# Elasticsearch running as service on Ubuntu is failing

**URL:** <https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505>\
**Category:** Elasticsearch\
**Created:** [June 12, 2019, 7:59pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505 "2019-06-12T19:59:13Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 12, 2019, 7:59pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/1 "2019-06-12T19:59:13Z")

</div>

I am trying to run elastisearch as a service on an ubuntu server but it keeps failing and I can't figure out what is wrong. Never installed elasticsearch on an ubuntu server. Version is 6.7.1

P.S. [server.com](http://server.com) isnt the name of the server just for security purposes.

● elasticsearch.service - Elasticsearch  
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)  
Active: failed (Result: exit-code) since Wed 2019-06-12 15:55:12 EDT; 6s ago  
Docs: [http://www.elastic.co](http://www.elastic.co)  
Process: 3889 ExecStart=/usr/share/elasticsearch/bin/elasticsearch -p ${PID\_DIR}/elasticsearch.pid --quiet (code=exited, status=1/FAILURE)  
Main PID: 3889 (code=exited, status=1/FAILURE)

Jun 12 15:55:12 [server.com](http://server.com) systemd[1]: Started Elasticsearch.  
Jun 12 15:55:12 [server.com](http://server.com) systemd[1]: elasticsearch.service: Main process exited, code=exited, status=1/FAILURE  
Jun 12 15:55:12 [server.com](http://server.com) systemd[1]: elasticsearch.service: Unit entered failed state.  
Jun 12 15:55:12 [server.com](http://server.com) systemd[1]: elasticsearch.service: Failed with result 'exit-code'.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 12, 2019, 10:03pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/2 "2019-06-12T22:03:29Z")

</div>

What do your actual Elasticsearch logs show?

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 12, 2019, 10:50pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/3 "2019-06-12T22:50:40Z")

</div>

Java HotSpot(TM) 64-Bit Server VM (25.212-b25) for linux-amd64 JRE (1.8.0\_212-b25), built on Apr 3 2019 01:21:17 by "fedora" with gcc 7.3.0  
Memory: 4k page, physical 16414324k(15081116k free), swap 7999484k(7999484k free)  
CommandLine flags: -XX:+AlwaysPreTouch -XX:CMSInitiatingOccupancyFraction=75 -XX:ErrorFile=/var/log/elasticsearch/hs\_err\_pid%p.log -XX:GCLogFileSize=67108864 -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=/var/lib/elasticsearch -XX:InitialHeapSize=1073741824 -XX:MaxHeapSize=1073741824 -XX:MaxNewSize=357916672 -XX:MaxTenuringThreshold=6 -XX:NewSize=357916672 -XX:NumberOfGCLogFiles=32 -XX:OldPLABSize=16 -XX:OldSize=715825152 -XX:-OmitStackTraceInFastThrow -XX:+PrintGC -XX:+PrintGCApplicationStoppedTime -XX:+PrintGCDateStamps -XX:+PrintGCDetails -XX:+PrintGCTimeStamps -XX:+PrintTenuringDistribution -XX:ThreadStackSize=1024 -XX:+UseCMSInitiatingOccupancyOnly -XX:+UseCompressedClassPointers -XX:+UseCompressedOops -XX:+UseConcMarkSweepGC -XX:+UseGCLogFileRotation -XX:+UseParNewGC  
2019-06-12T17:05:08.254-0400: 0.956: Total time for which application threads were stopped: 0.0001153 seconds, Stopping threads took: 0.0000515 seconds  
2019-06-12T17:05:08.752-0400: 1.454: Total time for which application threads were stopped: 0.0001096 seconds, Stopping threads took: 0.0000321 seconds  
2019-06-12T17:05:08.863-0400: 1.565: Total time for which application threads were stopped: 0.0001020 seconds, Stopping threads took: 0.0000353 seconds  
2019-06-12T17:05:09.036-0400: 1.738: Total time for which application threads were stopped: 0.0001421 seconds, Stopping threads took: 0.0000315 seconds  
2019-06-12T17:05:10.004-0400: 2.706: Total time for which application threads were stopped: 0.0002291 seconds, Stopping threads took: 0.0000401 seconds  
2019-06-12T17:05:10.005-0400: 2.707: Total time for which application threads were stopped: 0.0000891 seconds, Stopping threads took: 0.0000257 seconds  
2019-06-12T17:05:10.126-0400: 2.828: Total time for which application threads were stopped: 0.0001742 seconds, Stopping threads took: 0.0000333 seconds  
2019-06-12T17:05:10.504-0400: 3.206: Total time for which application threads were stopped: 0.0001853 seconds, Stopping threads took: 0.0000359 seconds  
2019-06-12T17:05:11.300-0400: 4.002: Total time for which application threads were stopped: 0.0002929 seconds, Stopping threads took: 0.0000503 seconds  
2019-06-12T17:05:11.709-0400: 4.411: Total time for which application threads were stopped: 0.0002584 seconds, Stopping threads took: 0.0000356 seconds  
2019-06-12T17:05:11.837-0400: 4.540: Total time for which application threads were stopped: 0.0002854 seconds, Stopping threads took: 0.0000647 seconds  
2019-06-12T17:05:11.950-0400: 4.652: Total time for which application threads were stopped: 0.0002640 seconds, Stopping threads took: 0.0000317 seconds  
2019-06-12T17:05:11.988-0400: 4.690: Total time for which application threads were stopped: 0.0002092 seconds, Stopping threads took: 0.0000291 seconds  
2019-06-12T17:05:12.018-0400: 4.720: Total time for which application threads were stopped: 0.0001035 seconds, Stopping threads took: 0.0000723 seconds  
2019-06-12T17:05:12.018-0400: 4.720: Total time for which application threads were stopped: 0.0000763 seconds, Stopping threads took: 0.0000406 seconds  
2019-06-12T17:05:12.018-0400: 4.720: Total time for which application threads were stopped: 0.0000727 seconds, Stopping threads took: 0.0000467 seconds  
2019-06-12T17:05:12.018-0400: 4.720: Total time for which application threads were stopped: 0.0000737 seconds, Stopping threads took: 0.0000462 seconds  
2019-06-12T17:05:12.019-0400: 4.721: Total time for which application threads were stopped: 0.0001295 seconds, Stopping threads took: 0.0001025 seconds  
Heap  
par new generation total 314560K, used 95093K [0x00000000c0000000, 0x00000000d5550000, 0x00000000d5550000)  
eden space 279616K, 34% used [0x00000000c0000000, 0x00000000c5cdd690, 0x00000000d1110000)  
from space 34944K, 0% used [0x00000000d1110000, 0x00000000d1110000, 0x00000000d3330000)  
to space 34944K, 0% used [0x00000000d3330000, 0x00000000d3330000, 0x00000000d5550000)  
concurrent mark-sweep generation total 699072K, used 0K [0x00000000d5550000, 0x0000000100000000, 0x0000000100000000)  
Metaspace used 16843K, capacity 17358K, committed 17664K, reserved 1064960K  
class space used 2020K, capacity 2201K, committed 2304K, reserved 1048576K

This is what I get from the gc.log.0.current file

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 12, 2019, 10:52pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/4 "2019-06-12T22:52:42Z")

</div>

Please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

What is in `/var/log/elasticsearch/elasticsearch.log` ?

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 12, 2019, 10:56pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/5 "2019-06-12T22:56:32Z")

</div>

Sorry about that. And the only thing in that folder is the gc.log.0.current file there is no elasticsearch.log file

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 12, 2019, 10:58pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/6 "2019-06-12T22:58:45Z")

</div>

What about `systemctl status elasticsearch`?

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 12, 2019, 11:01pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/7 "2019-06-12T23:01:20Z")

</div>

When I do that I get the error message I included in the first message

---

<div class="post-metadata">

**Author:** ![Dr\_Ramin\_Sadr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dr_ramin_sadr/32/48008_2.png) [@Dr\_Ramin\_Sadr](https://discuss.elastic.co/u/Dr_Ramin_Sadr)\
**Post date:** [June 12, 2019, 11:12pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/8 "2019-06-12T23:12:47Z")

</div>

I had the same problem and fixed it by setting PID\_DIR in the yml file.

I got it running but it crashes in 30 seconds or less. Cannot figure it out yet

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 12, 2019, 11:36pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/9 "2019-06-12T23:36:43Z")

</div>

Also, when attempting to run it not as a service. It says gives a warning 'Failing back to Java on path. This behavior is deprecated. Specify JAVA\_HOME.'

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 13, 2019, 12:00am UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/10 "2019-06-13T00:00:28Z")

</div>

Ok how did you install things?

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 13, 2019, 12:09am UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/11 "2019-06-13T00:09:16Z")

</div>

If i create the elasticsearch directory under /var/run/ should the elasticsearch user own it or root? Also should i create the elasticsearch.pid file? Or will that automatically be created by itself?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 13, 2019, 12:21am UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/12 "2019-06-13T00:21:31Z")

</div>

How did you install things - deb via apt?

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 13, 2019, 12:31am UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/13 "2019-06-13T00:31:32Z")

</div>

I assume it was. I didn't install it and the person who did is unreachable at the moment. How could I figure this out, if necessary?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 13, 2019, 12:59am UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/14 "2019-06-13T00:59:56Z")

</div>

If you're on Ubuntu then check `/etc/apt/sources.list.d/` for any mention of `elastic`.  
Otherwise check `dpkg -l|grep elasticsearch`.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 13, 2019, 2:37am UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/15 "2019-06-13T02:37:46Z")

</div>

I checked the sources.list.d folder but did not see anything related to elastic. For the second command I got this:

> ii elasticsearch-oss 6.7.1 all Elasticsearch is a distributed RESTful search engine built for the cloud. Reference documentation can be found at [Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/index.html) and the 'Elasticsearch: The Definitive Guide' book can be found at [Elasticsearch: The Definitive Guide [2.x] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/current/index.html)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 13, 2019, 3:55am UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/16 "2019-06-13T03:55:38Z")

</div>

Please don't post pictures of text, they are difficult to read, impossible to search and some people may not be even able to see them 🙂

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 13, 2019, 12:58pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/17 "2019-06-13T12:58:47Z")

</div>

Ok I changed it and it was through dpkg that elasticsearch was installed.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [June 13, 2019, 10:28pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/18 "2019-06-13T22:28:07Z")

</div>

Any other information I can provide to maybe to shorten the list of possible sources of the issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2019, 10:32pm UTC](https://discuss.elastic.co/t/elasticsearch-running-as-service-on-ubuntu-is-failing/185505/19 "2019-07-11T22:32:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
