# Elasticsearch 1.7.2 sudden crash after 26 hours

**URL:** <https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382>\
**Category:** Elasticsearch\
**Created:** [November 12, 2015, 8:15am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382 "2015-11-12T08:15:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaminvp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaminvp/32/5868_2.png) [@jaminvp](https://discuss.elastic.co/u/jaminvp)\
**Post date:** [November 12, 2015, 8:15am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/1 "2015-11-12T08:15:44Z")

</div>

Greetings,

I noticed my Elasticsearch v1.7.2 crashed after running for over 24 hours. The exact error is:

**_"A fatal error has been detected by the Java Runtime Environment:_**

**_EXCEPTION\_ACCESS\_VIOLATION (0xc0000005) at pc=0x000000006afd18a7, pid=23416, tid=13004_**

**_JRE version: Java(TM) SE Runtime Environment (8.0\_60-b27) (build 1.8.0\_60-b27)_**  
**_Java VM: Java HotSpot(TM) 64-Bit Server VM (25.60-b23 mixed mode windows-amd64 compressed oops)_**  
**_Problematic frame:_**  
**_V [jvm.dll+0x2118a7]_**

**_Failed to write core dump. Call to MiniDumpWriteDump() failed (Error 0x800705af: The paging file is too small for this operation to complete._**

**_)"_**

I wanted to add the hs\_err\_pid log file, but it seems only images can be added? I can PM the entire log if someone wants to see it. Adding it as plain text here would clutter this post too much.

I don't know what happened, could anyone provide some insight? Swapping is disabled so it shouldn't be the cause of this error.

Kind regards,

JaminVP

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 12, 2015, 8:25am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/2 "2015-11-12T08:25:47Z")

</div>

Please don't attach heap dumps 😄

It's hard to say why, is there more to the ES logs?

---

<div class="post-metadata">

**Author:** ![jaminvp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaminvp/32/5868_2.png) [@jaminvp](https://discuss.elastic.co/u/jaminvp)\
**Post date:** [November 12, 2015, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/3 "2015-11-12T08:40:53Z")

</div>

Nothing in the ES logs, only the hs\_err\_pid log shows details but they're not that clear to me. I guess I'll just restart it and see what happens in the next 48 hours. I suspect there was a memory error seeing as the system has a lot of stuff to process around the time ES crashed.

It's strange though how it took over 26 hours to crash, and even stranger how it crashed on a holiday when the system has less to process.

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [November 12, 2015, 9:42am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/4 "2015-11-12T09:42:58Z")

</div>

Your Java JVM is buggy, you should report this to Oracle.

---

<div class="post-metadata">

**Author:** ![jaminvp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaminvp/32/5868_2.png) [@jaminvp](https://discuss.elastic.co/u/jaminvp)\
**Post date:** [November 16, 2015, 1:15pm UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/5 "2015-11-16T13:15:41Z")

</div>

Well, after 4 days of continuous hard labor, Elasticsearch crashed again with the JVM stopping out of nowhere. Elasticsearch wasn't using its full allocated memory, I checked this one hour before it crashed.

Some things I noticed though:

- Before ES crashed, the java.exe process linked to Logstash 1.5.4 was using A LOT of memory, like 1.6GB. I restarted both Logstash and Elasticsearch and I noticed that there seems to be a memory leak in the java.exe linked to Logstash. It steadily rises with 8-32KB increments, never ceasing and never lowering. I suspect the Logstash memory leak is causing the ES JVM to crash.

- After ES crashes, the services tab shows a new service installed: elasticsearch-service- **x86**. Notice how the service.bat file installs the elasticsearch-service-x64 service. I have no idea why the x86 version gets installed after x64 crashes. It's installed as a disabled service.

Other servers with Logstash 1.5.4 installed do not seem to have this memory leak. Is there some sort of leak caused by running both ES and Logstash on the same machine?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 16, 2015, 10:43pm UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/6 "2015-11-16T22:43:49Z")

</div>

There is a known issue with ruby on windows that causes a memory leak, I think [this](https://github.com/elastic/logstash/issues/3722) is the issue about it.

---

<div class="post-metadata">

**Author:** ![PatrickKik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrickkik/32/619_2.png) [@PatrickKik](https://discuss.elastic.co/u/PatrickKik)\
**Post date:** [February 24, 2016, 12:49pm UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/7 "2016-02-24T12:49:02Z")

</div>

We're having the about same problem.

Some of us see the node collapsing moments after startup. There's no load on the node.

Elasticsearch 1.7.5, Java 1.8.0\_65 and other versions of Java 1.8.0.

---

<div class="post-metadata">

**Author:** ![PatrickKik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrickkik/32/619_2.png) [@PatrickKik](https://discuss.elastic.co/u/PatrickKik)\
**Post date:** [March 4, 2016, 6:43am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/8 "2016-03-04T06:43:08Z")

</div>

In our case it turns out that the combination of having Windows Updates KB3126593 and KB3126587 installed was causing the problem. We're on Window 7 Enterprise.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:11pm UTC](https://discuss.elastic.co/t/elasticsearch-1-7-2-sudden-crash-after-26-hours/34382/9 "2017-07-05T23:11:22Z")

</div>


