Skip to content
Discussion options

You must be logged in to vote

Went ahead and created an issue #15101

To fix this you should be able to take the cert from your standalone and paste it back into the fleet output policy. From your manager run sudo cat /etc/pki/elasticfleet-logstash.key then copy that entire output should look something like

-----BEGIN PRIVATE KEY-----
....
....
-----END PRIVATE KEY-----

Go back into the logstash fleet output policy and paste that into the 'Client SSL certificate key' section. Save the policy and check your agents are coming back into healthy state.

If this happens again you can repeat the cert steps and disable updates to the fleet output policy from happening automatically

within SOC -> Administration -> config (hit …

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@Lastautumnleaf
Comment options

Answer selected by Lastautumnleaf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants