# Bootstrap checks failed - no specifics

**URL:** <https://discuss.elastic.co/t/bootstrap-checks-failed-no-specifics/130295>\
**Category:** Elasticsearch\
**Created:** [May 2, 2018, 4:09pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-no-specifics/130295 "2018-05-02T16:09:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh\_McDonald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josh_mcdonald/32/30525_2.png) [@Josh\_McDonald](https://discuss.elastic.co/u/Josh_McDonald)\
**Post date:** [May 2, 2018, 4:09pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-no-specifics/130295/1 "2018-05-02T16:09:09Z")

</div>

Environment:

- ES 6.2.4 (installed via apt-get)
- Ubuntu 16.04

I'm trying to start ES bound to the proper IP in effort to follow the Getting Started Guide for Filebeats. I'm attempting to send syslog information from another server to this ES/Kiabana server. When I start the ES service, I get this error in the logs. I can't seem to find anything specific I need to change.

```
[2018-05-02T08:36:46,048][ERROR][o.e.b.Bootstrap] [wPTvoIB] node validation exception
[1] bootstrap checks failed
[1]: system call filters failed to install; check the logs and fix your configuration or disable system call filters at your own risk
```

---

<div class="post-metadata">

**Author:** ![shanec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanec/32/4004_2.png) [@shanec](https://discuss.elastic.co/u/shanec)\
**Post date:** [May 2, 2018, 9:01pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-no-specifics/130295/2 "2018-05-02T21:01:26Z")

</div>

> [@Josh\_McDonald](#):
>
> system call filters failed to install

You may want to look over [all](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/bootstrap-checks.html) of the bootstrap checks just to see what Elasticsearch requires at startup, but the specific one you're hitting here is the [system call filter check](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/_system_call_filter_check.html). This is Elasticsearch attempting to work under extra security ([seccomp](https://en.wikipedia.org/wiki/Seccomp)) and being unable to, possibly because you don't have seccomp compiled in your kernel. The docs for the system call filter bootstrap check state how to disable this (`bootstrap.system_call_filter: false`), but I'd recommend instead looking to make sure seccomp is enabled so you're not sidestepping recommended security features.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2018, 9:08pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-no-specifics/130295/3 "2018-05-30T21:08:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
