Install standalone Elastic Agents (advanced users)
editInstall standalone Elastic Agents (advanced users)
editRunning Elastic Agent in standalone mode is an advanced use case. The documentation is incomplete and not yet mature. When possible, we recommend using Fleet-managed agents instead of standalone mode.
To run an Elastic Agent in standalone mode, install the agent and manually configure the agent locally on the system where it’s installed. You are responsible for managing and upgrading the agents. This approach is recommended for advanced users only.
We recommend using Fleet-managed Elastic Agents, when possible, because it makes the management and upgrade of your agents considerably easier.
Standalone agents are unable to upgrade to new integration package versions automatically. When you upgrade the integration in Kibana, you’ll need to update the standalone policy manually.
You can install only a single Elastic Agent per host.
Elastic Agent can monitor the host where it’s deployed, and it can collect and forward data from remote services and hardware where direct deployment is not possible.
To install and run Elastic Agent standalone:
-
On your host, download and extract the installation package.
curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.8.2-darwin-x86_64.tar.gz tar xzvf elastic-agent-8.8.2-darwin-x86_64.tar.gz
curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.8.2-linux-x86_64.tar.gz tar xzvf elastic-agent-8.8.2-linux-x86_64.tar.gz
# PowerShell 5.0+ wget https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.8.2-windows-x86_64.zip -OutFile elastic-agent-8.8.2-windows-x86_64.zip Expand-Archive .\elastic-agent-8.8.2-windows-x86_64.zip
Or manually:
- Download the Elastic Agent Windows zip file from the download page.
- Extract the contents of the zip file.
To simplify upgrading to future versions of Elastic Agent, we recommended that you use the tarball distribution instead of the DEB distribution.
curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.8.2-amd64.deb sudo dpkg -i elastic-agent-8.8.2-amd64.deb
To simplify upgrading to future versions of Elastic Agent, we recommended that you use the tarball distribution instead of the RPM distribution.
curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.8.2-x86_64.rpm sudo rpm -vi elastic-agent-8.8.2-x86_64.rpm
Refer to the download page for other installation options.
-
Modify settings in the
elastic-agent.yml
as required.To get started quickly and avoid errors, use Kibana to create and download a standalone configuration file rather than trying to build it by hand. For more information, refer to Create a standalone Elastic Agent policy.
For additional configuration options, refer to Configure standalone Elastic Agents.
-
In the
elastic-agent.yml
policy file, underoutputs
, specify an API key or user credentials for the Elastic Agent to access Elasticsearch. For example:[...] outputs: default: type: elasticsearch hosts: - 'https://da4e3a6298c14a6683e6064ebfve9ace.us-central1.gcp.cloud.es.io:443' api_key: _Nj4oH0aWZVGqM7MGop8:349p_U1ERHyIc4Nm8_AYkw [...]
For more information required privileges and creating API keys, see Grant standalone Elastic Agents access to Elasticsearch.
- Make sure the assets you need, such as dashboards and ingest pipelines, are set up in Kibana and Elasticsearch. If you used Kibana to generate the standalone configuration, the assets are set up automatically. Otherwise, you need to install them. For more information, refer to View integration assets and Install integration assets.
-
From the agent directory, run the following commands to install Elastic Agent and start it as a service.
On macOS, Linux (tar package), and Windows, run the
install
command to install Elastic Agent as a managed service and start the service. The DEB and RPM packages include a service unit for Linux systems with systemd, so just enable then start the service.You must run this command as the root user because some integrations require root privileges to collect sensitive data.
sudo ./elastic-agent install
You must run this command as the root user because some integrations require root privileges to collect sensitive data.
sudo ./elastic-agent install
Open a PowerShell prompt as an Administrator (right-click the PowerShell icon and select Run As Administrator).
From the PowerShell prompt, change to the directory where you installed Elastic Agent, and run:
.\elastic-agent.exe install
You must run this command as the root user because some integrations require root privileges to collect sensitive data.
You must run this command as the root user because some integrations require root privileges to collect sensitive data.
Refer to Installation layout for the location of installed Elastic Agent files.
Because Elastic Agent is installed as an auto-starting service, it will restart automatically if the system is rebooted.
If you run into problems, refer to Troubleshoot common problems.