# Bootstrap.system\_call\_filter to false not able to configure cluster

**URL:** <https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062>\
**Category:** Elasticsearch\
**Created:** [August 31, 2017, 10:09pm UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062 "2017-08-31T22:09:48Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunmesiav](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@sunmesiav](https://discuss.elastic.co/u/sunmesiav)\
**Post date:** [August 31, 2017, 10:09pm UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/1 "2017-08-31T22:09:48Z")

</div>

Hi,

Iam using the Elasticsearch 5.5.2, and Iam not able to configure cluster. I dont see my nodes talking to each other. I tried using the following configuration in my elasticsearch.yml.

I tried changing the transport.host: to my server ip, but doing so the bootstrap check fails,  
unable to install syscall filter: java.lang.UnsupportedOperationException: seccomp unavailable: CONFIG\_SECCOMP not compiled into kernel, CONFIG\_SECCOMP and C ONFIG\_SECCOMP\_FILTER are needed at org.elasticsearch.bootstrap.SystemCallFilter.linuxImpl(SystemCallFilter.java:363) ~[elasticsearch-5.5.2.jar:5.5. 2]

Iam using Red Hat Enterprise Linux Server release 6.8 (Santiago) OS.

if I set bootstrap.system\_call\_filter: false and having the transport.host: localhost, the node is getting started but not able to talk to other nodes in other servers in the same network

**my question is if SecComp fails then can we still run the elasticsearch in the cluster mode?**

my elasticsearch.yml

```
`#

```

#action.destructive\_requires\_name: true

network.host: ${HOSTNAME}  
network.host: X.X.X.X  
transport.host: localhost  
transport.tcp.port: 9300

#bootstrap.system\_call\_filter: false

Enabling CORS - for production we need to restrict domain wise

http.cors.allow-origin: "/.\*/"  
http.cors.enabled: true  
http.cors.allow-headers: "X-Requested-With,content-type,authorization"  
http.cors.allow-credentials: true

Enabling clustering more

[cluster.name](http://cluster.name): logsearch  
[node.name](http://node.name): "node\_1"  
node.master: true  
node.data: true  
#discovery.zen.ping.multicast.enabled: false

discovery.zen.minimum\_master\_nodes: 1  
discovery.zen.ping.unicast.hosts: ["X.X.X.X:9300","X.X.X.X:9300"]  
`

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 1, 2017, 1:34am UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/2 "2017-09-01T01:34:59Z")

</div>

You cross-posted this to the open source repository too: [https://github.com/elastic/elasticsearch/issues/26461](https://github.com/elastic/elasticsearch/issues/26461). Please do not do that, it fractures discussions. Additionally, please post questions here first, and save the repository for verified bugs and feature requests. When in doubt, post here first.

---

<div class="post-metadata">

**Author:** ![sunmesiav](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@sunmesiav](https://discuss.elastic.co/u/sunmesiav)\
**Post date:** [September 1, 2017, 3:17am UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/3 "2017-09-01T03:17:05Z")

</div>

Hi Jason, sorry about that, the reason I posted here is after adding bootstrap.system\_call\_filter: false in the elasticsearch.yml and having the transport.host: localhost, the clustering is not getting enabled between the nodes so does it mean that if SECCOMP is not compiled into kernel cant we enable the cluster setup inspite of setting bootstrap.system\_call\_filter: false

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 1, 2017, 4:03am UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/4 "2017-09-01T04:03:27Z")

</div>

As I explained in the GitHub issue: no. If you set `bootstrap.system_call_filter` to `false` it neuters the system call filter bootstrap check, it will pass everytime; the point is that now you're explicitly accepting the risk of Elasticsearch not sandboxing itself via `seccomp`. That is not the cause of your nodes being unable to cluster. I'm not sure exactly what you're trying to do but if you have nodes on multiple machines that you want to cluster, then they can't cluster with `transport.host` set to `localhost`.

---

<div class="post-metadata">

**Author:** ![sunmesiav](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@sunmesiav](https://discuss.elastic.co/u/sunmesiav)\
**Post date:** [September 1, 2017, 4:45am UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/5 "2017-09-01T04:45:28Z")

</div>

Hi Jason,

Iam trying to set up a cluster for nodes running on multiple machine, Iam planning to have one master node and two slave node, when I try to start the master node elasticsearch I was getting the error unable to install syscall filter: java.lang.UnsupportedOperationException: seccomp unavailable..., so I included bootstrap.system\_call\_filter: false in the masternode elastisearch.yml and now as you mentioned that setting transport.host : localhost will not work, I tried pointing the transport.host: x.x.x.x (server ip address), but dodoing so Iam getting the below exception

> bound or publishing to a non-loopback or non-link-local address, enforcing bootstrap checks  
> ERROR: [2] bootstrap checks failed

is there any other settings I need to do to make the nodes running on multiple machines to cluster ?

