# Elastic agent fails under SysVinit due to dying endpoint security

**URL:** <https://discuss.elastic.co/t/elastic-agent-fails-under-sysvinit-due-to-dying-endpoint-security/257921>\
**Category:** Endpoint Security\
**Tags:** fleet\
**Created:** [December 7, 2020, 11:03pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-under-sysvinit-due-to-dying-endpoint-security/257921 "2020-12-07T23:03:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![grin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grin/32/80387_2.png) [@grin](https://discuss.elastic.co/u/grin)\
**Post date:** [December 7, 2020, 11:03pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-under-sysvinit-due-to-dying-endpoint-security/257921/1 "2020-12-07T23:03:50Z")

</div>

```auto
    running operation 'operation-install' for endpoint-security.7.10.0 
    Failed to dispatch action 'action_id: xxxxxxxxxxxxxxxx, type: POLICY_CHANGE', error: operator: failed to execute step sc-run, error: operation 'Exec' failed: : operation 'Exec' failed:
    failed to dispatch actions, error: operator: failed to execute step sc-run, error: operation 'Exec' failed: : operation 'Exec' failed:

```

This is all [repeatedly] what first-time user gets when trying to start fleet/agent. The problem seems to be that endpoint security requests the version of init, gets SysVInit version, tries a few times, then agrily leave with error 21, keeping elastic-agent in a continuous restart loop.

**Disabling endpoint security resolves the problem.** Took a better half of an hour to figure it out.

(No need to tell me that you use that disease called systemd, I have observed it [since I have to start agent manually, the init.d script is fubar], but crashing isn't the most polite way to convey the message "I will not run under init".)

Just maybe someone gets the same.

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [December 10, 2020, 1:43pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-under-sysvinit-due-to-dying-endpoint-security/257921/2 "2020-12-10T13:43:18Z")

</div>

Hi @grin Thanks for trying out Elastic Agent and Endpoint Security! You're right that Endpoint doesn't support sysvinit.

Where exactly did you see? Does "keeping elastic-agent in a continuous restart loop" mean Agent kept restarting itself, or that it kept trying to install endpoint security over and over but otherwise not cause any harm?

All supported distributions/versions ([https://www.elastic.co/support/matrix](https://www.elastic.co/support/matrix)) for Elastic Endpoint use systemd. However, I agree that there should be more graceful failure. We'll try to figure out a way to bubble up errors like this to the user in a more accessible way.

---

<div class="post-metadata">

**Author:** ![grin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grin/32/80387_2.png) [@grin](https://discuss.elastic.co/u/grin)\
**Post date:** [December 10, 2020, 6:48pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-under-sysvinit-due-to-dying-endpoint-security/257921/3 "2020-12-10T18:48:32Z")

</div>

> [@ferullo](#):
>
> Where exactly did you see? Does "keeping elastic-agent in a continuous restart loop" mean Agent kept restarting itself, or that it kept trying to install endpoint security over and over but otherwise not cause any harm?

Agent kept installing EPS and failed, and it kept the agent in offline state. The logs were also flooded by the failure messages.  
Since this was my fist try at agent I don't remember whether the offline state was caused _only_ due to EPS or it was something else, I can't be 100% sure the stall was caused by this only, but if I had to guess I'd say it was.

> [@ferullo](#):
>
> All supported distributions/versions ([Support Matrix | Elastic](https://www.elastic.co/support/matrix)) for Elastic Endpoint use systemd. However, I agree that there should be more graceful failure. We'll try to figure out a way to bubble up errors like this to the user in a more accessible way.

Since EPS install gives no output whatsoever that could be probably a good way to start. 🙂 Also I suggest to mention that in the documentation unless you change your mind.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2021, 6:48pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-under-sysvinit-due-to-dying-endpoint-security/257921/4 "2021-01-07T18:48:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
