elastic / elastic/elastic-agent

Ability for Elastic agent to restart osquerybeat without restarting the entire agent

Open
#80 1 comment 1 reaction 0 assignees View on GitHub
enhancement Osquerybeat Team:Asset Mgt Team:Elastic-Agent-Control-Plane
Dominant language
Go
Stars
275
Forks
264
Avg merge
1d 20h
Merged PRs (30d)
303

Description

**Describe the enhancement:**
Include an option for elastic agent to restart osquerybeat without impacting the other integration workflow.

**Describe a specific use case for the enhancement or feature:**
- Users running elastic agents with multiple integrations/policies. If and when we need to restart agent (perhaps to troubleshoot other issues with other integrations,etc) that may disrupt other log collection flow.
- If we can't restart osquerybeat via UI, perhaps we should provide a option to do it via CLI?
(See [slack discussion](https://elastic.slack.com/archives/C01CL30B20K/p1644900476917889) with dev and PM for further context)

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or existing entry point; start by locating the osquerybeat lifecycle and any agent UI or CLI controls. Define whether restart is exposed through the UI or CLI, then verify that only osquerybeat restarts while other integrations continue collecting.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
devops
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.