# How to stop filebeat running under non-root account - other than kill

**URL:** <https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 30, 2016, 9:55pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471 "2016-06-30T21:55:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [June 30, 2016, 9:55pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/1 "2016-06-30T21:55:30Z")

</div>

Is there a way to send shutdown/reboot signal to filebeat running under non-root account? From root account service filebeat restart/stop/start works great - but from non-root account?

Thanks,  
Zoran

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 1, 2016, 3:49am UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/2 "2016-07-01T03:49:58Z")

</div>

I suggest you use sudo to grant the user in question specific permissions to run the needed commands.

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 1, 2016, 12:28pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/3 "2016-07-01T12:28:58Z")

</div>

Yes we did that in few cases but it becomes impractical on large scale; would be good to have different option in this case - maybe password protected signal on specific port.

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 1, 2016, 5:59pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/4 "2016-07-01T17:59:05Z")

</div>

> Yes we did that in few cases but it becomes impractical on large scale

How so?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 1, 2016, 6:46pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/5 "2016-07-01T18:46:16Z")

</div>

it's on purpose the OS does not allow user X killing processes run by user Y.

You need to run filebeat as root? If so, any other user should not be allowed to kill the process. This is not filebeat specific, but provided by OS.

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 3, 2016, 7:13pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/6 "2016-07-03T19:13:05Z")

</div>

it is the other way around - due to the need to deploy this to large number  
of VMs where we do not have root access, it would be deployed under  
separate account - say filebeat, in filebeat group. In that case I assume  
it could not be run as service ( there are workarounds but they seem to at  
least require sudo setup of some kind - which again is impractical for  
large number of different purpose VMs) - so in that case filebeat could be  
started with nohup into the background, but in that case there is no way to  
stop it - other than kill. Not sure if that could cause any issues with  
filebeat after it is restarted.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 4, 2016, 5:29am UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/7 "2016-07-04T05:29:43Z")

</div>

> but in that case there is no way to stop it - other than kill. Not sure if that could cause any issues with filebeat after it is restarted.

Just kill it with a normal SIGTERM. That's the normal way of stopping processes and it's what happens when processes run as daemons/services are stopped. Killing it with SIGKILL should be avoided, just like with any other program.

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 5, 2016, 4:40pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/8 "2016-07-05T16:40:58Z")

</div>

Thank you - so basically using regular 'kill' command as opposed to kill -9 ...

Thanks,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2016, 9:56pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-running-under-non-root-account-other-than-kill/54471/9 "2016-07-21T21:56:05Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
