3.3 Fleet Server & Elastic Agent Integration Management

Key Takeaways

  • Elastic Agent replaces individual standalone Beats with a single unified binary that provides endpoint security, log ingestion, and metric telemetry.

  • Fleet Server provides a centralized, scalable control plane that manages agent configurations, policy revisions, and enrollment over secure outbound HTTPS connections.

  • Agent policies declaratively configure integrations, automatically routing ingested telemetry into granular data streams adhering to 'type-dataset-namespace' naming.

  • The Elastic Defend integration adds malware, ransomware, memory threat and malicious behavior protections plus endpoint telemetry, configured through presets from Data Collection to Complete EDR.

  • Fleet continuously monitors agent statuses (Healthy, Unhealthy, Updating, Offline, Inactive, Unenrolled) and supports remote diagnostic collection and rolling binary upgrades.

Last updated: September 2026

Centralized Fleet Architecture vs. Standalone Beats

In legacy Elastic Stack deployments, monitoring an enterprise estate required deploying, configuring, and updating multiple standalone Beats on every server: Filebeat for logs, Metricbeat for host performance, Packetbeat for network flows, Auditbeat for Linux audit trails, and standalone Endpoint Security agents. Each Beat required its own local YAML configuration file, separate binary updates, and independent service management. Across thousands of enterprise endpoints, configuration drift and update management became major operational bottlenecks.

The Elastic Agent unifies all telemetry collection capabilities into a single binary. Rather than manually managing local configuration files on endpoints, Elastic Agents are centrally governed through Fleet in Kibana and coordinated by Fleet Server.

Fleet Architecture and Communication Model

The Fleet architecture consists of four interconnected components:

  1. Kibana Fleet UI: The centralized administrative console where SOC teams configure agent policies, add integration packages, monitor agent health, and trigger remote diagnostics.
  2. Fleet Server: A scalable backend control plane (deployed as an Elastic Agent process with the Fleet Server integration enabled) that brokers communication between thousands of managed Elastic Agents and Elasticsearch.
  3. Elasticsearch: The central datastore that houses agent policies, enrollment tokens, integration packages, and the ingested telemetry data streams.
  4. Elastic Agent: The endpoint binary installed on servers, workstations, and cloud instances. It establishes an outbound HTTPS connection to Fleet Server (default port 8220), retrieves policy revisions, executes configured integrations, and ships normalized telemetry directly to Elasticsearch (default port 9200).

Because Elastic Agents initiate outbound connections to Fleet Server, managed endpoints located in protected enclaves, branch offices, or cloud VPCs do not require inbound firewall openings.


Enrollment Tokens and Agent Policies

To onboard an Elastic Agent into Fleet, the endpoint must be registered using an Enrollment Token associated with an Agent Policy.

Declarative Agent Policies

An Agent Policy is a centralized configuration document that dictates an agent's runtime behavior:

  • Enabled Integrations: Specific modules configured for the host (e.g., Windows Event Logs, Linux System, Elastic Defend, AWS, Zeek).
  • Collection Settings: Polling intervals, target log file paths, and parsing pipelines.
  • Output Destination: The target Elasticsearch cluster and credentials used for data shipping.

Policies use automated revision versioning. When an administrator modifies an integration in the Fleet UI, Fleet increments the policy revision number. Connected Elastic Agents receive the update via long-polling, validate the new specification, and apply it atomically without restarting the host or dropping active telemetry streams.

Enrollment Tokens

Enrollment tokens authenticate agents during initial onboarding:

  • Each token is permanently bound to a designated Agent Policy.
  • Tokens can be scoped by environment (e.g., Production-Linux-Token, DMZ-Firewall-Token).
  • If an enrollment token is compromised or a deployment campaign completes, administrators can revoke the token in the Fleet UI without affecting already-enrolled agents.

To install and enroll an Elastic Agent via the command line:

sudo ./elastic-agent install \
  --url=https://fleet-server.corp.internal:8220 \
  --enrollment-token=QUJjMTIzWHl6... \
  --certificate-authorities=/etc/pki/ca.crt

Integrations and Data Stream Architecture

Integrations are modular software packages downloaded from the Elastic Package Registry (EPR) that provide input configuration, ingest pipelines, index mappings and, often, Kibana dashboards.

The Elastic Defend Integration

For security analysts, the Elastic Defend (formerly Endpoint Security) integration is the primary endpoint protection mechanism. Adding Elastic Defend to an Agent Policy enables:

  • Malware Protection: Scans executables when they are written or run and uses an on-host machine-learning model, plus signatures and your blocklist, to detect or block malware.
  • Ransomware Protection: Detects and halts unauthorized mass encryption of user documents, canary files, and filesystem structures.
  • Behavioral Protection: Detects suspicious process ancestry, API hooking, memory injection (process hollowing, thread injection), and credential dumping against LSASS.
  • Configuration Presets: When you add Elastic Defend for Traditional Endpoints, you choose a preset that you can customize later:
    • Data Collection: all events, no preventions.
    • Next-Generation Antivirus (NGAV): process events plus all preventions.
    • Essential EDR: process, network and file events plus all preventions.
    • Complete EDR: all events plus all preventions. Every preset except Data Collection enables the malware, ransomware, memory threat, malicious behavior and credential theft preventions by default. The separate Cloud Workloads presets target cloud Linux hosts, collect process, network and file events with session data, and start with preventions disabled.

