# Elasticsearch service gets killed

**URL:** <https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039>\
**Category:** Elasticsearch\
**Created:** [July 29, 2020, 11:11am UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039 "2020-07-29T11:11:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abdul\_Hameed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdul_hameed/32/46158_2.png) [@Abdul\_Hameed](https://discuss.elastic.co/u/Abdul_Hameed)\
**Post date:** [July 29, 2020, 11:11am UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/1 "2020-07-29T11:11:16Z")

</div>

Hi,

I have a setup of ELK on one server. Elasticsearch service and kibana run fine until I start the logstash service.  
When I start logstash, elasticsearch gets killed instantly and I see this error:

```auto
elasticsearch systemd[1]: elasticsearch.service: Main process exited, code=killed, status=9/KILL
elasticsearch systemd[1]: elasticsearch.service: Failed with result 'signal'.

```

I checked the journal logs and found

```auto
elasticsearch kernel: Out of memory: Kill process 5402 (java) score 556 or sacrifice child
elasticsearch kernel: Killed process 5402 (java) total-vm:12237240kB, anon-rss:8885908kB, file-rss:24300kB, shmem-rss:0kB

```

Some Configurations for reference:

```auto
cat /proc/sys/vm/swappiness
1
cat /proc/sys/vm/override
1
cat /proc/10056/limits
Limit Soft Limit Hard Limit Units     
Max cpu time unlimited unlimited seconds   
Max file size unlimited unlimited bytes     
Max data size unlimited unlimited bytes     
Max stack size 8388608 unlimited bytes     
Max core file size 0 unlimited bytes     
Max resident set unlimited unlimited bytes     
Max processes 4096 4096 processes 
Max open files 65536 65536 files     
Max locked memory unlimited unlimited bytes     
Max address space unlimited unlimited bytes     
Max file locks unlimited unlimited locks     
Max pending signals 62533 62533 signals   
Max msgqueue size 819200 819200 bytes     
Max nice priority 0 0                    
Max realtime priority 0 0                    
Max realtime timeout unlimited unlimited us   

```

What is making the system to kill the service??

Thanks and Regards  
Hameed

---

<div class="post-metadata">

**Author:** ![ness1602](https://avatars.discourse-cdn.com/v4/letter/n/848f3c/32.png) [@ness1602](https://discuss.elastic.co/u/ness1602)\
**Post date:** [July 29, 2020, 2:11pm UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/2 "2020-07-29T14:11:03Z")

</div>

This is linux OOM, so it means that you are running out of memory on this node. Add more RAM.

---

<div class="post-metadata">

**Author:** ![Abdul\_Hameed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdul_hameed/32/46158_2.png) [@Abdul\_Hameed](https://discuss.elastic.co/u/Abdul_Hameed)\
**Post date:** [July 30, 2020, 7:41pm UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/3 "2020-07-30T19:41:19Z")

</div>

I have 16GB RAM available on the server and have set the heap size as 8GB.  
When I changed the heap size to 4GB, the elasticsearch doesn't get killed now.

What could be the reason this happens?

---

<div class="post-metadata">

**Author:** ![ness1602](https://avatars.discourse-cdn.com/v4/letter/n/848f3c/32.png) [@ness1602](https://discuss.elastic.co/u/ness1602)\
**Post date:** [July 30, 2020, 8:10pm UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/4 "2020-07-30T20:10:43Z")

</div>

Hi i usually set heap to 1/3 of the machine RAM, that is the safe case.

---

<div class="post-metadata">

**Author:** ![Abdul\_Hameed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdul_hameed/32/46158_2.png) [@Abdul\_Hameed](https://discuss.elastic.co/u/Abdul_Hameed)\
**Post date:** [July 30, 2020, 8:12pm UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/5 "2020-07-30T20:12:22Z")

</div>

Ok.

I had read to set to half the size which lead me to set 8GB, guess that's wrong then.  
Will try and set it to 6GB and see what outcome I get.

Thanks for your help

---

<div class="post-metadata">

**Author:** ![ness1602](https://avatars.discourse-cdn.com/v4/letter/n/848f3c/32.png) [@ness1602](https://discuss.elastic.co/u/ness1602)\
**Post date:** [July 30, 2020, 8:46pm UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/6 "2020-07-30T20:46:01Z")

</div>

Half of RAM is max i would set it, and no more than 32GB per machine.  
I depends what else you have on that machine, if there is similar database( postgres also likes caching,etc).

---

<div class="post-metadata">

**Author:** ![Abdul\_Hameed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdul_hameed/32/46158_2.png) [@Abdul\_Hameed](https://discuss.elastic.co/u/Abdul_Hameed)\
**Post date:** [July 30, 2020, 8:47pm UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/7 "2020-07-30T20:47:22Z")

</div>

How would I go about to calculate how much RAM is needed by elasticsearch for me?

---

<div class="post-metadata">

**Author:** ![ness1602](https://avatars.discourse-cdn.com/v4/letter/n/848f3c/32.png) [@ness1602](https://discuss.elastic.co/u/ness1602)\
**Post date:** [July 31, 2020, 5:14am UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/8 "2020-07-31T05:14:07Z")

</div>

That entirely based on your systems, i usually have script that reserves 30% of RAM to heap, and then i leave the rest for the system and other programs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2020, 5:14am UTC](https://discuss.elastic.co/t/elasticsearch-service-gets-killed/243039/9 "2020-08-28T05:14:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
