# Installed Kibana 5. Can only run as root

**URL:** <https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462>\
**Category:** Kibana\
**Created:** [May 19, 2017, 4:05pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462 "2017-05-19T16:05:03Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [May 19, 2017, 4:05pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/1 "2017-05-19T16:05:03Z")

</div>

If I run as root everything works fine. If I do not run as root I get the following error:

/usr/share/kibana/bin/../node/bin/node /usr/share/kibana/bin/../src/cli -c /etc/kibana/kibana.yml  
net.js:10  
const cares = process.binding('cares\_wrap');  
^  
Error: EFILE  
at Error (native)  
at net.js:10:23  
at NativeModule.compile (bootstrap\_node.js:497:7)  
at NativeModule.require (bootstrap\_node.js:438:18)  
at tty.js:4:13  
at NativeModule.compile (bootstrap\_node.js:497:7)  
at Function.NativeModule.require (bootstrap\_node.js:438:18)  
at Function.Module.\_load (module.js:426:25)  
at Module.require (module.js:497:17)  
at require (internal/module.js:20:19)

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 19, 2017, 9:37pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/2 "2017-05-19T21:37:38Z")

</div>

What method did you use to install kibana? apt, yum, binary? Did you install fresh, or was it an upgrade? Lastly, what command are you executing to run kibana?

---

<div class="post-metadata">

**Author:** ![caixiac1](https://avatars.discourse-cdn.com/v4/letter/c/67e7ee/32.png) [@caixiac1](https://discuss.elastic.co/u/caixiac1)\
**Post date:** [May 23, 2017, 7:04am UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/3 "2017-05-23T07:04:39Z")

</div>

We also met this issue, and we install kibana from fresh with yum.  
The command to run kibana is  
systemctl start kibana

---

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [May 23, 2017, 11:30am UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/4 "2017-05-23T11:30:47Z")

</div>

kibana-5.2.1-x86\_64.rpm fresh install using yum via our own repository

The command I use is in the original post. It's the same command that runs when you start it via a service interface. Ultimately that's what I want it to do (run as a service):

/usr/share/kibana/bin/../node/bin/node /usr/share/kibana/bin/../src/cli -c /etc/kibana/kibana.yml

---

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [May 23, 2017, 11:34am UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/5 "2017-05-23T11:34:58Z")

</div>

The service won't start because of the same underlying issue. That's how I got here.

As a side note this is RHEL6 so systemd is not the service initialization engine (so your command to start the service won't work). It's still using sys-v.

As a side note to the side note, Logstash uses upstart on RHEL6 for no good reason. You'd think all three would start the same way. (different topic for a different thread perhaps)

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 23, 2017, 3:38pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/6 "2017-05-23T15:38:26Z")

</div>

Are you running that command as the `kibana` user?

Also, sysV should be available: [https://www.elastic.co/guide/en/kibana/5.2/rpm.html#rpm-running-init](https://www.elastic.co/guide/en/kibana/5.2/rpm.html#rpm-running-init)

The sysv path is `/etc/init.d/kibana`

---

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [May 23, 2017, 3:54pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/7 "2017-05-23T15:54:58Z")

</div>

Sysv is available yes. I was replying to the post that said to use systemd.

EDIT: The kibana user exists. I am not trying to run the service with anything special in the config so ostensibly it's trying to run as kibana.

---

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [May 23, 2017, 7:42pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/8 "2017-05-23T19:42:38Z")

</div>

Latest...

Here is the EXACT command I use to attempt to run kibana from the command line. It gives me the same error as when I try to run kibana as a service.

sudo -H -u kibana bash -c '/usr/share/kibana/bin/../node/bin/node /usr/share/kibana/bin/../src/cli -c /etc/kibana/kibana.yml'

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 23, 2017, 8:26pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/9 "2017-05-23T20:26:30Z")

</div>

Hmmm, I'm pretty much tapped for ideas. Honestly we haven't seen this particular error before. The error seems to be thrown by Node itself. Most references to the error I'm able to find involve Windows and dns issues. Is your machine's network locked down and perhaps blocking something node needs access to? Or maybe there's an odd DNS configuration?

You could also try updating to the latest version Kibana, we've bumped node versions since 5.2.1 so maybe it'll be fixed in the latest.

---

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [May 24, 2017, 3:03pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/10 "2017-05-24T15:03:29Z")

</div>

We're locked down tighter than a kettle drum here. I'd be happy to ease restrictions but first I need to know what is breaking. The stacktrace isn't exactly helpful, as you can see.

More info: I just verified that 4.x installs and works without issue, so this has something to do with the 5.x line needing something that 4.x doesn't.

Do you have the ability to list what Node is looking for? Just a general list is fine. I'll go item-by-item to chmod 777 and see what happens.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 24, 2017, 5:46pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/11 "2017-05-24T17:46:02Z")

</div>

Since the error seems to originate from the `net` module you could try enabling debug logging on it by setting the NODE\_DEBUG environment variable. Prepend your command with `NODE_DEBUG=net`. You can list the names of other internal modules there as well in a comma delimited list, if you want to cast a larger net.

If that doesn't help you could also try enabling node's [remote debugger](https://nodejs.org/api/cli.html#cli_inspect_host_port), set a breakpoint on the [offending line](https://github.com/nodejs/node/blob/v6.9.0/lib/net.js#L10) and see if the error object contains any additional info beyond what's being printed in the console.

---

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [May 24, 2017, 5:47pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/12 "2017-05-24T17:47:49Z")

</div>

I had a similar thought.

I just ran a strace on /usr/share/kibana/bin/kibana with 0 arguments. Turns out node needs to be able to read /etc/resolv.conf (which was denied). Once I gave the kibana account read access everything worked!

Thank you for your patience and help.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 24, 2017, 6:13pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/13 "2017-05-24T18:13:10Z")

</div>

Awesome, glad you got it figured out! Using strace is a good idea, I'll have to keep that in my back pocket.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2017, 6:13pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462/14 "2017-06-21T18:13:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
