# Log4j errors when starting ES

**URL:** <https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484>\
**Category:** Elasticsearch\
**Created:** [October 31, 2016, 7:06pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484 "2016-10-31T19:06:48Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [October 31, 2016, 7:06pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/1 "2016-10-31T19:06:48Z")

</div>

Hello, I am installing the new ES and i keep recieving these errors on start.  
main ERROR Null object returned for RollingFile in Appenders.

Oct 31 19:01:40 elasticsearch[18779]: 2016-10-31 19:01:40,165 main ERROR Null object returned for RollingFile in Appenders.  
Oct 31 19:01:40 elasticsearch[18779]: 2016-10-31 19:01:40,165 main ERROR Null object returned for RollingFile in Appenders.  
Oct 31 19:01:40 elasticsearch[18779]: 2016-10-31 19:01:40,166 main ERROR Unable to locate appender "index\_indexing\_slowlog\_rolling" for logger config "index.indexing.slowlog.index"  
Oct 31 19:01:40 elasticsearch[18779]: 2016-10-31 19:01:40,166 main ERROR Unable to locate appender "audit\_rolling" for logger config "org.elasticsearch.xpack.security.audit.logfile.LoggingAuditTrail"  
Oct 31 19:01:40 elasticsearch[18779]: 2016-10-31 19:01:40,166 main ERROR Unable to locate appender "index\_search\_slowlog\_rolling" for logger config "index.search.slowlog"

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [October 31, 2016, 7:19pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/2 "2016-10-31T19:19:37Z")

</div>

How did you install ES and how did you start it? If you used the rpm or deb make sure you use systemd or the init script or you might end up with weird, weird, paths breaking things.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [October 31, 2016, 8:07pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/3 "2016-10-31T20:07:56Z")

</div>

i used the RPM. Service elasticsearch start was what i ran

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [October 31, 2016, 9:14pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/4 "2016-10-31T21:14:29Z")

</div>

Weird! Can you make a gist of `find /usr/share/elasticsearch` and `find /etc/elasticsearch` ?

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [October 31, 2016, 9:36pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/5 "2016-10-31T21:36:00Z")

</div>

I have the exact same error (after wiping my virtual board clean and starting over with ver 5)

If I comment out this line from my elasticsearch.yml file  
: _action.auto\_create\_index: .security,.monitoring\*,.watches,.triggered\_watches,.watcher-history\*_

Then my elasticsearch daemon starts just fine. I have a feeling the X-pack instructions are missing something. Page I'm talking about here: [https://www.elastic.co/guide/en/x-pack/5.0/installing-xpack.html](https://www.elastic.co/guide/en/x-pack/5.0/installing-xpack.html) Step 3.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [November 1, 2016, 2:46pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/6 "2016-11-01T14:46:53Z")

</div>

How would you like me to send the findings of each? They are pretty big to paste here.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [November 1, 2016, 2:47pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/7 "2016-11-01T14:47:13Z")

</div>

I tried this and still the same issue.

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 2:58pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/8 "2016-11-01T14:58:38Z")

</div>

Weird.. that solved mine. Although I have something else going on now that I'll start a new thread on.

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 3:51pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/9 "2016-11-01T15:51:20Z")

</div>

OK I lied.. this error returns but only after I try hitting the web interface once. Then it kills the ES process.

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 4:24pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/10 "2016-11-01T16:24:38Z")

</div>

Since my error mimics teh OP's I think it'd be best to keep the info close by. Here's a tail of journalctl -f when i start elasticsearch. It's wordy so be warned.

[http://pastebin.com/G1siCD1Z](http://pastebin.com/G1siCD1Z)

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [November 1, 2016, 4:29pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/11 "2016-11-01T16:29:17Z")

</div>

your issue looks like a permission issue for the file path /var/log/eleasticsearch/gntc\_elk.log

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 4:32pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/12 "2016-11-01T16:32:51Z")

</div>

I did just find that typo. _blasted fat fingers_ I fixed that, stopped then restarted ES to no avail. Different error now though so maybe OP typo'd the yml.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 1, 2016, 4:51pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/13 "2016-11-01T16:51:23Z")

</div>

Maybe you can share the output as a [gist](https://gist.github.com/) or pastebin? Also, can you provide your elasticsearch.yml (stripping any sensitive info) and any modifications made to the logging file?

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [November 1, 2016, 6:22pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/14 "2016-11-01T18:22:51Z")

</div>

[http://pastebin.com/naaKFhzW](http://pastebin.com/naaKFhzW)

[http://pastebin.com/E6L1sVBe](http://pastebin.com/E6L1sVBe)

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [November 1, 2016, 6:29pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/15 "2016-11-01T18:29:38Z")

</div>

[http://pastebin.com/CPfXB74X](http://pastebin.com/CPfXB74X)

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 1, 2016, 8:30pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/16 "2016-11-01T20:30:26Z")

</div>

Do you have x-pack installed? The original output included x-pack items but that is nowhere to be found in the information you've provided.

Also, it appears that there is both `/etc/elasticsearch` and `/usr/share/elasticsearch/config`. Which file are you editing? Did you install different ways or copy files around?

---

<div class="post-metadata">

**Author:** ![skeer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skeer/32/12775_2.png) [@skeer](https://discuss.elastic.co/u/skeer)\
**Post date:** [November 1, 2016, 8:41pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/17 "2016-11-01T20:41:37Z")

</div>

Actually I did install X-Pack as per the instructions. And yeah I just copied teh confg files I have to make sure they're both in teh same location.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [November 1, 2016, 8:46pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/18 "2016-11-01T20:46:03Z")

</div>

i made some progress but now my issue is this .

node validation exception  
bootstrap checks failed  
max virtual memory areas vm.max\_map\_count [65530] likely too low, increase to at least [262144]

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [November 1, 2016, 8:46pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/19 "2016-11-01T20:46:28Z")

</div>

I made the change to sysconfig file and restarted but still same issue

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 2, 2016, 10:55am UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484/20 "2016-11-02T10:55:15Z")

</div>

> [@kmroz](#):
>
> I made the change to sysconfig file and restarted but still same issue

What OS are you using? What did you put in the sysctl.conf file? Did you try `sysctl -w vm.max_map_count=262144` and then starting elasticsearch?

[Next page](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484.md?page=2)
