# Beginner: Trouble getting started

**URL:** <https://discuss.elastic.co/t/beginner-trouble-getting-started/282617>\
**Category:** Elasticsearch\
**Created:** [August 26, 2021, 10:45pm UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617 "2021-08-26T22:45:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmsbooth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jmsbooth/32/93793_2.png) [@jmsbooth](https://discuss.elastic.co/u/jmsbooth)\
**Post date:** [August 26, 2021, 10:45pm UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/1 "2021-08-26T22:45:06Z")

</div>

Deployed elasticsearch to an Ubuntu VM within Azure cloud. Edited the elasticsearch.yaml for the port, cluster.initial\_master\_nodes, and the network host:

```auto
[network.host](https://network.host/): "localhost"
http.port: 9200
cluster.initial_master_nodes: ["PRIVATE IP"]

```

Then edited the jvm.options to set the heap size:

```auto
-Xms128m
-Xmx128m

```

When starting to run the service it failed and below is the output of the journalctl -xe

```auto
root@kai-elk:/etc/elasticsearch# journalctl -xe

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: ... 10 more

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: Caused by: while scanning a simple key

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: in 'reader', line 57, column 1:

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: http.port:9200

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: ^

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: could not find expected ':'

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: in 'reader', line 58, column 1:

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: cluster.initial_master_nodes: [" ...

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: ^

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: at org.yaml.snakeyaml.scanner.ScannerImpl.stalePossibleSimpleKeys([ScannerImpl.java:464](https://scannerimpl.java:464/))

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: at org.yaml.snakeyaml.scanner.ScannerImpl.needMoreTokens([ScannerImpl.java:278](https://scannerimpl.java:278/))

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: at org.yaml.snakeyaml.scanner.ScannerImpl.checkToken([ScannerImpl.java:226](https://scannerimpl.java:226/))

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: at org.yaml.snakeyaml.parser.ParserImpl$ParseBlockMappingKey.produce([ParserImpl.java:558](https://parserimpl.java:558/))

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: at org.yaml.snakeyaml.parser.ParserImpl.peekEvent([ParserImpl.java:158](https://parserimpl.java:158/))

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: at org.yaml.snakeyaml.parser.ParserImpl.getEvent([ParserImpl.java:168](https://parserimpl.java:168/))

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: at com.fasterxml.jackson.dataformat.yaml.YAMLParser.nextToken([YAMLParser.java:355](https://yamlparser.java:355/))

Aug 26 22:17:02 kai-elk systemd-entrypoint[24922]: ... 15 more

Aug 26 22:17:02 kai-elk systemd-entrypoint[24978]: encountered [2] errors parsing [/etc/elasticsearch/jvm.options]

Aug 26 22:17:02 kai-elk systemd-entrypoint[24978]: [1]: encountered improperly formatted JVM option in [/etc/elasticsearch/jvm.options] on line number [31]: [-Xms128m]

Aug 26 22:17:02 kai-elk systemd-entrypoint[24978]: [2]: encountered improperly formatted JVM option in [/etc/elasticsearch/jvm.options] on line number [32]: [-Xmx128m]

Aug 26 22:17:02 kai-elk systemd[1]: elasticsearch.service: Main process exited, code=exited, status=1/FAILURE

-- Subject: Unit process exited

-- Defined-By: systemd

-- Support: http://www.ubuntu.com/support

--

-- An ExecStart= process belonging to unit elasticsearch.service has exited.

--

-- The process' exit code is 'exited' and its exit status is 1.

Aug 26 22:17:02 kai-elk sudo[24861]: pam_unix(sudo:session): session closed for user root

Aug 26 22:17:02 kai-elk systemd[1]: elasticsearch.service: Failed with result 'exit-code'.

-- Subject: Unit failed

-- Defined-By: systemd

-- Support: http://www.ubuntu.com/support

--

-- The unit elasticsearch.service has entered the 'failed' state with result 'exit-code'.

Aug 26 22:17:02 kai-elk systemd[1]: Failed to start Elasticsearch.

-- Subject: A start job for unit elasticsearch.service has failed

-- Defined-By: systemd

-- Support: http://www.ubuntu.com/support

--

-- A start job for unit elasticsearch.service has finished with a failure.

--

-- The job identifier is 2340 and the job result is failed.

Aug 26 22:18:51 kai-elk sudo[25014]: root : TTY=pts/0 ; PWD=/etc/elasticsearch ; USER=root ; COMMAND=/usr/sbin/service elasticsearch start

Aug 26 22:18:51 kai-elk sudo[25014]: pam_unix(sudo:session): session opened for user root by azureuser(uid=0)

Aug 26 22:18:52 kai-elk systemd[1]: Starting Elasticsearch...

-- Subject: A start job for unit elasticsearch.service has begun execution

-- Defined-By: systemd

-- Support: http://www.ubuntu.com/support

--

-- A start job for unit elasticsearch.service has begun execution.

--

-- The job identifier is 2437.

Aug 26 22:18:54 kai-elk systemd-entrypoint[25128]: encountered [2] errors parsing [/etc/elasticsearch/jvm.options]

Aug 26 22:18:54 kai-elk systemd-entrypoint[25128]: [1]: encountered improperly formatted JVM option in [/etc/elasticsearch/jvm.options] on line number [31]: [-Xms128m]

Aug 26 22:18:54 kai-elk systemd-entrypoint[25128]: [2]: encountered improperly formatted JVM option in [/etc/elasticsearch/jvm.options] on line number [32]: [-Xmx128m]

Aug 26 22:18:54 kai-elk systemd[1]: elasticsearch.service: Main process exited, code=exited, status=1/FAILURE

-- Subject: Unit process exited

-- Defined-By: systemd

-- Support: http://www.ubuntu.com/support

--

-- An ExecStart= process belonging to unit elasticsearch.service has exited.

--

-- The process' exit code is 'exited' and its exit status is 1.

Aug 26 22:18:54 kai-elk sudo[25014]: pam_unix(sudo:session): session closed for user root

Aug 26 22:18:54 kai-elk systemd[1]: elasticsearch.service: Failed with result 'exit-code'.

-- Subject: Unit failed

-- Defined-By: systemd

-- Support: http://www.ubuntu.com/support

--

-- The unit elasticsearch.service has entered the 'failed' state with result 'exit-code'.

Aug 26 22:18:54 kai-elk systemd[1]: Failed to start Elasticsearch.

-- Subject: A start job for unit elasticsearch.service has failed

-- Defined-By: systemd

-- Support: http://www.ubuntu.com/support

--

-- A start job for unit elasticsearch.service has finished with a failure.

--

-- The job identifier is 2437 and the job result is failed.

Aug 26 22:20:21 kai-elk sshd[25163]: error: kex_exchange_identification: Connection closed by remote host

Aug 26 22:21:26 kai-elk sshd[25177]: error: kex_exchange_identification: Connection closed by remote host

Aug 26 22:22:16 kai-elk sshd[25196]: error: kex_exchange_identification: Connection closed by remote host

Aug 26 22:22:27 kai-elk sshd[25200]: Unable to negotiate with [141.98.10.250](https://141.98.10.250/) port 36086: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1 [preauth]

Aug 26 22:28:13 kai-elk python3[709]: 2021-08-26T22:28:13.546163Z INFO ExtHandler ExtHandler [HEARTBEAT] Agent WALinuxAgent-2.4.0.2 is running as the goal state agent [DEBUG HeartbeatCounter: 3;HeartbeatId: B6BE69CB-3F8F-40DC-BE79-B8E72971364D;DroppedPackets: 0;UpdateGSErrors: 0;AutoUpdate: 1]

lines 1221-1304/1304 (END)

```

Can someone help me determine what I did wrong?

---

<div class="post-metadata">

**Author:** ![gsmitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gsmitt/32/93795_2.png) [@gsmitt](https://discuss.elastic.co/u/gsmitt)\
**Post date:** [August 27, 2021, 12:36am UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/2 "2021-08-27T00:36:29Z")

</div>

Hello,

> [@jmsbooth](#):
>
> `on line number [31]: [-Xms128m]`

Can you show us your `/etc/elasticsearch/jvm.options` file?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 27, 2021, 12:48am UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/3 "2021-08-27T00:48:43Z")

</div>

@jmsbooth Welcome to the community

Also your `elasticsearch.yml`

The errors indicate a syntax error.

Please format your code with the `</>` buttons

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 27, 2021, 4:44am UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/4 "2021-08-27T04:44:01Z")

</div>

I do not think I have ever seen Elasticsearch run with such a small heap so I would recommend increasing it to at least 512MB.

---

<div class="post-metadata">

**Author:** ![jmsbooth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jmsbooth/32/93793_2.png) [@jmsbooth](https://discuss.elastic.co/u/jmsbooth)\
**Post date:** [August 27, 2021, 12:22pm UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/5 "2021-08-27T12:22:51Z")

</div>

jvm.options

```auto
################################################################

## GC configuration
8-13:-XX:+UseConcMarkSweepGC
8-13:-XX:CMSInitiatingOccupancyFraction=75
8-13:-XX:+UseCMSInitiatingOccupancyOnly

## G1GC Configuration
# NOTE: G1 GC is only supported on JDK version 10 or later
# to use G1GC, uncomment the next two lines and update the version on the
# following three lines to your version of the JDK
# 10-13:-XX:-UseConcMarkSweepGC
# 10-13:-XX:-UseCMSInitiatingOccupancyOnly
14-:-XX:+UseG1GC

## JVM temporary directory
-Djava.io.tmpdir=${ES_TMPDIR}

## heap dumps

# generate a heap dump when an allocation from the Java heap fails; heap dumps
# are created in the working directory of the JVM unless an alternative path is
# specified
-XX:+HeapDumpOnOutOfMemoryError

# specify an alternative path for heap dumps; ensure the directory exists and
# has sufficient space
-XX:HeapDumpPath=/var/lib/elasticsearch

# specify an alternative path for JVM fatal error logs
-XX:ErrorFile=/var/log/elasticsearch/hs_err_pid%p.log

## JDK 8 GC logging
8:-XX:+PrintGCDetails
8:-XX:+PrintGCDateStamps
8:-XX:+PrintTenuringDistribution
8:-XX:+PrintGCApplicationStoppedTime
8:-Xloggc:/var/log/elasticsearch/gc.log
8:-XX:+UseGCLogFileRotation
8:-XX:NumberOfGCLogFiles=32
8:-XX:GCLogFileSize=64m

# JDK 9+ GC logging
9-:-Xlog:gc*,gc+age=trace,safepoint:file=/var/log/elasticsearch/gc.log:utctime,pid,tags:filecount=32,filesize=64m
9-:-Xlog:gc*,gc+age=trace,safepoint:file=/var/log/elasticsearch/gc.log:utctime,pid,tags:filecount=32,filesize=64m

```

elasticsearch.yml

```auto
#
# ----------------------------------- Memory -----------------------------------
#
# Lock the memory on startup:
#
#bootstrap.memory_lock: true
#
# Make sure that the heap size is set to about half the memory available
# on the system and that the owner of the process is allowed to use this
# limit.
#
# Elasticsearch performs poorly when the system is swapping the memory.
#
# ---------------------------------- Network -----------------------------------
#
# By default Elasticsearch is only accessible on localhost. Set a different
# address here to expose this node on the network:
#
network.host: "localhost"
http.port: 9200
cluster.initial_master_nodes: ["PRIVATEIP"]
#
# By default Elasticsearch listens for HTTP traffic on the first free port it
# finds starting at 9200. Set a specific HTTP port here:
#
#http.port: 9200
#
# For more information, consult the network module documentation.
#
# --------------------------------- Discovery ----------------------------------
#
# Pass an initial list of hosts to perform discovery when this node is started:
# The default list of hosts is ["127.0.0.1", "[::1]"]
#
#discovery.seed_hosts: ["host1", "host2"]
#
# Bootstrap the cluster using an initial set of master-eligible nodes:
#
#cluster.initial_master_nodes: ["node-1", "node-2"]
#
# For more information, consult the discovery and cluster formation module documentation.
#
# ---------------------------------- Various -----------------------------------
#
# Require explicit names when deleting indices:
#
#action.destructive_requires_name: true

```

---

<div class="post-metadata">

**Author:** ![jmsbooth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jmsbooth/32/93793_2.png) [@jmsbooth](https://discuss.elastic.co/u/jmsbooth)\
**Post date:** [August 27, 2021, 12:27pm UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/6 "2021-08-27T12:27:46Z")

</div>

I figured and plan to expand it. Its a lab for me so tried going small to begin with.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 27, 2021, 12:34pm UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/7 "2021-08-27T12:34:15Z")

</div>

That is too small IMHO. Elasticsearch does not scale down that far.

---

<div class="post-metadata">

**Author:** ![gsmitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gsmitt/32/93795_2.png) [@gsmitt](https://discuss.elastic.co/u/gsmitt)\
**Post date:** [August 27, 2021, 11:33pm UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/8 "2021-08-27T23:33:21Z")

</div>

Hello,

Part of your jvm.options file is missing.

```auto
 line number [31]: & line number [32]:

```

> [@jmsbooth](#):
>
> `encountered improperly formatted JVM option in [/etc/elasticsearch/jvm.options] on line number [31]: [-Xms128m]`

I have to agree with @Christian_Dahlqvist that is very small for heap.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2021, 11:33pm UTC](https://discuss.elastic.co/t/beginner-trouble-getting-started/282617/9 "2021-09-24T23:33:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
