Skip to content

Elastic Defend fails to reconnect with RPM agent, when RPM host is offline for a few hours and no new data for System integration. #8840

@amolnater-qasource

Description

@amolnater-qasource

Kibana Build details:

VERSION: 9.1.0 BC2
BUILD: 87800
COMMIT: bf32d85033f9db9a8b57c1b68b26f3f19f48f1a5
Artifact Link: https://staging.elastic.co/9.1.0-e7409ce7/downloads/beats/elastic-agent/elastic-agent-9.1.0-x86_64.rpm

Host OS: SLES-15

Preconditions:

  1. 9.1.0 BC2 Kibana cloud environment should be available.
  2. RPM agent is enrolled with System & Elastic Defend integration.

Steps to reproduce:

  1. Ensure the RPM agent is connected to Elastic Defend and data is flowing under System & Elastic Defend integration.
  2. Take the RPM host offline for several hours (e.g., 7-8+ hours).
  3. Bring the RPM host back online.
  4. Observe the Agent gets into orphaned state as Elastic Defend is not able to connect agent.
  5. Observe new data for Elastic Defend, however no new data for System integration.

Expected Result:
When the RPM host comes back online, Elastic Defend should automatically reconnect to the RPM agent, and System integration should resume data collection without issues.

Notes:

  • The issue is reproducible consistently after prolonged offline periods.
  • Issue is also reproducible for 9.0.3 rpm agent.

Screen Recordings:
Before host is offline:

ip-172-31-20-250.-.Agents.-.Fleet.-.Elastic.-.Google.Chrome.2025-07-03.19-04-39.mp4

After host is offline:

Agents.-.Fleet.-.Elastic.-.Google.Chrome.2025-07-04.10-47-41.mp4

Logs:
We are not able to collect logs with diagnostics command and hence we have manually collected the logs.

logs.zip

Image

Agent JSON:

ip-172-31-20-250-agent-details.zip

elastic-agent.yml:

elastic-agent (1).zip

Metadata

Metadata

Assignees

No one assigned

    Labels

    QA:ValidatedValidated by the QA TeamTeam:Elastic-Agent-Control-PlaneLabel for the Agent Control Plane teambugSomething isn't workingimpact:highShort-term priority; add to current release, or definitely next.

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions