Elastic Status · History · Incident #7084

RESOLVED

Elastic Agent enrollment/check-in failures on 9.5.3 (and 9.4.6) with Fleet remote Elasticsearch output

Major · Started Sep 9, 2026 · 8:44 PM

  • Duration

    7d 13h 45m

  • Severity

    Major

  • Detection lead

  • User reports

Summary

Elastic Agent enrollment/check-in failures on 9.5.3 (and 9.4.6) with Fleet remote Elasticsearch output

We have confirmed that Elastic Agents are no longer experiencing enrollment failures related to this issue. Corrected Fleet Server releases (9.5.4 / 9.4.6) have been available on Elastic Cloud Hosted and Elastic Cloud Enterprise stack packs since September 10, 2026, and all known affected deployments have confirmed recovery. If you upgraded to an affected release before that time and have not yet applied the mitigation, guidance is available here: https://support.elastic.co/knowledge/bee1c75c.


  • Started

    Sep 9, 2026 · 8:44 PM

  • Resolved

    Sep 17, 2026 · 10:30 AM

  • Duration

    7d 13h 45m

  • Severity

    Major

Event timeline

How this incident unfolded

  • Identified

    Sep 9 · 8:44 PM Elastic

    We've identified a bug in Fleet Server 9.5.3 (also present in 9.4.6) that can cause Elastic Agents to crash-loop and go offline when Fleet pushes a configuration update, including enrollment, a policy change, or a routine revision bump. This only affects policies that use Fleet's remote Elasticsearch output feature. Recommendation: If you use Fleet's remote Elasticsearch output, do not upgrade to 9.5.3 or 9.4.6 until a fixed version is available. If you're already on an affected version and experiencing agent check-in failures, contact Support for remediation steps. A fix has been merged and will ship in the next 9.5.x and 9.4.x releases. Known Issue documentation: fleet-server#7791, elastic-agent#16542.

  • Identified

    Sep 11 · 2:25 PM Elastic

    We have patched Fleet Server versions 9.5.3 and 9.4.6 with corrected releases deployed as of September 10, 2026 at 21:20 UTC. - Upgrading to the current 9.4.6 or 9.5.3 releases will not be affected by this bug as the updated release contains the fix. - If you upgraded to 9.4.6 or 9.5.3 before 21:20 UTC on 10 September 2026, perform the following mitigation: 1. Force restart the Integration Server component of you affected deployment 2. Run cleanup procedures on affected Elastic Agents (see https://support.elastic.co/knowledge/bee1c75c) — required if agents failed to check in or remained offline after the Integration Server restart

  • Identified

    Sep 11 · 4:00 PM Elastic

    We have patched Fleet Server versions 9.5.3 and 9.4.6 with corrected releases deployed as of September 10, 2026 at 21:20 UTC. - Upgrading to the current 9.4.6 or 9.5.3 releases will not be affected by this bug as the updated release contains the fix. - If you upgraded to 9.4.6 or 9.5.3 before 21:20 UTC on 10 September 2026, perform the following mitigation: 1. Force restart the Integration Server component of you affected deployment 2. Run cleanup procedures on affected Elastic Agents (see https://support.elastic.co/knowledge/bee1c75c) — required if agents failed to check in or remained offline after the Integration Server restart IMPORTANT: The patched Fleet Server is not available outside Elastic Cloud Enterprise (ECE) Stack Packs and Elastic Cloud Hosted (ECH).

  • Resolved

    Sep 17 · 10:30 AM Elastic

    We have confirmed that Elastic Agents are no longer experiencing enrollment failures related to this issue. Corrected Fleet Server releases (9.5.4 / 9.4.6) have been available on Elastic Cloud Hosted and Elastic Cloud Enterprise stack packs since September 10, 2026, and all known affected deployments have confirmed recovery. If you upgraded to an affected release before that time and have not yet applied the mitigation, guidance is available here: https://support.elastic.co/knowledge/bee1c75c.

Get alerted before the next Elastic outage.

Pulsetic catches degradations minutes before vendors acknowledge them.