastic Defend Integration
For security analysts, the Elastic Defend (formerly Endpoint Security) integration is the primary endpoint protection mechanism. Adding Elastic Defend to an Agent Policy enables:
- Malware Protection: Scans executables when they are written or run and uses an on-host machine-learning model, plus signatures and your blocklist, to detect or block malware.
- Ransomware Protection: Detects and halts unauthorized mass encryption of user documents, canary files, and filesystem structures.
- Behavioral Protection: Detects suspicious process ancestry, API hooking, memory injection (process hollowing, thread injection), and credential dumping against LSASS.
- Configuration Presets: When you add Elastic Defend for Traditional Endpoints, you choose a preset that you can customize later:
- Data Collection: all events, no preventions.
- Next-Generation Antivirus (NGAV): process events plus all preventions.
- Essential EDR: process, network and file events plus all preventions.
- Complete EDR: all events plus all preventions. Every preset except Data Collection enables the malware, ransomware, memory threat, malicious behavior and credential theft preventions by default. The separate Cloud Workloads presets target cloud Linux hosts, collect process, network and file events with session data, and start with preventions disabled.
Data Stream Naming: type-dataset-namespace
Fleet-managed agents write all telemetry into Elasticsearch Data Streams. Data streams enforce a three-part naming hierarchy:
type: Broad category of telemetry. Standard values arelogs,metrics,synthetics, andtraces.dataset: The specific log or telemetry source defined by the integration (e.g.,windows.sysmon_operational,system.auth,aws.cloudtrail,endpoint.events.process).namespace: An administrator-defined grouping reflecting an environment, tenant, or business unit (e.g.,production,pci,development,default).
For example, Windows Sysmon telemetry collected from production servers routes to:
logs-windows.sysmon_operational-production
This granular naming convention allows administrators to attach distinct Index Lifecycle Management (ILM) retention policies, ingest pipelines, and Role-Based Access Controls (RBAC) to specific datasets and namespaces independently.
Agent Lifecycle and Troubleshooting
Fleet provides real-time visibility into the operational state of every managed endpoint.
Elastic Agent Statuses and Remediation Matrix
| Agent Status | Operational Meaning | Common Root Causes | Remediation Procedure |
|---|---|---|---|
| Healthy | Agent is running normally and checking in with Fleet. | Normal operation. | None required; monitor ingestion volume. |
| Unhealthy | Agent is running but has errors or a degraded component or integration. | Missing permissions, invalid log paths, resource exhaustion, component crash. | Run elastic-agent status locally, check integration health in Fleet, collect diagnostics. |
| Updating | Agent is updating its policy or binary, or enrolling or unenrolling. | Policy change or Fleet-initiated upgrade. | Wait for completion; investigate if it does not finish. |
| Offline | Agent has stopped checking in for a period; its API keys remain valid. | Host powered off, network path to Fleet Server blocked, service stopped. | Verify the route to Fleet Server and the local service (systemctl status elastic-agent or Windows Services). |
| Inactive | Agent has been offline longer than the policy's inactivity timeout; it is hidden from the main Fleet view. | Decommissioned or long-disconnected host. | Unenroll it if it is no longer valid. |
| Unenrolled | Agent was manually unenrolled and its API keys were removed. | Intentional removal. | Re-enroll with a new enrollment token if needed. |
Endpoint CLI Diagnostics and Enterprise Proxy Support
When investigating an unhealthy or non-responsive agent directly on an endpoint:
- Inspect Component Health:
Displays the granular status of each managed component process (e.g.,sudo elastic-agent statusfilebeat,metricbeat,endpoint-security). - Generate Diagnostic Bundle:
Writes a diagnostics .zip archive containing configuration snapshots, component logs and runtime metrics. Administrators can also collect this remotely from Fleet with the agent's Request diagnostics .zip action, without host SSH access.sudo elastic-agent diagnostics - Enterprise Proxy Configuration: For endpoints operating in restricted enclaves without direct routing to Fleet Server, agents support HTTP/HTTPS forward proxies, set at install time or in Fleet proxy settings:
sudo ./elastic-agent install --url=https://fleet-server.corp.internal:8220 \ --enrollment-token=QUJjMTIzWHl6... --proxy-url=http://proxy.corp.internal:8080
An Elastic Agent deployed on a critical application server reports an Unhealthy status in the Fleet management console, even though the host is powered on and actively communicating over HTTPS with Fleet Server. What does this status indicate?
The agent has lost network connectivity to Elasticsearch on port 9200.
The agent enrollment token has expired and must be re-issued.
The agent is actively applying a binary upgrade and will return to Online shortly.
The main agent process is checking in, but one or more underlying integrations or component sub-processes has crashed or encountered a runtime error.
A SOC team configures a data stream for AWS CloudTrail logs collected across all production cloud accounts using the standard Elastic Agent integration naming convention. What is the resulting data stream name?
cloudtrail.aws.logs.production
logs-aws.cloudtrail-production
aws-cloudtrail-logs-default
production-logs-aws-cloudtrail
When enrolling thousands of new endpoints across multiple remote branch offices into Fleet, which practice ensures secure enrollment without exposing administrative credentials?
Disable HTTPS certificate verification (--insecure) to avoid distributing the internal CA certificate.
Embed a Kibana Superuser API key directly in the elastic-agent.yml configuration file on each endpoint.
Generate dedicated, policy-scoped Enrollment Tokens with restricted permissions, and distribute only the token and Fleet Server URL to the installer scripts.
Configure endpoints to run in standalone unmanaged mode using hardcoded Elasticsearch root passwords.
Sections you finish are checked off in the contents.