Skip to content

Troubleshooting overview

Start with the user-visible symptom and identify the first layer that is not working as expected.

Do not modify managed infrastructure, disable TLS verification, or grant broader permissions simply to work around an error.

First checks

Work through these checks in order.

  1. Identify what is affected

Determine whether the issue affects:

  • the Azure deployment;
  • network connectivity;
  • DNS;
  • TLS;
  • authentication;
  • Elasticsearch;
  • Kibana;
  • Fleet or Elastic Agent;
  • OpenTelemetry ingestion;
  • a specific application or user.

  • Check deployment readiness

If this is a new deployment, confirm that you received the Your deployment is ready notification.

Azure Marketplace provisioning can complete before the managed platform is ready for use.

  1. Check the network path

For private access, confirm:

  • the Private Endpoint exists;
  • the connection is approved;
  • client networks can route to it.

For public access, confirm that required clients can reach the public endpoint over HTTPS.

  1. Check DNS

Resolve the exact service hostname from an affected client.

nslookup <service-hostname>

For private access, it should resolve to the Private Endpoint private IP.

  1. Check TLS

Validate the certificate using the service hostname.

Confirm:

  • the certificate is valid;
  • the hostname is included in the SANs;
  • the certificate chain is trusted;
  • the certificate has not expired.

  • Check authentication

After networking, DNS, and TLS work, verify the account, API key, or SSO identity being used.

Do not reset credentials until you have confirmed the failure is actually authentication-related.

  1. Check Elasticsearch and Kibana

Determine whether:

  • Elasticsearch is reachable;
  • Kibana loads;
  • the expected data is available;
  • the failing query or indexing operation can be reproduced.

  • Check Fleet and Elastic Agent

For observability issues, open Fleet → Agents.

Confirm:

  • the agent is enrolled;
  • the correct policy is assigned;
  • the agent recently checked in;
  • status is Healthy.

  • Check OpenTelemetry ingestion

If the agent is healthy but logs, metrics, or traces are missing, check:

  • the OpenTelemetry integration;
  • OTLP endpoint configuration;
  • application exporter configuration;
  • expected OTel-native data streams;
  • required resource and service attributes.

Choose the issue guide

Symptom Continue with
Marketplace validation, ARM deployment failure, or deployment does not become ready Deployment issues
Private Endpoint, routing, DNS, TLS, browser, or connection failure Connectivity issues
Elasticsearch health, indexing, search, Kibana, or data issue Elasticsearch issues
Elastic Agent or telemetry collection issue Start with Fleet and the affected integration
iVedha action or investigation is required Contact support

Collect useful evidence

Before contacting support, collect:

  • deployment reference;
  • approximate start time of the issue;
  • affected service or workload;
  • whether the issue affects all users or only some users;
  • relevant HTTP status codes;
  • correlation or request IDs when available;
  • redacted error messages;
  • Elastic Agent status when relevant.

Do not include:

  • passwords;
  • API keys;
  • enrollment tokens;
  • private keys;
  • authentication headers;
  • browser cookies;
  • unredacted secrets.

Contact iVedha

For assistance:

  • AI chat: https://copilot.ivedha.cloud
  • Support portal: https://support.ivedha.com/

Use the AI chat for guided troubleshooting and supported platform actions. Use the support portal when a support case or engineering investigation is required.

Next step

Choose the issue guide that matches the failing layer. If the problem remains unresolved or requires managed-platform investigation, continue to contact support.