# Elastcisearch process gets killed automatically

**URL:** <https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679>\
**Category:** Elasticsearch\
**Created:** [July 16, 2016, 9:35pm UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679 "2016-07-16T21:35:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![anoopmk007](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@anoopmk007](https://discuss.elastic.co/u/anoopmk007)\
**Post date:** [July 16, 2016, 9:35pm UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679/1 "2016-07-16T21:35:51Z")

</div>

Hello,

I am new to ELK, recently configured AWS-Linux box with elastcisearch and kibana.

Process for both kibana and elastcisearch started successfully and able to get the logs and corresponding results.

But after sometime elastciseach process gets killed automatically, ie i have to start the process again to get active. Could you please suggest any help on this?

**elastciseach logs:-**

_dashboard]$ ./elasticsearch-2.3.3/bin/elasticsearch_  
_[2016-07-16 21:31:26,738][INFO][node] [Centurion] version[2.3.3], pid[23133], build[218bdf1/2016-05-17T15:40:04Z]_  
_[2016-07-16 21:31:26,739][INFO][node] [Centurion] initializing ..._  
_[2016-07-16 21:31:28,133][INFO][plugins] [Centurion] modules [lang-groovy, reindex, lang-expression], plugins [], sites []_  
_[2016-07-16 21:31:28,179][INFO][env] [Centurion] using [1] data paths, mounts [[/ (/dev/xvda1)]], net usable\_space [5.9gb], net total\_space [7.7gb], spins? [no], types [ext4]_  
_[2016-07-16 21:31:28,179][INFO][env] [Centurion] heap size [1015.6mb], compressed ordinary object pointers [true]_  
_[2016-07-16 21:31:28,180][WARN][env] [Centurion] max file descriptors [4096] for elasticsearch process likely too low, consider increasing to at least [65536]_  
_[2016-07-16 21:31:32,469][INFO][node] [Centurion] initialized_  
_[2016-07-16 21:31:32,469][INFO][node] [Centurion] starting ..._  
_[2016-07-16 21:31:32,596][INFO][transport] [Centurion] publish\_address {[xxx.xxx.xxx.xxx:9300](http://xxx.xxx.xxx.xxx:9300)}, bound\_addresses {[xxx.xxx.xxx.xxx:9300](http://xxx.xxx.xxx.xxx:9300)}_  
_[2016-07-16 21:31:32,605][INFO][discovery] [Centurion] elasticsearch/f-BQjtvWQCaunaOLu8OJkA_  
_[2016-07-16 21:31:35,805][INFO][cluster.service] [Centurion] new\_master {Centurion}{f-BQjtvWQCaunaOLu8OJkA}{[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)}{[xxx.xxx.xxx.xxx:9300](http://xxx.xxx.xxx.xxx:9300)}, reason: zen-disco-join(elected\_as\_master, [0] joins received)_  
_[2016-07-16 21:31:35,837][INFO][http] [Centurion] publish\_address {[xxx.xxx.xxx.xxx:9200](http://xxx.xxx.xxx.xxx:9200)}, bound\_addresses {[xxx.xxx.xxx.xxx:9200](http://xxx.xxx.xxx.xxx:9200)}_  
_[2016-07-16 21:31:35,838][INFO][node] [Centurion] started_  
_[2016-07-16 21:31:35,962][INFO][gateway] [Centurion] recovered [2] indices into cluster\_state_  
_[2016-07-16 21:31:37,238][INFO][cluster.routing.allocation] [Centurion] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[logstash-2016.07.07][4]] ...])._

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 17, 2016, 1:55am UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679/2 "2016-07-17T01:55:42Z")

</div>

Please format your logs with \</\> icon.

Do you start Elasticsearch with bin/elasticsearch?  
So anytime you log out, the process is stopped because it runs in foreground.

You should run Elasticsearch as a service instead.  
Use Deb or rpm packages instead.

---

<div class="post-metadata">

**Author:** ![anoopmk007](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@anoopmk007](https://discuss.elastic.co/u/anoopmk007)\
**Post date:** [July 17, 2016, 3:38am UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679/3 "2016-07-17T03:38:20Z")

</div>

Thank you David for the response!

I am using command -- "bin/elasticsearch & " for running in background.

Also could you please elaborate "format your logs with \</\> icon" ?

I am using logs format as below

Log file:-

[LAYER]GSDIM, [TYPE]REQ, [METHOD]SESSION, [ACTION]START, [latitude]47.60621,[longitude]-122.33207  
[LAYER]GSDIM, [TYPE]REP, [TIME]1, [METHOD]SESSION, [ACTION]START, [RESPONSE]Session Started,[latitude]47.60621,[longitude]-122.33207

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 17, 2016, 4:03am UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679/4 "2016-07-17T04:03:04Z")

</div>

I meant that instead of posting here:

dashboard]$ ./elasticsearch-2.3.3/bin/elasticsearch  
[2016-07-16 21:31:26,738][INFO][node] [Centurion] version[2.3.3], pid[23133], build[218bdf1/2016-05-17T15:40:04Z]  
[2016-07-16 21:31:26,739][INFO][node] [Centurion] initializing ...

Do:

```
dashboard]$ ./elasticsearch-2.3.3/bin/elasticsearch
[2016-07-16 21:31:26,738][INFO][node] [Centurion] version[2.3.3], pid[23133], build[218bdf1/2016-05-17T15:40:04Z]
[2016-07-16 21:31:26,739][INFO][node] [Centurion] initializing ...
```

---

<div class="post-metadata">

**Author:** ![unknownunknown](https://avatars.discourse-cdn.com/v4/letter/u/4da419/32.png) [@unknownunknown](https://discuss.elastic.co/u/unknownunknown)\
**Post date:** [July 18, 2016, 1:36pm UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679/5 "2016-07-18T13:36:08Z")

</div>

> [@anoopmk007](#):
>
> I am using command -- "bin/elasticsearch & " for running in background.

Even though this runs in the background it will still get killed when you logout. I definitely agree with the recommendation to use existing RPM or DEBs and to run this as a service.

However, if you really don't want to run it as a service, you can detach the background process from your session if you want it to continue when you logout:

```
# bin/elasticsearch >& /dev/null &
# disown %1

```

---

<div class="post-metadata">

**Author:** ![anoopmk007](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@anoopmk007](https://discuss.elastic.co/u/anoopmk007)\
**Post date:** [July 22, 2016, 9:22pm UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679/6 "2016-07-22T21:22:51Z")

</div>

Hello,

Just now changed the process to run as a service using RPM, but still have the issue of getting automatically stopped/killed.

Couple of other observations:-

1. If I am starting **only** elastcisearch service then elastcisearch service will **not** gets killed/stopped.

sudo service elasticsearch start

1. If i am starting elasctisearch and kibana in same server then elastcisearch service will gets killed/stopped after some time.

sudo service elasticsearch start  
sudo service kibana start

Any logs i can check here for this issue? Any help appreciated!

---

<div class="post-metadata">

**Author:** ![unknownunknown](https://avatars.discourse-cdn.com/v4/letter/u/4da419/32.png) [@unknownunknown](https://discuss.elastic.co/u/unknownunknown)\
**Post date:** [July 25, 2016, 5:46pm UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679/7 "2016-07-25T17:46:31Z")

</div>

dmesg and /var/log/messages might show any system errors like out of memory conditions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:33pm UTC](https://discuss.elastic.co/t/elastcisearch-process-gets-killed-automatically/55679/8 "2017-07-05T22:33:06Z")

</div>


