# ES service keeps crashing

**URL:** <https://discuss.elastic.co/t/es-service-keeps-crashing/250661>\
**Category:** Elasticsearch\
**Created:** [October 1, 2020, 11:40am UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661 "2020-10-01T11:40:38Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 1, 2020, 11:40am UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/1 "2020-10-01T11:40:38Z")

</div>

Hi,

Just realised that after I start the service for Elastic it stops running after about 2 minutes. Checked the event logs and see some errors:

> Application: elasticsearch.exe  
> Framework Version: v4.0.30319  
> Description: The process was terminated due to an unhandled exception.  
> Exception Info: Elastic.ProcessHosts.Process.StartupException  
> at Elastic.ProcessHosts.Process.ProcessBase.HandleException(System.Exception)  
> at System.Reactive.ObserverBase`1[[System.__Canon, mscorlib, Version=[4.0.0.0](https://4.0.0.0/), Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnError(System.Exception) at System.Reactive.Observer`1[[System.\_\_Canon, mscorlib, Version=[4.0.0.0](https://4.0.0.0/), Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnError(System.Exception)  
> at System.Reactive.Linq.ObservableImpl.AsObservable`1+_[[System.__Canon, mscorlib, Version=[4.0.0.0](https://4.0.0.0/), Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnError(System.Exception) at System.Reactive.AutoDetachObserver`1[[System.\_\_Canon, mscorlib, Version=[4.0.0.0](https://4.0.0.0/), Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnErrorCore(System.Exception)  
> at System.Reactive.ObserverBase`1[[System.__Canon, mscorlib, Version=[4.0.0.0](https://4.0.0.0/), Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnError(System.Exception) at Elastic.ProcessHosts.Process.ObservableProcess+<>c__DisplayClass22_0.<CreateProcessExitSubscription>b__0(System.Reactive.EventPattern`1\<System.Object\>)  
> at System.Reactive.AnonymousSafeObserver`1[[System.\_\_Canon, mscorlib, Version=[4.0.0.0](https://4.0.0.0/), Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnNext(System.\_\_Canon)  
> at System.EventHandler.Invoke(System.Object, System.EventArgs)  
> at System.Diagnostics.Process.OnExited()  
> at System.Diagnostics.Process.RaiseOnExited()  
> at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)  
> at [System.Threading.ExecutionContext.Run](https://system.threading.executioncontext.run/)(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)  
> at System.Threading.\_ThreadPoolWaitOrTimerCallback.PerformWaitOrTimerCallback(System.Object, Boolean)

2nd Error:

> Faulting application name: elasticsearch.exe, version: [7.9.2.0](https://7.9.2.0/), time stamp: 0x5f6ac09d  
> Faulting module name: KERNELBASE.dll, version: 10.0.17763.1432, time stamp: 0x9b30685b  
> Exception code: 0xe0434352  
> Fault offset: 0x0000000000039689  
> Faulting process id: 0x24c4  
> Faulting application start time: 0x01d697e4a6848d22  
> Faulting application path: D:\Elastic\Elastic-7.9.2\7.9.2\bin\elasticsearch.exe  
> Faulting module path: C:\Windows\System32\KERNELBASE.dll  
> Report Id: 979054f3-f60a-40f3-9875-a651c3139d00  
> Faulting package full name:  
> Faulting package-relative application ID:

Any thoughts?

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 1, 2020, 2:36pm UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/2 "2020-10-01T14:36:35Z")

</div>

Would you able to share the logs from elasticsearch?

Elasticsearch logs for windows usually store at `%ALLUSERSPROFILE%\Elastic\Elasticsearch\logs`

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 1, 2020, 2:48pm UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/3 "2020-10-01T14:48:55Z")

</div>

Think I found the problem, I have network.host: "0.0.0.0" in the elasticsearch.yml file, and when that is valid, the service crashes, if I # it out, it runs fine.  
Would Logstash still be able to send logs to ES even if this field is not working? Logstash is installed on another server

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 1, 2020, 2:59pm UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/4 "2020-10-01T14:59:18Z")

</div>

> Would Logstash still be able to send logs to ES even if this field is not working? Logstash is installed on another server

Sorry I'm not too sure on this.

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 1, 2020, 3:40pm UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/5 "2020-10-01T15:40:44Z")

</div>

OK cool, what about how to resolve the issue of allowing other servers to access the ES server, as obviously, it defaults to localhost which won't work from another server

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 1, 2020, 3:55pm UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/6 "2020-10-01T15:55:32Z")

</div>

Can you share your elasticsearch.yml ?

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 1, 2020, 3:59pm UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/7 "2020-10-01T15:59:25Z")

</div>

Sure:

```auto
    bootstrap.memory_lock: false
    cluster.name: Elastic
    http.port: 9200
    node.data: true
    node.ingest: true
    node.master: true
    node.max_local_storage_nodes: 1
    node.name: SV-MSE-ELTC-001
    path.data: D:\Elastic\Elastic-7.9.2\Data
    path.logs: D:\Elastic\Elastic-7.9.2\Logs
    transport.tcp.port: 9300
    xpack.license.self_generated.type: basic
    xpack.security.enabled: false
    #network.host: "0.0.0.0"

```

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 1, 2020, 4:30pm UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/8 "2020-10-01T16:30:08Z")

</div>

> [@ES service keeps crashing](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/2):
>
> Would you able to share the logs from elasticsearch? Elasticsearch logs for windows usually store at %ALLUSERSPROFILE%\Elastic\Elasticsearch\logs

Sorry, what about the logs?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 1, 2020, 10:57pm UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/9 "2020-10-01T22:57:27Z")

</div>

If [this](https://www.reddit.com/r/elasticsearch/comments/j36ram/elastic_service_crashing/) is your reddit thread, then it looks like you had `server.host` in your `elasticsearch.yml`, which is not a valid setting.

If you have added `network.host` and it's not working, please provide the Elasticsearch logs.

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 2, 2020, 10:23am UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/10 "2020-10-02T10:23:01Z")

</div>

Hi, Thanks, logs are below:

```auto
[2020-10-02T11:06:01,706][INFO][o.e.p.PluginsService] [SV-MSE-ELTC-001] no plugins loaded
[2020-10-02T11:06:02,472][INFO][o.e.e.NodeEnvironment] [SV-MSE-ELTC-001] using [1] data paths, mounts [[Elastic (D:)]], net usable_space [196.5gb], net total_space [199.9gb], types [NTFS]
[2020-10-02T11:06:02,472][INFO][o.e.e.NodeEnvironment] [SV-MSE-ELTC-001] heap size [2gb], compressed ordinary object pointers [true]
[2020-10-02T11:06:02,878][INFO][o.e.n.Node] [SV-MSE-ELTC-001] node name [SV-MSE-ELTC-001], node ID [8xNypMzjRF2ZRibK0rgABA], cluster name [Elastic]
[2020-10-02T11:06:07,843][INFO][o.e.x.m.p.l.CppLogMessageHandler] [SV-MSE-ELTC-001] [controller/6740] [Main.cc@114] controller (64 bit): Version 7.9.2 (Build 6a60f0cf2dd5a5) Copyright (c) 2020 Elasticsearch BV
[2020-10-02T11:06:09,417][INFO][o.e.t.NettyAllocator] [SV-MSE-ELTC-001] creating NettyAllocator with the following configs: [name=elasticsearch_configured, chunk_size=256kb, factors={es.unsafe.use_netty_default_chunk_and_page_size=false, g1gc_enabled=true, g1gc_region_size=1mb}]
[2020-10-02T11:06:09,514][INFO][o.e.d.DiscoveryModule] [SV-MSE-ELTC-001] using discovery type [zen] and seed hosts providers [settings]
[2020-10-02T11:06:09,985][WARN][o.e.g.DanglingIndicesState] [SV-MSE-ELTC-001] gateway.auto_import_dangling_indices is disabled, dangling indices will not be automatically detected or imported and must be managed manually
[2020-10-02T11:06:10,347][INFO][o.e.n.Node] [SV-MSE-ELTC-001] initialized
[2020-10-02T11:06:10,347][INFO][o.e.n.Node] [SV-MSE-ELTC-001] starting ...
[2020-10-02T11:06:10,585][INFO][o.e.t.TransportService] [SV-MSE-ELTC-001] publish_address {10.103.186.210:9300}, bound_addresses {[::]:9300}
[2020-10-02T11:06:11,057][INFO][o.e.b.BootstrapChecks] [SV-MSE-ELTC-001] bound or publishing to a non-loopback address, enforcing bootstrap checks
[2020-10-02T11:06:11,057][ERROR][o.e.b.Bootstrap] [SV-MSE-ELTC-001] node validation exception
[1] bootstrap checks failed
[1]: the default discovery settings are unsuitable for production use; at least one of [discovery.seed_hosts, discovery.seed_providers, cluster.initial_master_nodes] must be configured
[2020-10-02T11:06:11,072][INFO][o.e.n.Node] [SV-MSE-ELTC-001] stopping ...
[2020-10-02T11:06:11,081][INFO][o.e.n.Node] [SV-MSE-ELTC-001] stopped
[2020-10-02T11:06:11,081][INFO][o.e.n.Node] [SV-MSE-ELTC-001] closing ...
[2020-10-02T11:06:11,097][INFO][o.e.n.Node] [SV-MSE-ELTC-001] closed
[2020-10-02T11:06:11,097][INFO][o.e.x.m.p.NativeController] [SV-MSE-ELTC-001] Native controller process has stopped - no new native processes can be started

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 2, 2020, 10:34am UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/11 "2020-10-02T10:34:45Z")

</div>

```auto
[1] bootstrap checks failed
[1]: the default discovery settings are unsuitable for production use; at least one of [discovery.seed_hosts, discovery.seed_providers, cluster.initial_master_nodes] must be configured

```

Please read [https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html)

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 2, 2020, 10:38am UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/12 "2020-10-02T10:38:48Z")

</div>

Literally just resolved this due to that error, thanks a lot. I added the following into the YML file:

```auto
discovery.seed_hosts: []
discovery.type: single-node

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2020, 10:38am UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661/13 "2020-10-30T10:38:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
