# Elasticsearch Linux User

**URL:** <https://discuss.elastic.co/t/elasticsearch-linux-user/311031>\
**Category:** Elasticsearch\
**Created:** [July 30, 2022, 8:47am UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031 "2022-07-30T08:47:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![lucian1094](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucian1094/32/109048_2.png) [@lucian1094](https://discuss.elastic.co/u/lucian1094)\
**Post date:** [July 30, 2022, 8:47am UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031/1 "2022-07-30T08:47:03Z")

</div>

I installed an Elasticsearch on CentOS using rpm file. After install, elaticsearch user and group is created, user which can't be used to manage (start/stop/restart) elasticsearch (nologin, nonexistent). I don't want to manage elasticsearch with root user. Should I create a new user for that or to modify elasticsearch user? What will be the best approach?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 4:19pm UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031/2 "2022-07-30T16:19:14Z")

</div>

Hi @lucian1094 Welcome to the community...

No do not create another user.

When you install elastic with and .rpm and start elasticsearch with sudo systemctl it will run as the non-root user `elastic` ... exactly as designed.

the systemctl command is run as `sudo` BUT elasticsearch is executed / launched under the less privlieged `elastic` user ... exactly as designed.

Elasticsearch will not run as `root` as designed... following the existing docs / procedure is best practice and is used my 1000s of users to run elasticsearch securely and best practice.

If you want to run systemctl without sudo... that is a linux question best addressed by your linux admin...

---

<div class="post-metadata">

**Author:** ![lucian1094](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucian1094/32/109048_2.png) [@lucian1094](https://discuss.elastic.co/u/lucian1094)\
**Post date:** [July 30, 2022, 5:09pm UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031/4 "2022-07-30T17:09:01Z")

</div>

Thank you Stephen for your answer and for your time. My bad, I didn't start the cluster because I didn't finish the settings, now I can see the elastic user. So, I think, is it enough to add elastic user in sudoers file and then to use it for start/stop elasticsearch, edit configuration files, etc. ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 5:11pm UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031/5 "2022-07-30T17:11:00Z")

</div>

> [@lucian1094](#):
>
> So, I think, is it enough to add elastic user in sudoers file and then to use it for start/stop elasticsearch, edit configuration files, etc. ?

Yes... it sounds like you are your own Linux admin, so you understand the options / risks etc.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 30, 2022, 5:41pm UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031/6 "2022-07-30T17:41:38Z")

</div>

> [@lucian1094](#):
>
> So, I think, is it enough to add elastic user in sudoers file and then to use it for start/stop elasticsearch, edit configuration files, etc. ?

As already said, there is no need for that. Also, the elasticsearch user is a nologin user, so it make no sense for it to be in sudoers.

You just need to use a normal user with sudo privileges to start/stop the elasticsearch service.

How did you install elasticsearch? How do you connect to your server?

You should have a normal user and use `sudo` to perform privileged operations, use this same user to start and stop elasticsearch with `sudo systemctl start elasticsearch` and `sudo systemctl stop elasticsearch`.

---

<div class="post-metadata">

**Author:** ![lucian1094](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucian1094/32/109048_2.png) [@lucian1094](https://discuss.elastic.co/u/lucian1094)\
**Post date:** [July 30, 2022, 6:04pm UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031/7 "2022-07-30T18:04:33Z")

</div>

I was thinking to add elastic user, not elasticsearch user. For now I just learning and testing. But now is clear for me about elasticsearch os users, thank you for your time, appreciate.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2022, 6:05pm UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031/8 "2022-08-27T18:05:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