**log trace:**

> [2017-09-01T04:28:54,578][INFO][o.e.p.PluginsService] [sit077] loaded plugin [x-pack]  
> [2017-09-01T04:28:57,065][DEBUG][o.e.a.ActionModule] Using REST wrapper from plugin org.elasticsearch.xpack.XPackPlugin  
> [2017-09-01T04:28:58,038][INFO][o.e.x.m.j.p.l.CppLogMessageHandler] [controller/39566] [Main.cc@128] controller (64 bit): Version 5.5.2 (Build 0d83940bb9d682) Copyright (c) 2017 Elasticsearch BV  
> [2017-09-01T04:28:58,112][INFO][o.e.d.DiscoveryModule] [sit077] using discovery type [zen]  
> [2017-09-01T04:28:59,369][INFO][o.e.n.Node] [sit077] initialized  
> [2017-09-01T04:28:59,369][INFO][o.e.n.Node] [sit077] starting ...  
> [2017-09-01T04:28:59,759][INFO][o.e.t.TransportService] [sit077] publish\_address {x.x.x.x:9300}, bound\_addresses {x.x.x.x:9300}  
> [2017-09-01T04:28:59,774][INFO][o.e.b.BootstrapChecks] [sit077] bound or publishing to a non-loopback or non-link-local address, enforcing bootstrap checks  
> ERROR: [2] bootstrap checks failed  
> [1]: max file descriptors [4096] for elasticsearch process is too low, increase to at least [65536]  
> [2]: max virtual memory areas vm.max\_map\_count [65530] is too low, increase to at least [262144]  
> [2017-09-01T04:28:59,785][INFO][o.e.n.Node] [sit077] stopping ...  
> [2017-09-01T04:28:59,833][INFO][o.e.n.Node] [sit077] stopped  
> [2017-09-01T04:28:59,834][INFO][o.e.n.Node] [sit077] closing ...  
> [2017-09-01T04:28:59,850][INFO][o.e.n.Node] [sit077] closed

**my elasticsearch.yml for the above run is as below**

```
network.host: ${HOSTNAME}
#transport.host: localhost
transport.host: x.x.x.x
transport.tcp.port: 9300

bootstrap.system_call_filter: false

http.cors.allow-origin: "/.*/"
http.cors.enabled: true
http.cors.allow-headers: "X-Requested-With,content-type,authorization"
http.cors.allow-credentials: true

cluster.name: logsearch
node.name: "sit077"
node.master: true
node.data: true
#discovery.zen.ping.multicast.enabled: false
#discovery.zen.ping.unicast.hosts: ["sit077.dc.bc.com:9300","sit076.dc.bc.com:9300"]
discovery.zen.ping.unicast.hosts: ["x.x.x.x:9300","y.y.y.y:9300"]
discovery.zen.minimum_master_nodes: 1

```

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 1, 2017, 11:26am UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/6 "2017-09-01T11:26:18Z")

</div>

You still have failing bootstrap checks:

```auto
ERROR: [2] bootstrap checks failed
[1]: max file descriptors [4096] for elasticsearch process is too low, increase to at least [65536]
[2]: max virtual memory areas vm.max_map_count [65530] is too low, increase to at least [262144]

```

---

<div class="post-metadata">

**Author:** ![sunmesiav](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@sunmesiav](https://discuss.elastic.co/u/sunmesiav)\
**Post date:** [September 1, 2017, 1:23pm UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/7 "2017-09-01T13:23:37Z")

</div>

> [@Sudhakar\_Sundar](#):
>
> bootstrap.system\_call\_filter: false

setting bootstrap.system\_call\_filter: false wont take care of suppressing those two failed bootstrap checks?

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 1, 2017, 1:41pm UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/8 "2017-09-01T13:41:26Z")

</div>

No. Why would it? Those are completely unrelated issues.

---

<div class="post-metadata">

**Author:** ![sunmesiav](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@sunmesiav](https://discuss.elastic.co/u/sunmesiav)\
**Post date:** [September 1, 2017, 2:10pm UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/9 "2017-09-01T14:10:27Z")

</div>

Ok, is there anyway to suppress these checks with our own risk?

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 1, 2017, 2:30pm UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/10 "2017-09-01T14:30:44Z")

</div>

No, there is not.

---

<div class="post-metadata">

**Author:** ![sunmesiav](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@sunmesiav](https://discuss.elastic.co/u/sunmesiav)\
**Post date:** [September 1, 2017, 6:25pm UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/11 "2017-09-01T18:25:21Z")

</div>

Thanks a lot Jason for your quick responses, much appreciated !!

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 2, 2017, 1:09am UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/12 "2017-09-02T01:09:49Z")

</div>

You're welcome. In case you have not seen it, it might be worthwhile for you to read our [blog post about the bootstrap checks](https://www.elastic.co/blog/bootstrap_checks_annoying_instead_of_devastating).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2017, 1:09am UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062/13 "2017-09-30T01:09:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
