Skip to content

No System logs are generated for Linux agent, when agent is installed with --unprivileged flag. #4112

@amolnater-qasource

Description

@amolnater-qasource

Kibana Build details:

VERSION: 8.13.0-SNAPSHOT
BUILD: 70749
COMMIT: a0f4897f7c04069faf2a86dbda1dabea78c161c1
Artifact Link: https://snapshots.elastic.co/8.13.0-l534sdis/downloads/beats/elastic-agent/elastic-agent-8.13.0-SNAPSHOT-linux-x86_64.tar.gz

Host OS: Linux- SLES15, Ubuntu 22

Preconditions:

  1. 8.13.0 Snapshot linux agent should be installed.
  2. Linux Agents should be installed using below command:
    sudo ./elastic-agent install --url=<url> --enrollment-token=<token> --unprivileged

Steps to reproduce:

  1. Navigate to Data Streams tab.
  2. Select Type: logs, System Integration, and required namespace filters.
  3. Observe no System integration logs for linux agent installed with --unprivileged flag.

What's working fine:

  • Issue is not reproducible on Linux- SLES15, Ubuntu 22 when agents are installed without --unprivileged flag.

Screen Recording:

Data.streams.-.Fleet.-.Elastic.-.Google.Chrome.2024-01-22.13-59-51.mp4

Logs:
elastic-agent-diagnostics-2024-01-22T08-42-48Z-00.zip
elastic-agent-diagnostics-2024-01-22T08-42-55Z-00.zip

Expected Result:
System logs should be generated for Linux agent, when agent is installed with --unprivileged flag.

Feature:
https://github.com/elastic/ingest-dev/issues/1766

Metadata

Metadata

Assignees

No one assigned

    Labels

    QA:Ready For TestingCode is merged and ready for QA to validateTeam:Elastic-Agent-Control-PlaneLabel for the Agent Control Plane teambugSomething isn't workingimpact:highShort-term priority; add to current release, or definitely next.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions