Skip to content

system.syslog and system.auth logs are not generated for Debian 13. #15084

@amolnater-qasource

Description

@amolnater-qasource

Kibana version:

VERSION: 9.2.0-SNAPSHOT
BUILD: 89749
COMMIT: 9007297d8280c30040034707054745efaa708958
Artifact Link: https://snapshots.elastic.co/9.2.0-f3caf25b/downloads/beats/elastic-agent/elastic-agent-9.2.0-SNAPSHOT-amd64.deb

HOST OS:
Debian 13.0

Preconditions:

  1. 9.2.0-SNAPSHOT Kibana cloud environment should be available.
  2. Agent policy should be available having System & Elastic Defend integration.

Steps to reproduce:

  1. Navigate to Agents tab.
  2. Install agent on Debian 13 using Add agent flyout.
  3. Navigate to Data Streams tab and observe system.syslog and system.auth logs are not generated.

Expected behavior:
system.syslog and system.auth logs should be generated for Debian 13.

Agent Logs:

elastic-agent-diagnostics-2025-08-27T08-25-28Z-00.zip

Agent JSON:

ip-172-31-16-93-agent-details.json.zip

Screen Capture:

Screen.Recording.2025-08-27.at.1.54.38.PM.mov

Related Feature:
https://github.com/elastic/ingest-dev/issues/5923

Metadata

Metadata

Assignees

No one assigned

    Labels

    QA:Needs ValidationNeeds validation by the QA TeamTeam:Elastic-Agent-Control-PlaneLabel for the Agent Control Plane teambugSomething isn't working, use only for issuesimpact:highShort-term priority; add to current release, or definitely next.

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions