# After "service elasticsearch start" it crashes

**URL:** <https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795>\
**Category:** Elasticsearch\
**Created:** [February 12, 2017, 9:48am UTC](https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795 "2017-02-12T09:48:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [February 12, 2017, 9:48am UTC](https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795/1 "2017-02-12T09:48:04Z")

</div>

Hi everyone,

I am new to ElasticSearch, I tried to create a new VM with version 5.2 of ES. I did so with an rpm file.

After all the process i try to start ES by "service elasticsearch start" and it works fine!  
After checking status for a few second i get a result as following:  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/26990faa1c2fcbb7c57dba29b698e2eb72033500.png)

I have JRE 1.8.0\_112 and did not change any config. except the name of the host and port number.

Will be happy for any help 😄

Many thanks,

Tomer Zaks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 12, 2017, 9:52am UTC](https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795/2 "2017-02-12T09:52:41Z")

</div>

Please don't post pictures of text, they are difficult to read and some people may not be even able to see them 🙂

Have you looked at the logs for Elasticsearch?

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [February 12, 2017, 10:06am UTC](https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795/3 "2017-02-12T10:06:36Z")

</div>

Thanks for the notice will try not to post them, 👍  
Now I found the logs and found this (didnt know how to open logs until now):

"[2017-02-12T10:24:34,155][WARN][o.e.b.BootstrapChecks] [mNBvEp6] max number of threads [1024] for user [elasticsearch] is too low, increase to at least [2048]  
[2017-02-12T10:24:34,156][WARN][o.e.b.BootstrapChecks] [mNBvEp6] system call filters failed to install; check the logs and fix your configuration or disable system call filters at your own risk"

After a check on the net I got this option:

"When using the RPM or Debian packages on systems that use systemd, system limits must be specified via systemd.

The systemd service file (/usr/lib/systemd/system/elasticsearch.service) contains the limits that are applied by default.

To override these, add a file called /etc/systemd/system/elasticsearch.service.d/elasticsearch.conf and specify any changes in that file, such as:

[Service]  
LimitMEMLOCK=infinity"

But the VM does not allow me to save the new file

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 12, 2017, 11:28pm UTC](https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795/5 "2017-02-12T23:28:41Z")

</div>

> [@tomer](#):
>
> But the VM does not allow me to save the new file

What does this mean exactly?

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [February 16, 2017, 9:18am UTC](https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795/7 "2017-02-16T09:18:05Z")

</div>

Actually I did a dumb mistake... I dont have systemd at all since I am working on CentOs 6...  
On CentOs 6 i saw that I have to set bootstrap.memory\_lock: to false, but also this crashes ElasticSearch and gives me:

system call filters failed to install; check the logs and fix your configuration or disable system call filters at your own risk

any help will be great

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [February 16, 2017, 9:44am UTC](https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795/8 "2017-02-16T09:44:26Z")

</div>

Well the solution to this problem was to enter a line:

"bootstrap.system\_call\_filter: false" to elasticsearch.yml.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2017, 9:44am UTC](https://discuss.elastic.co/t/after-service-elasticsearch-start-it-crashes/74795/9 "2017-03-16T09:44:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