Data Stream Naming: type-dataset-namespace

Fleet-managed agents write all telemetry into Elasticsearch Data Streams. Data streams enforce a three-part naming hierarchy:

type−dataset−namespace\text{type}-\text{dataset}-\text{namespace}

  1. type: Broad category of telemetry. Standard values are logs, metrics, synthetics, and traces.
  2. dataset: The specific log or telemetry source defined by the integration (e.g., windows.sysmon_operational, system.auth, aws.cloudtrail, endpoint.events.process).
  3. namespace: An administrator-defined grouping reflecting an environment, tenant, or business unit (e.g., production, pci, development, default).

For example, Windows Sysmon telemetry collected from production servers routes to: logs-windows.sysmon_operational-production

This granular naming convention allows administrators to attach distinct Index Lifecycle Management (ILM) retention policies, ingest pipelines, and Role-Based Access Controls (RBAC) to specific datasets and namespaces independently.


Agent Lifecycle and Troubleshooting

Fleet provides real-time visibility into the operational state of every managed endpoint.

Elastic Agent Statuses and Remediation Matrix

Agent StatusOperational MeaningCommon Root CausesRemediation Procedure
HealthyAgent is running normally and checking in with Fleet.Normal operation.None required; monitor ingestion volume.
UnhealthyAgent is running but has errors or a degraded component or integration.Missing permissions, invalid log paths, resource exhaustion, component crash.Run elastic-agent status locally, check integration health in Fleet, collect diagnostics.
UpdatingAgent is updating its policy or binary, or enrolling or unenrolling.Policy change or Fleet-initiated upgrade.Wait for completion; investigate if it does not finish.
OfflineAgent has stopped checking in for a period; its API keys remain valid.Host powered off, network path to Fleet Server blocked, service stopped.Verify the route to Fleet Server and the local service (systemctl status elastic-agent or Windows Services).
InactiveAgent has been offline longer than the policy's inactivity timeout; it is hidden from the main Fleet view.Decommissioned or long-disconnected host.Unenroll it if it is no longer valid.
UnenrolledAgent was manually unenrolled and its API keys were removed.Intentional removal.Re-enroll with a new enrollment token if needed.

Endpoint CLI Diagnostics and Enterprise Proxy Support

When investigating an unhealthy or non-responsive agent directly on an endpoint:

  • Inspect Component Health:
    sudo elastic-agent status
    
    Displays the granular status of each managed component process (e.g., filebeat, metricbeat, endpoint-security).
  • Generate Diagnostic Bundle:
    sudo elastic-agent diagnostics
    
    Writes a diagnostics .zip archive containing configuration snapshots, component logs and runtime metrics. Administrators can also collect this remotely from Fleet with the agent's Request diagnostics .zip action, without host SSH access.
  • Enterprise Proxy Configuration: For endpoints operating in restricted enclaves without direct routing to Fleet Server, agents support HTTP/HTTPS forward proxies, set at install time or in Fleet proxy settings:
    sudo ./elastic-agent install --url=https://fleet-server.corp.internal:8220 \
      --enrollment-token=QUJjMTIzWHl6... --proxy-url=http://proxy.corp.internal:8080
    
Loading diagram...
Fleet Management & Telemetry Communication Flow
Test Your Knowledge

An Elastic Agent deployed on a critical application server reports an Unhealthy status in the Fleet management console, even though the host is powered on and actively communicating over HTTPS with Fleet Server. What does this status indicate?

A

The agent has lost network connectivity to Elasticsearch on port 9200.

B

The agent enrollment token has expired and must be re-issued.

C

The agent is actively applying a binary upgrade and will return to Online shortly.

D

The main agent process is checking in, but one or more underlying integrations or component sub-processes has crashed or encountered a runtime error.

Test Your Knowledge

A SOC team configures a data stream for AWS CloudTrail logs collected across all production cloud accounts using the standard Elastic Agent integration naming convention. What is the resulting data stream name?

A

cloudtrail.aws.logs.production

B

logs-aws.cloudtrail-production

C

aws-cloudtrail-logs-default

D

production-logs-aws-cloudtrail

Test Your Knowledge

When enrolling thousands of new endpoints across multiple remote branch offices into Fleet, which practice ensures secure enrollment without exposing administrative credentials?

A

Disable HTTPS certificate verification (--insecure) to avoid distributing the internal CA certificate.

B

Embed a Kibana Superuser API key directly in the elastic-agent.yml configuration file on each endpoint.

C

Generate dedicated, policy-scoped Enrollment Tokens with restricted permissions, and distribute only the token and Fleet Server URL to the installer scripts.

D

Configure endpoints to run in standalone unmanaged mode using hardcoded Elasticsearch root passwords.

Sections you finish are checked off in the contents.