# Fresh ELK setup.. no http?

**URL:** <https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576>\
**Category:** Elasticsearch\
**Created:** [November 1, 2016, 3:10pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576 "2016-11-01T15:10:37Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 3:10pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/1 "2016-11-01T15:10:37Z")

</div>

Following here: [https://www.elastic.co/guide/en/elastic-stack/current/installing-elastic-stack.html](https://www.elastic.co/guide/en/elastic-stack/current/installing-elastic-stack.html) And I've gotten elasticsearch, kibana, logstash and teh x-pack installed but no http when I hit teh servers IP. It's likely something trivial and stupid that I've missed but I can't find it.  
Can ping the ip just fine, however nmap shows only 22 and 25 open. What'd I miss?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 1, 2016, 3:14pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/2 "2016-11-01T15:14:35Z")

</div>

Did you forget do adjust the `network.host` option to have ES listen on non-loopback interfaces?

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 3:16pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/3 "2016-11-01T15:16:19Z")

</div>

Well I tried both the default 127.0.0.1 then when that didnt work I change it to the current IP on the only ethernet interface on this vm. Still go bueno.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 1, 2016, 3:17pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/4 "2016-11-01T15:17:18Z")

</div>

Have you verified that ES actually starts up?

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 3:43pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/5 "2016-11-01T15:43:08Z")

</div>

Hmm well it starts fine, until I try to hit the interface, then it bombs out with the same error I had yesterday:

[mtops@localhost elasticsearch]$ systemctl status elasticsearch  
● elasticsearch.service - Elasticsearch  
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled)  
Active: failed (Result: exit-code) since Tue 2016-11-01 09:41:46 MDT; 3s ago  
Docs: [http://www.elastic.co](http://www.elastic.co)  
Process: 2692 ExecStart=/usr/share/elasticsearch/bin/elasticsearch -p ${PID\_DIR}/elasticsearch.pid --quiet -Edefault.path.logs=${LOG\_DIR} -Edefault.path.data=${DATA\_DIR} -Edefault.path.conf=${CONF\_DIR} (code=exited, status=1/FAILURE)  
Process: 2690 ExecStartPre=/usr/share/elasticsearch/bin/elasticsearch-systemd-pre-exec (code=exited, status=0/SUCCESS)  
Main PID: 2692 (code=exited, status=1/FAILURE)

Nov 01 09:41:44 localhost.localdomain elasticsearch[2692]: 2016-11-01 09:41:43,988 main ERROR Null object returned for RollingFile in Appenders.  
Nov 01 09:41:44 localhost.localdomain elasticsearch[2692]: 2016-11-01 09:41:43,989 main ERROR Null object returned for RollingFile in Appenders.  
Nov 01 09:41:44 localhost.localdomain elasticsearch[2692]: 2016-11-01 09:41:43,989 main ERROR Unable to locate appender "rolling" for logger config "root"  
Nov 01 09:41:44 localhost.localdomain elasticsearch[2692]: 2016-11-01 09:41:43,990 main ERROR Unable to locate appender "index\_indexing\_slowlog\_rolling" for logger config "index.index...wlog.index"  
Nov 01 09:41:44 localhost.localdomain elasticsearch[2692]: 2016-11-01 09:41:43,990 main ERROR Unable to locate appender "audit\_rolling" for logger config "org.elasticsearch.xpack.secu...AuditTrail"  
Nov 01 09:41:44 localhost.localdomain elasticsearch[2692]: 2016-11-01 09:41:43,995 main ERROR Unable to locate appender "index\_search\_slowlog\_rolling" for logger config "index.search.slowlog"  
Nov 01 09:41:44 localhost.localdomain elasticsearch[2692]: 2016-11-01 09:41:43,996 main ERROR Unable to locate appender "deprecation\_rolling" for logger config "org.elasticsearch.deprecation"  
Nov 01 09:41:46 localhost.localdomain systemd[1]: elasticsearch.service: main process exited, code=exited, status=1/FAILURE  
Nov 01 09:41:46 localhost.localdomain systemd[1]: Unit elasticsearch.service entered failed state.  
Nov 01 09:41:46 localhost.localdomain systemd[1]: elasticsearch.service failed.  
Hint: Some lines were ellipsized, use -l to show in full.

Yesterday it would not start at all until I commented out the x-pack line:

action.auto\_create\_index: .security,.monitoring\*,.watches,.triggered\_watches,.watcher-history\*

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 4:10pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/6 "2016-11-01T16:10:09Z")

</div>

Can't find much on this but it seems to be Java related.

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 4:44pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/7 "2016-11-01T16:44:47Z")

</div>

Ok Magnus.. ignore the above entries. Those were indeed caused by a typo in the /var/log path. SO back to what I hope is the actual problem.

