# Elastic and kibana send resets on Ubuntu server

**URL:** <https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216>\
**Category:** Elasticsearch\
**Created:** [August 22, 2019, 2:20am UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216 "2019-08-22T02:20:32Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mezoloth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mezoloth/32/45613_2.png) [@Mezoloth](https://discuss.elastic.co/u/Mezoloth)\
**Post date:** [August 22, 2019, 2:20am UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/1 "2019-08-22T02:20:32Z")

</div>

I have elastic and kibana setup and running. I can curl to localhost:9200 as show below:

```
root@elk:~# curl http://127.0.0.1:9200
    {
      "name" : "elk",
      "cluster_name" : "elasticsearch",
      "cluster_uuid" : "EqHMzJiWT1-od9wkmcL8-w",
      "version" : {
    "number" : "7.3.0",
    "build_flavor" : "default",
    "build_type" : "deb",
    "build_hash" : "de777fa",
    "build_date" : "2019-07-24T18:30:11.767338Z",
    "build_snapshot" : false,
    "lucene_version" : "8.1.0",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
      },
      "tagline" : "You Know, for Search"
    }

root@elk:~# wget localhost:5601
--2019-08-22 02:07:59-- http://localhost:5601/
Resolving localhost (localhost)... 127.0.0.1
Connecting to localhost (localhost)|127.0.0.1|:5601... connected.
HTTP request sent, awaiting response... 302 Found
Location: /app/kibana [following]
--2019-08-22 02:07:59-- http://localhost:5601/app/kibana
Connecting to localhost (localhost)|127.0.0.1|:5601... connected.
HTTP request sent, awaiting response... 200 OK
Length: 72679 (71K) [text/html]
Saving to: ‘index.html.1’

index.html.1 100%[=========================================================================>] 70.98K --.-KB/s in 0s

2019-08-22 02:08:00 (298 MB/s) - ‘index.html.1’ saved [72679/72679]

```

But when I try to connect externally, I get TCP resets:

```
oot@elk:~# tcpdump port 9200
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ens160, link-type EN10MB (Ethernet), capture size 262144 bytes
02:12:22.205554 IP 192.168.2.187.42340 > elk.9200: Flags [S], seq 1830289600, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:22.205610 IP elk.9200 > 192.168.2.187.42340: Flags [R.], seq 0, ack 1830289601, win 0, length 0
02:12:22.457587 IP 192.168.2.187.42341 > elk.9200: Flags [S], seq 4168675762, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:22.457606 IP elk.9200 > 192.168.2.187.42341: Flags [R.], seq 0, ack 4168675763, win 0, length 0
02:12:22.705841 IP 192.168.2.187.42340 > elk.9200: Flags [S], seq 1830289600, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:22.705883 IP elk.9200 > 192.168.2.187.42340: Flags [R.], seq 0, ack 1, win 0, length 0
02:12:22.958906 IP 192.168.2.187.42341 > elk.9200: Flags [S], seq 4168675762, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:22.958947 IP elk.9200 > 192.168.2.187.42341: Flags [R.], seq 0, ack 1, win 0, length 0
02:12:23.205999 IP 192.168.2.187.42340 > elk.9200: Flags [S], seq 1830289600, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:23.206040 IP elk.9200 > 192.168.2.187.42340: Flags [R.], seq 0, ack 1, win 0, length 0
02:12:23.459044 IP 192.168.2.187.42341 > elk.9200: Flags [S], seq 4168675762, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:23.459083 IP elk.9200 > 192.168.2.187.42341: Flags [R.], seq 0, ack 1, win 0, length 0
^C
12 packets captured
12 packets received by filter
0 packets dropped by kernel
root@elk:~# tcpdump port 5601
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ens160, link-type EN10MB (Ethernet), capture size 262144 bytes
02:12:55.855770 IP 192.168.2.187.42349 > elk.5601: Flags [S], seq 190547619, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:55.855827 IP elk.5601 > 192.168.2.187.42349: Flags [R.], seq 0, ack 190547620, win 0, length 0
02:12:56.106356 IP 192.168.2.187.42350 > elk.5601: Flags [S], seq 2523034990, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:56.106394 IP elk.5601 > 192.168.2.187.42350: Flags [R.], seq 0, ack 2523034991, win 0, length 0
02:12:56.356717 IP 192.168.2.187.42349 > elk.5601: Flags [S], seq 190547619, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:56.356767 IP elk.5601 > 192.168.2.187.42349: Flags [R.], seq 0, ack 1, win 0, length 0
02:12:56.606771 IP 192.168.2.187.42350 > elk.5601: Flags [S], seq 2523034990, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:56.606801 IP elk.5601 > 192.168.2.187.42350: Flags [R.], seq 0, ack 1, win 0, length 0
02:12:56.857817 IP 192.168.2.187.42349 > elk.5601: Flags [S], seq 190547619, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:56.857871 IP elk.5601 > 192.168.2.187.42349: Flags [R.], seq 0, ack 1, win 0, length 0
02:12:57.107910 IP 192.168.2.187.42350 > elk.5601: Flags [S], seq 2523034990, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
02:12:57.107964 IP elk.5601 > 192.168.2.187.42350: Flags [R.], seq 0, ack 1, win 0, length

