# Elasticsearch does not start CentOS7

**URL:** <https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373>\
**Category:** Elasticsearch\
**Created:** [November 8, 2022, 1:13am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373 "2022-11-08T01:13:11Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 1:13am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/1 "2022-11-08T01:13:11Z")

</div>

Hi!  
Installed Elasticsearch as mentioned in Elastic Docs  
Generated certificates and keys - followed this link - [How to install Elasticsearch and Kibana 8.0 on Centos 7](https://www.scioshield.uk/how-to-install-elasticsearch-and-kibana-8-0-on-centos-7/)

puppet here in the log - just name of the server - do not pay attention

Elasticsearch does not start and gives error:

```auto
2022-11-07T17:53:40,154][WARN][stderr] [puppet] The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")
[2022-11-07T17:53:40,154][WARN][stderr] [puppet] The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")
[2022-11-07T17:53:40,154][WARN][stderr] [puppet] The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")
[2022-11-07T17:53:40,153][WARN][stderr] [puppet] The system environment variables are not available to Log4j due to security restrictions: java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getenv.*")
[2022-11-07T17:53:40,153][ERROR][o.e.b.ElasticsearchUncaughtExceptionHandler] [puppet] uncaught exception in thread [process reaper (pid 7127)]
java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "modifyThread")
	at java.security.AccessControlContext.checkPermission(AccessControlContext.java:485) ~[?:?]
	at java.security.AccessController.checkPermission(AccessController.java:1068) ~[?:?]
	at java.lang.SecurityManager.checkPermission(SecurityManager.java:411) ~[?:?]
	at org.elasticsearch.secure_sm.SecureSM.checkThreadAccess(SecureSM.java:166) ~[?:?]
	at org.elasticsearch.secure_sm.SecureSM.checkAccess(SecureSM.java:120) ~[?:?]
	at java.lang.Thread.checkAccess(Thread.java:2360) ~[?:?]
	at java.lang.Thread.setDaemon(Thread.java:2308) ~[?:?]
	at java.lang.ProcessHandleImpl.lambda$static$0(ProcessHandleImpl.java:103) ~[?:?]
	at java.util.concurrent.ThreadPoolExecutor$Worker.<init>(ThreadPoolExecutor.java:637) ~[?:?]
	at java.util.concurrent.ThreadPoolExecutor.addWorker(ThreadPoolExecutor.java:928) ~[?:?]
	at java.util.concurrent.ThreadPoolExecutor.processWorkerExit(ThreadPoolExecutor.java:1021) ~[?:?]
	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1158) ~[?:?]
	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:642) ~[?:?]
	at java.lang.Thread.run(Thread.java:1589) ~[?:?]
	at jdk.internal.misc.InnocuousThread.run(InnocuousThread.java:186) ~[?:?]

```

Pls, help

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 8, 2022, 1:37am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/2 "2022-11-08T01:37:49Z")

</div>

Hi @vassiliy.vins Welcome to the community...

It is hard for us to help when users use some other / unofficial blog instead of the official docs to install the Elastic Stack with other components etc... and are unclear why the install does not work.

Why did you chose that blog / installation method? First glance it sort of looks OK but hard to say.

Not sure why you are getting that error...

Perhaps you should just look at [our docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/install-elasticsearch.html) and install?

Do you have Docker on your Desktop?

Do you have access to just a plain ole CentOS Box?

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 1:02pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/3 "2022-11-08T13:02:01Z")

</div>

Hi Stephen!

Installation was done according to official Elasticsearch web page

The unofficial blog was used ONLY for creating and signing certificates. for Elasticsearch and Kibana because official page does not describe this part in some order

For installation was used CentOS7 installed on VMware

I can easily repeat ELK installation steps from official page one more time.

Regards,

Vassiliy

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 8, 2022, 2:14pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/4 "2022-11-08T14:14:25Z")

</div>

> [@vassiliy.vins](#):
>
> The unofficial blog was used ONLY for creating and signing certificates. for Elasticsearch and Kibana because official page does not describe this part in some order

If you do the default installation following [the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/rpm.html#rpm-security-configuration) all the certs are done for you.

> Start Elasticsearch with security enabled
> 
> When installing Elasticsearch, security features are enabled and configured by default. When you install Elasticsearch, the following security configuration occurs automatically:
> 
> Authentication and authorization are enabled, and a password is generated for the elastic built-in superuser.  
> Certificates and keys for TLS are generated for the transport and HTTP layer, and TLS is enabled and configured with these keys and certificates.

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 5:20pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/5 "2022-11-08T17:20:20Z")

</div>

the reason I was using the link provided was:  
Docs says - run this command  
/usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana  
I did and got output  
ERROR: [xpack.security.enrollment.enabled] must be set to `true` to create an enrollment token  
I understand that I should go and enable this xpack in elasticsearch.yml

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 5:24pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/6 "2022-11-08T17:24:23Z")

</div>

if I go and enable this feature and run it again I will get next error  
ERROR: Unable to create an enrollment token. Elasticsearch node HTTP layer SSL configuration is not configured with a keystore

What I want to say I can't see in docs steps I need to go to get running stack. Even with very basic configuration I could start to play with

But thank you for your supporting me

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 5:27pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/7 "2022-11-08T17:27:37Z")

</div>

Actually my question is - which options should I enable in elasticsearch,yml, kibana.yml, logstash.yml to get running ELK stack. Fromn this point I could start adding certificates and play with different options

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 5:29pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/8 "2022-11-08T17:29:10Z")

</div>

to be clear - I have now completely fresh installation ELK stack 8.5 followed ELK official Docs

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 5:37pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/9 "2022-11-08T17:37:34Z")

</div>

after new set up I have Kibana running, Elasticsearch running, logstash running.  
I have in browser for port 9200

```auto
{
  "name" : "dlx-prd-dal-search-11-p",
  "cluster_name" : "my-application",
  "cluster_uuid" : "hoBqwGgpSyClek5brPRaBA",
  "version" : {
    "number" : "8.5.0",
    "build_flavor" : "default",
    "build_type" : "rpm",
    "build_hash" : "c94b4700cda13820dad5aa74fae6db185ca5c304",
    "build_date" : "2022-10-24T16:54:16.433628434Z",
    "build_snapshot" : false,
    "lucene_version" : "9.4.1",
    "minimum_wire_compatibility_version" : "7.17.0",
    "minimum_index_compatibility_version" : "7.0.0"
  },
  "tagline" : "You Know, for Search"
}

```

And I can connect Kibana on port 5601 but I see this message:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d613f67dc50028a6e23397cc176c7b1659de41e8.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 8, 2022, 6:15pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/10 "2022-11-08T18:15:20Z")

</div>

> [@vassiliy.vins](#):
>
> ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d613f67dc50028a6e23397cc176c7b1659de41e8.png)
> 
> image1171×153 16.6 KB

You are seeing that in Kibana?

I think You can ignore that unless you want to use Fleet / Agent your firewall is blocking the connection to the Elastic Package Registry

> Kibana connects to the Elastic Package Registry at `epr.elastic.co` using the Elastic Package Manager,

> **[Fleet and Elastic Agent overview | Fleet and Elastic Agent Guide \[8.5\] | Elastic](https://www.elastic.co/guide/en/fleet/8.5/fleet-overview.html#package-registry-intro)**

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 6:23pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/11 "2022-11-08T18:23:40Z")

</div>

OK, I can ignore that. Now how can I check if kibana is able to connect to elasticsearch?  
As i mentione previously I was not able to create kibana token. That;'s why I put xpack.security.enabled: 'false' in elasticsearch.yml

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 8, 2022, 6:34pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/12 "2022-11-08T18:34:33Z")

</div>

> [@vassiliy.vins](#):
>
> OK, I can ignore that. Now how can I check if kibana is able to connect to elasticsearch?  
> As i mentione previously I was not able to create kibana token. That;'s why I put xpack.security.enabled: 'false' in elasticsearch.yml

If you set `xpack.security.enabled: 'false'` you are going to mess up a few things...

You can generate a new kibana token ... if you want... but it you start turning off security make sure you know what you are doing.

if you simply clean up everything including the Elasticsearch Data Directories...

Install elasticsearch .. .it will create the kibana enrollment token in the terminal during setup.

Then install Kibana ... click on the url in the terminal during kibana install, enter the enrollment token that was generated during the elasticsearch install everything will work... all the configurations happens automatically

The whole process end to end takes about 5 minutes

But if it works .. then that is fine!

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/13 "2022-11-08T18:48:38Z")

</div>

where can I find enrollment token for kibana? I didn't see it during installation, that's the reason I'm trying to recreate it.

And I've already installed kibana without this token. Can I add it somehow now?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 8, 2022, 6:57pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/14 "2022-11-08T18:57:43Z")

</div>

> [@vassiliy.vins](#):
>
> where can I find enrollment token for kibana? I didn't see it during installation, that's the reason I'm trying to recreate it.
> 
> And I've already installed kibana without this token. Can I add it somehow now?

The enrollment token is created during Elasticsearch installation, if you didn't copy the entire text that was printed in the screen I'm not sure you can recreate the enrollment token.

I think that it would be easy to create a service account for Kibana and use this service account to authentication in Elasticsearch.

To create a service account you need to make the following request to Elasticsearch.

```auto
curl -X POST "https://your-es-host:9200/_security/service/elastic/kibana/credential/token/kibanatoken?pretty" -u elastic:PASSWORD -k

```

Where `PASSWORD` is the password set for the `elastic` user.

It will return a json similar to this:

```auto
{
  "created" : true,
  "token" : {
    "name" : "kibanatoken",
    "value" : "token"
  }
}

```

Now you need to copy the token and configure it in Kibana.

Just put the following in your `kibana.yml`.

```auto
elasticsearch.serviceAccountToken: token

```

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 6:58pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/15 "2022-11-08T18:58:42Z")

</div>

OK, let me try

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 8, 2022, 7:00pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/16 "2022-11-08T19:00:17Z")

</div>

Can I use IP instead of hostname in the command?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 8, 2022, 7:01pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/17 "2022-11-08T19:01:18Z")

</div>

> [@vassiliy.vins](#):
>
> Can I use IP instead of hostname in the command?

It makes no difference, you just need to make a request to your Elasticsearch.

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 9, 2022, 1:16pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/18 "2022-11-09T13:16:32Z")

</div>

I have tried to run command using my password and IP  
curl -X POST "[https://your-es-host:9200/\_security/service/elastic/kibana/credential/token/kibanatoken?pretty](https://your-es-host:9200/_security/service/elastic/kibana/credential/token/kibanatoken?pretty)" -u elastic:PASSWORD -k

didn't work.. output " curl: (35) SSL received a record that exceeded the maximum permissible length"

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 9, 2022, 1:27pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/19 "2022-11-09T13:27:49Z")

</div>

Never saw this error.

Do you have anything in front of your Elasticsearch, something like NGINX? Also, did you enabled https for your elasticsearch?

How did you get the status for your elasticsearch, this response:

```auto
{
  "name" : "dlx-prd-dal-search-11-p",
  "cluster_name" : "my-application",
  "cluster_uuid" : "hoBqwGgpSyClek5brPRaBA",
  "version" : {
    "number" : "8.5.0",
    "build_flavor" : "default",
    "build_type" : "rpm",
    "build_hash" : "c94b4700cda13820dad5aa74fae6db185ca5c304",
    "build_date" : "2022-10-24T16:54:16.433628434Z",
    "build_snapshot" : false,
    "lucene_version" : "9.4.1",
    "minimum_wire_compatibility_version" : "7.17.0",
    "minimum_index_compatibility_version" : "7.0.0"
  },
  "tagline" : "You Know, for Search"
}

```

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [November 9, 2022, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373/20 "2022-11-09T13:35:04Z")

</div>

No, I don't have Nginx installed  
the output I provided - I got using my browser [http://localhost:9200/](http://localhost:9200/)  
I read somewhere in internet - it is a way to check if elasticsearch works normally after installation. So, as you can see it works normally.  
in elasticsearch.yml I enabled http.port: 9200

[Next page](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373.md?page=2)