Now when starting ES and checking the status I get:

[mtops@localhost elasticsearch]$ systemctl status elasticsearch -l  
● elasticsearch.service - Elasticsearch  
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled)  
Active: failed (Result: exit-code) since Tue 2016-11-01 10:32:09 MDT; 14s ago  
Docs: [http://www.elastic.co](http://www.elastic.co)  
Process: 5916 ExecStart=/usr/share/elasticsearch/bin/elasticsearch -p ${PID\_DIR}/elasticsearch.pid --quiet -Edefault.path.logs=${LOG\_DIR} -Edefault.path.data=${DATA\_DIR} -Edefault.path.conf=${CONF\_DIR} (code=exited, status=1/FAILURE)  
Process: 5914 ExecStartPre=/usr/share/elasticsearch/bin/elasticsearch-systemd-pre-exec (code=exited, status=0/SUCCESS)  
Main PID: 5916 (code=exited, status=1/FAILURE)

Nov 01 10:31:52 localhost.localdomain systemd[1]: Starting Elasticsearch...  
Nov 01 10:31:52 localhost.localdomain systemd[1]: Started Elasticsearch.  
Nov 01 10:32:09 localhost.localdomain systemd[1]: elasticsearch.service: main process exited, code=exited, status=1/FAILURE  
Nov 01 10:32:09 localhost.localdomain systemd[1]: Unit elasticsearch.service entered failed state.  
Nov 01 10:32:09 localhost.localdomain systemd[1]: elasticsearch.service failed.  
[mtops@localhost elasticsearch]$

Stopping and restarting according to journalctl:

Nov 01 10:36:37 localhost.localdomain sudo[6578]: mtops : TTY=pts/1 ; PWD=/etc/elasticsearch ; USER=root ; COMMAND=/bin/systemctl start elasticsearch  
Nov 01 10:36:37 localhost.localdomain polkitd[658]: Registered Authentication Agent for unix-process:6579:7437717 (system bus name :1.109 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en\_US.UTF-8)  
Nov 01 10:36:37 localhost.localdomain systemd[1]: Starting Elasticsearch...  
Nov 01 10:36:37 localhost.localdomain systemd[1]: Started Elasticsearch.  
Nov 01 10:36:37 localhost.localdomain polkitd[658]: Unregistered Authentication Agent for unix-process:6579:7437717 (system bus name :1.109, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en\_US.UTF-8) (disconnected from bus)  
Nov 01 10:36:59 localhost.localdomain systemd[1]: elasticsearch.service: main process exited, code=exited, status=1/FAILURE  
Nov 01 10:36:59 localhost.localdomain systemd[1]: Unit elasticsearch.service entered failed state.  
Nov 01 10:36:59 localhost.localdomain systemd[1]: elasticsearch.service failed.

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 9:46pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/8 "2016-11-01T21:46:46Z")

</div>

Still having this weird issue. Updated Java to 8u111, no help.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 2, 2016, 8:25am UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/9 "2016-11-02T08:25:03Z")

</div>

Check your actual ES logs.

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 2, 2016, 1:11pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/10 "2016-11-02T13:11:45Z")

</div>

/var/log/elasticsearch.log yes?

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 2, 2016, 3:08pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/11 "2016-11-02T15:08:04Z")

</div>

Looking at this log, seems there's no entries since 10/31 when it was installed the last time.

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 2, 2016, 4:35pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/12 "2016-11-02T16:35:13Z")

</div>

Did I find some unknown bug or just being an idiot and missing an obvious correction? Usually I'd go with the latter but people are typically all to quick to point out a mistake, lol.

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 2, 2016, 9:54pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/13 "2016-11-02T21:54:51Z")

</div>

Seems this issue has grown stale. So I went looking for a resolution to my Kibana issue and found great help. It seems that Kibana 5 doesnt want to start unless it can read the ES url.

And since I followed the Elastic guide on setting up an ELK stack in version 5.0 my system has been broken. Here is a pastebin of my Es startup issue and a couple things I did to try to remedy it.

[http://pastebin.com/0WEZ26eM](http://pastebin.com/0WEZ26eM)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 2, 2016, 10:19pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/14 "2016-11-02T22:19:36Z")

</div>

> [@skeer](#):
>
> /var/log/elasticsearch.log yes?

Depends, did you change `cluster.name`?

> [@skeer](#):
>
> Seems this issue has grown stale.

What do you mean?

> [@skeer](#):
>
> It seems that Kibana 5 doesnt want to start unless it can read the ES url.

Read the URL how? KB will start if if cannot connect to ES, it'll just sit there waiting for the cluster to become available if it's not. If you have a bad config setting, that may cause KB to not start.

> [@skeer](#):
>
> And since I followed the Elastic guide on setting up an ELK stack in version 5.0 my system has been broken.

Which guide?

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 2, 2016, 10:23pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/15 "2016-11-02T22:23:59Z")

</div>

> [@warkolm](#):
>
> Depends, did you change cluster.name?

I did, it's changed to "gntc\_elk"

> [@warkolm](#):
>
> Seems this issue has grown stale.

That's me getting too anxious for a resolution.

> [@warkolm](#):
>
> Read the URL how? KB will start if if cannot connect to ES, it'll just sit there waiting for the cluster to become available if it's not. If you have a bad config setting, that may cause KB to not start.

Take a look at the pastebin link I embedded earlier.. That's kinda why I did that to show anyone what's going on.[quote="warkolm, post:14, topic:64576"]  
And since I followed the Elastic guide on setting up an ELK stack in version 5.0 my system has been broken.  
[/quote]

The url in my very first post in this thread. The official Elastic guide.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 2, 2016, 10:28pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/16 "2016-11-02T22:28:05Z")

</div>

> [@skeer](#):
>
> I did, it's changed to "gntc\_elk"

Ok, cause if so the log will be named accordingly, as it's based on that cluster name.

How did you install things though, using packages or tar?

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 2, 2016, 10:30pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/17 "2016-11-02T22:30:39Z")

</div>

First time thru RPM's only. After I ran into issues I went for the tarballs.

I see about the log.. did not know that. Inspecting the contents though it's teh exact same messages as my last pastebin above. A bunch of java BS.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:07pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576/18 "2017-07-05T22:07:09Z")

</div>


