Skip to content

Connectivity issues

Use this guide when a deployment is ready but Elasticsearch, Kibana, Fleet, or Logstash cannot be reached.

Start with Troubleshooting overview.

Run tests from an affected client and, when possible, compare the result with a known-good client.

1. Identify the affected endpoint

Determine which service is failing:

  • Elasticsearch;
  • Kibana;
  • Fleet;
  • Logstash.

Use only the hostname provided for your deployment.

Do not construct service names from Azure resource names or internal naming conventions.

2. Check the network path

For public access, confirm the client can reach the service over HTTPS.

nc -vz <service-hostname> 443

For private access, confirm:

  • the Private Endpoint exists;
  • connection status is Approved;
  • it has a private IP address;
  • the client network can route to the Private Endpoint subnet;
  • customer firewall or network controls permit the required connection.

If several services fail at the same time, investigate the shared network path before troubleshooting individual applications.

3. Check DNS

Resolve the exact service hostname.

nslookup <service-hostname>

For private access, the result should be the Private Endpoint private IP.

If DNS returns:

  • NXDOMAIN — check the DNS record, zone, or forwarding configuration;
  • a public address for a private deployment — check private DNS resolution;
  • an old private address — check stale records and DNS caching.

For hybrid environments, also confirm corporate DNS forwarding to Azure is working.

4. Check TLS

Validate the certificate with the exact service hostname.

SERVICE_HOSTNAME="<service-hostname>"

openssl s_client \
  -connect "${SERVICE_HOSTNAME}:443" \
  -servername "${SERVICE_HOSTNAME}" \
  -verify_return_error </dev/null

A successful result should include:

Verify return code: 0 (ok)

The platform-generated CSR covers the required deployment service hostnames, including:

  • Kibana;
  • Elasticsearch;
  • Fleet;
  • Logstash.

Check that the certificate:

  • is within its validity period;
  • contains the expected hostname in its SANs;
  • includes the required intermediate certificates;
  • chains to a CA trusted by the client.

Do not disable certificate verification to work around TLS errors.

Common connectivity results

Result Investigate
Name or service not known or NXDOMAIN DNS configuration
Connection timeout Routing, firewall, Private Endpoint, or service availability
Connection refused Endpoint or service availability
unable to get local issuer certificate Certificate chain or client trust
Hostname mismatch DNS hostname or certificate SAN
Expired certificate Certificate renewal
TLS works but HTTP returns 401 Authentication
TLS works but HTTP returns 403 Authorization or role permissions

5. Check authentication

Only troubleshoot authentication after network, DNS, and TLS checks succeed.

For Elasticsearch, verify the configured user or API key.

For Kibana, test using a private browser session when stale cookies or SSO sessions might be involved.

For Fleet or Elastic Agent connectivity, also confirm:

  • the correct Fleet endpoint is configured;
  • the agent is enrolled;
  • the correct policy is assigned;
  • the agent can establish TLS trust.

6. Fleet and Elastic Agent connectivity

If an Elastic Agent is unhealthy or offline:

  1. Check Fleet → Agents.
  2. Confirm the agent's last check-in time.
  3. Confirm the assigned policy.
  4. Check DNS resolution to the Fleet endpoint.
  5. Check network connectivity.
  6. Check TLS trust.
  7. Review Elastic Agent logs.

If the agent is Healthy but telemetry is missing, continue troubleshooting the integration or OpenTelemetry pipeline rather than the Fleet connection.

7. Logstash connectivity

If Logstash is enabled for the deployment, confirm:

  • the correct Logstash hostname is being used;
  • DNS resolves correctly;
  • the required network path is open;
  • TLS validates against the deployment certificate;
  • the configured protocol and port match the supported deployment configuration.

Do not assume Logstash uses the same application protocol or port as Elasticsearch.

Use the endpoint information provided for the deployment.

If the issue remains

For assistance:

  • AI chat: https://copilot.ivedha.cloud
  • Support portal: https://support.ivedha.com/

Provide:

  • deployment reference;
  • affected service hostname;
  • whether access is public or private;
  • DNS result;
  • TCP connectivity result;
  • TLS verification result;
  • relevant HTTP status or redacted error.

Do not include passwords, API keys, enrollment tokens, or private keys.

Next step

If connectivity works but Elasticsearch, Kibana, indexing, or search behavior is incorrect, continue with Elasticsearch issues.