• Fleet and Elastic Agent Guide: other versions:
  • Fleet and Elastic Agent overview
    • Restrictions for Elastic Cloud Serverless
  • Beats and Elastic Agent capabilities
  • Quick starts
  • Migrate from Beats to Elastic Agent
    • Migrate from Auditbeat to Elastic Agent
  • Deployment models
    • What is Fleet Server?
    • Deploy on Elastic Cloud
    • Deploy on-premises and self-managed
    • Deploy Fleet Server on-premises and Elasticsearch on Cloud
    • Deploy Fleet Server on Kubernetes
    • Fleet Server scalability
    • Fleet Server Secrets
      • Secret files guide
    • Monitor a self-managed Fleet Server
  • Install Elastic Agents
    • Install Fleet-managed Elastic Agents
    • Install standalone Elastic Agents
      • Upgrade standalone Elastic Agents
    • Install Elastic Agents in a containerized environment
      • Run Elastic Agent in a container
      • Run Elastic Agent on Kubernetes managed by Fleet
      • Install Elastic Agent on Kubernetes using Helm
      • Example: Install standalone Elastic Agent on Kubernetes using Helm
      • Example: Install Fleet-managed Elastic Agent on Kubernetes using Helm
      • Advanced Elastic Agent configuration managed by Fleet
      • Configuring Kubernetes metadata enrichment on Elastic Agent
      • Run Elastic Agent on GKE managed by Fleet
      • Run Elastic Agent on Amazon EKS managed by Fleet
      • Run Elastic Agent on Azure AKS managed by Fleet
      • Run Elastic Agent Standalone on Kubernetes
      • Scaling Elastic Agent on Kubernetes
      • Using a custom ingest pipeline with the Kubernetes Integration
      • Environment variables
    • Run Elastic Agent as an OTel Collector
      • Transform an installed Elastic Agent to run as an OTel Collector
    • Run Elastic Agent without administrative privileges
    • Install Elastic Agent from an MSI package
    • Installation layout
    • Air-gapped environments
    • Using a proxy server with Elastic Agent and Fleet
      • When to configure proxy settings
      • Proxy Server connectivity using default host variables
      • Fleet managed Elastic Agent connectivity using a proxy server
      • Standalone Elastic Agent connectivity using a proxy server
      • Set the proxy URL of the Elastic Package Registry
    • Uninstall Elastic Agents from edge hosts
    • Start and stop Elastic Agents on edge hosts
    • Elastic Agent configuration encryption
  • FIPS mode for Ingest tools
  • Secure connections
    • Configure SSL/TLS for self-managed Fleet Servers
    • Rotate SSL/TLS CA certificates
    • Elastic Agent deployment models with mutual TLS
    • One-way and mutual TLS certifications flow
    • Configure SSL/TLS for the Logstash output
  • Manage Elastic Agents in Fleet
    • Fleet settings
      • Elasticsearch output settings
      • Logstash output settings
      • Kafka output settings
      • Remote Elasticsearch output
      • Considerations when changing outputs
    • Elastic Agents
      • Unenroll Elastic Agents
      • Set inactivity timeout
      • Upgrade Elastic Agents
      • Migrate Elastic Agents
      • Monitor Elastic Agents
      • Elastic Agent health status
      • Add tags to filter the Agents list
      • Enrollment handing for containerized agents
    • Policies
      • Create an agent policy without using the UI
      • Enable custom settings in an agent policy
      • Set environment variables in an Elastic Agent policy
    • Required roles and privileges
    • Fleet enrollment tokens
    • Kibana Fleet APIs
  • Configure standalone Elastic Agents
    • Create a standalone Elastic Agent policy
    • Structure of a config file
    • Inputs
      • Simplified log ingestion
      • Elastic Agent inputs
      • Variables and conditions in input configurations
    • Providers
      • Local
      • Agent provider
      • Host provider
      • Env Provider
      • Kubernetes Secrets Provider
      • Kubernetes LeaderElection Provider
      • Local dynamic provider
      • Docker Provider
      • Kubernetes Provider
    • Outputs
      • Elasticsearch
      • Kafka
      • Logstash
    • SSL/TLS
    • Logging
    • Feature flags
    • Agent download
    • Config file examples
      • Apache HTTP Server
      • Nginx HTTP Server
    • Grant standalone Elastic Agents access to Elasticsearch
    • Example: Use standalone Elastic Agent with Elastic Cloud Serverless to monitor nginx
    • Example: Use standalone Elastic Agent with Elasticsearch Service to monitor nginx
    • Debug standalone Elastic Agents
    • Kubernetes autodiscovery with Elastic Agent
      • Conditions based autodiscover
      • Hints annotations based autodiscover
    • Monitoring
    • Reference YAML
  • Manage integrations
    • Package signatures
    • Add an integration to an Elastic Agent policy
    • View integration policies
    • Edit or delete an integration policy
    • Install and uninstall integration assets
    • View integration assets
    • Set integration-level outputs
    • Upgrade an integration
    • Managed integrations content
    • Best practices for integration assets
    • Data streams
      • Tutorials: Customize data retention policies
      • Scenario 1: All data streams in all namespaces
      • Scenario 2: Selected data streams in all namespaces
      • Scenario 3: Selected integrations and namespaces
      • Tutorial: Transform data with custom ingest pipelines
      • Advanced data stream features
  • Define processors
    • Processor syntax
    • add_cloud_metadata
    • add_cloudfoundry_metadata
    • add_docker_metadata
    • add_fields
    • add_host_metadata
    • add_id
    • add_kubernetes_metadata
    • add_labels
    • add_locale
    • add_network_direction
    • add_nomad_metadata
    • add_observer_metadata
    • add_process_metadata
    • add_tags
    • community_id
    • convert
    • copy_fields
    • decode_base64_field
    • decode_cef
    • decode_csv_fields
    • decode_duration
    • decode_json_fields
    • decode_xml
    • decode_xml_wineventlog
    • decompress_gzip_field
    • detect_mime_type
    • dissect
    • dns
    • drop_event
    • drop_fields
    • extract_array
    • fingerprint
    • include_fields
    • move_fields
    • parse_aws_vpc_flow_log
    • rate_limit
    • registered_domain
    • rename
    • replace
    • script
    • syslog
    • timestamp
    • translate_sid
    • truncate_fields
    • urldecode
  • Command reference
  • Troubleshoot
    • Troubleshoot common problems
    • Frequently asked questions
  • Release notes
    • Fleet and Elastic Agent 8.19.12
    • Fleet and Elastic Agent 8.19.11
    • Fleet and Elastic Agent 8.19.10
    • Fleet and Elastic Agent 8.19.9
    • Fleet and Elastic Agent 8.19.8
    • Fleet and Elastic Agent 8.19.7
    • Fleet and Elastic Agent 8.19.6
    • Fleet and Elastic Agent 8.19.5
    • Fleet and Elastic Agent 8.19.4
    • Fleet and Elastic Agent 8.19.3
    • Fleet and Elastic Agent 8.19.2
    • Fleet and Elastic Agent 8.19.1
    • Fleet and Elastic Agent 8.19.0