Hello ,
I have migrated wazuh server from 5.x to 6.4.2 which is built on elastic and the other modules of this source.Post completion of migration unable to start the "elasticsearchservice" .getting below error for your reference.Please let me know if anyone of you experienced similar and have a solution in place.
Error code
[root@wazuh-server ~]# systemctl status elasticsearch.service
● elasticsearch.service - Elasticsearch
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled)
Active: failed (Result: exit-code) since Tue 2018-10-30 02:38:34 CDT; 39s ago
Docs: http://www.elastic.co
Process: 1096 ExecStart=/usr/share/elasticsearch/bin/elasticsearch -p ${PID_DIR}/elasticsearch.pid --quiet (code=exited, status=1/FAILURE)
Main PID: 1096 (code=exited, status=1/FAILURE)
Oct 30 02:38:31 wazuh-server elasticsearch[1096]: 2018-10-30 02:38:31,652 main ERROR Null object returned for RollingFile in Appenders.
Oct 30 02:38:31 wazuh-server elasticsearch[1096]: 2018-10-30 02:38:31,653 main ERROR Null object returned for RollingFile in Appenders.
Oct 30 02:38:31 wazuh-server elasticsearch[1096]: 2018-10-30 02:38:31,653 main ERROR Unable to locate appender "rolling" for logger config "root"
Oct 30 02:38:31 wazuh-server elasticsearch[1096]: 2018-10-30 02:38:31,654 main ERROR Unable to locate appender "index_indexing_slowlog_rolling" for logger c...og.index"
Oct 30 02:38:31 wazuh-server elasticsearch[1096]: 2018-10-30 02:38:31,654 main ERROR Unable to locate appender "audit_rolling" for logger config "org.elasti...ditTrail"
Oct 30 02:38:31 wazuh-server elasticsearch[1096]: 2018-10-30 02:38:31,655 main ERROR Unable to locate appender "index_search_slowlog_rolling" for logger con....slowlog"
Oct 30 02:38:31 wazuh-server elasticsearch[1096]: 2018-10-30 02:38:31,655 main ERROR Unable to locate appender "deprecation_rolling" for logger config "org....recation"
Oct 30 02:38:34 wazuh-server systemd[1]: elasticsearch.service: main process exited, code=exited, status=1/FAILURE
Oct 30 02:38:34 wazuh-server systemd[1]: Unit elasticsearch.service entered failed state.
Oct 30 02:38:34 wazuh-server systemd[1]: elasticsearch.service failed.
Hint: Some lines were ellipsized, use -l to show in full.
Do let me know if you need further information on the same.
Regards,
Praveen