```

The firewall is off:

```
root@elk:~# ufw status verbose
Status: inactive

```

I can SSH to the server, so I know the network is fine.  
Anyone have any ideas on this?

The OS is the latest Ubuntu server.

Thanks,

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 22, 2019, 12:20pm UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/2 "2019-08-22T12:20:55Z")

</div>

is elasticsearch configured to listen on anything else than localhost? Can you share the configuration file?

---

<div class="post-metadata">

**Author:** ![Mezoloth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mezoloth/32/45613_2.png) [@Mezoloth](https://discuss.elastic.co/u/Mezoloth)\
**Post date:** [August 22, 2019, 1:22pm UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/3 "2019-08-22T13:22:28Z")

</div>

I have tried setting network.hos to the following.

```
 #network.host: 192.168.0.1
#
#network.host: 0.0.0.0
#network.host: 129.168.2.39
network.host: 127.0.0.1
# Set a custom port for HTTP:
#
#http.port: 9200
http.port: 9200

```

If I set it to anything other than 127.0.0.1, elastic search won't stay started and exits with either; status=1/failure or status=78/n/a

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 22, 2019, 2:44pm UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/4 "2019-08-22T14:44:03Z")

</div>

if you configure it on anything else than localhost, the bootstrap checks are actually run, please take a look at your logfiles and see what is preventing startup. The logs usually include link to description on how to fix the issue.

---

<div class="post-metadata">

**Author:** ![Mezoloth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mezoloth/32/45613_2.png) [@Mezoloth](https://discuss.elastic.co/u/Mezoloth)\
**Post date:** [August 22, 2019, 9:53pm UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/5 "2019-08-22T21:53:37Z")

</div>

Which elasticsearch log should I be looking at?

Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 23, 2019, 6:59am UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/6 "2019-08-23T06:59:43Z")

</div>

Check in the `/var/log/elasticsearch` directory

---

<div class="post-metadata">

**Author:** ![Mezoloth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mezoloth/32/45613_2.png) [@Mezoloth](https://discuss.elastic.co/u/Mezoloth)\
**Post date:** [August 23, 2019, 2:46pm UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/7 "2019-08-23T14:46:07Z")

</div>

Yeah, I know the directory. But which file would actually give relevant information?

elasticsearch.log  
gc.log  
elasticsearch\_audit.json  
elasticsearch\_deprecation.json  
elasticsearch\_deprecation.log  
elasticsearch elasticsearch  
elasticsearch\_index\_indexing\_slowlog.json  
elasticsearch\_index\_indexing\_slowlog.log  
elasticsearch\_index\_search\_slowlog.json  
elasticsearch\_index\_search\_slowlog.log  
elasticsearch.log  
elasticsearch\_server.json

Thanks,

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 26, 2019, 8:20am UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/8 "2019-08-26T08:20:53Z")

</div>

the `elasticsearch.log` would be a first try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2019, 8:20am UTC](https://discuss.elastic.co/t/elastic-and-kibana-send-resets-on-ubuntu-server/196216/9 "2019-09-23T08:20:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
