Troubleshooting overview
Start with the user-visible symptom and identify the first layer that is not working as expected.
Do not modify managed infrastructure, disable TLS verification, or grant broader permissions simply to work around an error.
First checks
Work through these checks in order.
- Identify what is affected
Determine whether the issue affects:
- the Azure deployment;
- network connectivity;
- DNS;
- TLS;
- authentication;
- Elasticsearch;
- Kibana;
- Fleet or Elastic Agent;
- OpenTelemetry ingestion;
-
a specific application or user.
-
Check deployment readiness
If this is a new deployment, confirm that you received the Your deployment is ready notification.
Azure Marketplace provisioning can complete before the managed platform is ready for use.
- Check the network path
For private access, confirm:
- the Private Endpoint exists;
- the connection is approved;
- client networks can route to it.
For public access, confirm that required clients can reach the public endpoint over HTTPS.
- Check DNS
Resolve the exact service hostname from an affected client.
nslookup <service-hostname>
For private access, it should resolve to the Private Endpoint private IP.
- Check TLS
Validate the certificate using the service hostname.
Confirm:
- the certificate is valid;
- the hostname is included in the SANs;
- the certificate chain is trusted;
-
the certificate has not expired.
-
Check authentication
After networking, DNS, and TLS work, verify the account, API key, or SSO identity being used.
Do not reset credentials until you have confirmed the failure is actually authentication-related.
- Check Elasticsearch and Kibana
Determine whether:
- Elasticsearch is reachable;
- Kibana loads;
- the expected data is available;
-
the failing query or indexing operation can be reproduced.
-
Check Fleet and Elastic Agent
For observability issues, open Fleet → Agents.
Confirm:
- the agent is enrolled;
- the correct policy is assigned;
- the agent recently checked in;
-
status is Healthy.
-
Check OpenTelemetry ingestion
If the agent is healthy but logs, metrics, or traces are missing, check:
- the OpenTelemetry integration;
- OTLP endpoint configuration;
- application exporter configuration;
- expected OTel-native data streams;
- required resource and service attributes.
Choose the issue guide
| Symptom | Continue with |
|---|---|
| Marketplace validation, ARM deployment failure, or deployment does not become ready | Deployment issues |
| Private Endpoint, routing, DNS, TLS, browser, or connection failure | Connectivity issues |
| Elasticsearch health, indexing, search, Kibana, or data issue | Elasticsearch issues |
| Elastic Agent or telemetry collection issue | Start with Fleet and the affected integration |
| iVedha action or investigation is required | Contact support |
Collect useful evidence
Before contacting support, collect:
- deployment reference;
- approximate start time of the issue;
- affected service or workload;
- whether the issue affects all users or only some users;
- relevant HTTP status codes;
- correlation or request IDs when available;
- redacted error messages;
- Elastic Agent status when relevant.
Do not include:
- passwords;
- API keys;
- enrollment tokens;
- private keys;
- authentication headers;
- browser cookies;
- unredacted secrets.
Contact iVedha
For assistance:
- AI chat:
https://copilot.ivedha.cloud - Support portal:
https://support.ivedha.com/
Use the AI chat for guided troubleshooting and supported platform actions. Use the support portal when a support case or engineering investigation is required.
Next step
Choose the issue guide that matches the failing layer. If the problem remains unresolved or requires managed-platform investigation, continue to contact support.