Major impactResolvedSearch

Elasticsearch outage: Elastic Agent enrollment/check-in failures on 9.5.3 (and 9.4.6) with Fleet remote Elasticsearch output

Elasticsearch reported this major-impact incident on its official status page on Sep 9, 2026, 20:44 UTC. It was resolved after 7d 13h.

Right now Elasticsearch is operational. Live Elasticsearch status →

🔔 Get alerted when Elasticsearch has issuesFree · email alerts · no credit card
Sep 9, 2026, 20:44 UTC
started
Sep 17, 2026, 10:30 UTC
resolved
7d 13h
duration
Major
impact
  1. resolvedSep 17, 2026, 10:30 UTC

    We have confirmed that Elastic Agents are no longer experiencing enrollment failures related to this issue. Corrected Fleet Server releases (9.5.4 / 9.4.6) have been available on Elastic Cloud Hosted and Elastic Cloud Enterprise stack packs since September 10, 2026, and all known affected deployments have confirmed recovery. If you upgraded to an affected release before that time and have not yet applied the mitigation, guidance is available here: https://support.elastic.co/knowledge/bee1c75c.

  2. identifiedSep 11, 2026, 16:00 UTC

    We have patched Fleet Server versions 9.5.3 and 9.4.6 with corrected releases deployed as of September 10, 2026 at 21:20 UTC. - Upgrading to the current 9.4.6 or 9.5.3 releases will not be affected by this bug as the updated release contains the fix. - If you upgraded to 9.4.6 or 9.5.3 before 21:20 UTC on 10 September 2026, perform the following mitigation: 1. Force restart the Integration Server component of you affected deployment 2. Run cleanup procedures on affected Elastic Agents (see https://support.elastic.co/knowledge/bee1c75c) — required if agents failed to check in or remained offline after the Integration Server restart IMPORTANT: The patched Fleet Server is not available outside Elastic Cloud Enterprise (ECE) Stack Packs and Elastic Cloud Hosted (ECH).

  3. identifiedSep 11, 2026, 14:25 UTC

    We have patched Fleet Server versions 9.5.3 and 9.4.6 with corrected releases deployed as of September 10, 2026 at 21:20 UTC. - Upgrading to the current 9.4.6 or 9.5.3 releases will not be affected by this bug as the updated release contains the fix. - If you upgraded to 9.4.6 or 9.5.3 before 21:20 UTC on 10 September 2026, perform the following mitigation: 1. Force restart the Integration Server component of you affected deployment 2. Run cleanup procedures on affected Elastic Agents (see https://support.elastic.co/knowledge/bee1c75c) — required if agents failed to check in or remained offline after the Integration Server restart

  4. identifiedSep 9, 2026, 20:44 UTC

    We've identified a bug in Fleet Server 9.5.3 (also present in 9.4.6) that can cause Elastic Agents to crash-loop and go offline when Fleet pushes a configuration update, including enrollment, a policy change, or a routine revision bump. This only affects policies that use Fleet's remote Elasticsearch output feature. Recommendation: If you use Fleet's remote Elasticsearch output, do not upgrade to 9.5.3 or 9.4.6 until a fixed version is available. If you're already on an affected version and experiencing agent check-in failures, contact Support for remediation steps. A fix has been merged and will ship in the next 9.5.x and 9.4.x releases. Known Issue documentation: fleet-server#7791, elastic-agent#16542.

What APIStatus.watch saw

Our 5-minute checks didn't record a change in Elasticsearch's overall status around this incident. Smaller or regional incidents often leave a provider's overall status green.

Other services with incidents at the same time

Overlapping incidents aren't necessarily related.

How often does Elasticsearch have incidents?

Elasticsearch reported 23 incidents in the last 90 days, 20 of them major or critical. A typical incident lasted 3h 35m. See Elasticsearch's uptime and incident history

Elasticsearch outage on Sep 9, 2026: Elastic Agent enrollment/check-in failures on 9.5.3 (and 9.4.6) with Fleet remote Elasticsearch output · APIStatus.watch