# My kibana.service failed after i made a change in kibana.yml

**URL:** <https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420>\
**Category:** Kibana\
**Created:** [March 5, 2025, 3:40am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420 "2025-03-05T03:40:59Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 5, 2025, 3:40am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/1 "2025-03-05T03:40:59Z")

</div>

i installed kibana by rpm, it was running til i made some change to kibana.yml, after that it failed immediately. This is what i changed:

server.port: 5601

server.host:"10.6.145.226"

elasticsearch.hosts: ["https:/\_/10.6.145.226:9200"]

---

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 5, 2025, 3:42am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/2 "2025-03-05T03:42:21Z")

</div>

**This is my Kibana.yml file**

# For more configuration options see the configuration guide for Kibana in

# [Elastic Docs | Elastic](https://www.elastic.co/guide/index.html)

# =================== System: Kibana Server ===================

# Kibana is served by a back end server. This setting specifies the port to use.

server.port: 5601

# Specifies the address to which the Kibana server will bind. IP addresses and host names are both valid values.

# The default is 'localhost', which usually means remote machines will not be able to connect.

# To allow connections from remote users, set this parameter to a non-loopback address.

server.host:"10.6.145.226"

# Enables you to specify a path to mount Kibana at if you are running behind a proxy.

# Use the `server.rewriteBasePath` setting to tell Kibana if it should remove the basePath

# from requests it receives, and to prevent a deprecation warning at startup.

# This setting cannot end in a slash.

#server.basePath: ""

# Specifies whether Kibana should rewrite requests that are prefixed with

# `server.basePath` or require that they are rewritten by your reverse proxy.

# Defaults to `false`.

#server.rewriteBasePath: false

# Specifies the public URL at which Kibana is available for end users. If

# `server.basePath` is configured this URL should end with the same basePath.

#server.publicBaseUrl: ""

# The maximum payload size in bytes for incoming server requests.

#server.maxPayload: 1048576

# The Kibana server's name. This is used for display purposes.

#server.name: "your-hostname"

# =================== System: Kibana Server (Optional) ===================

# Enables SSL and paths to the PEM-format SSL certificate and SSL key files, respectively.

# These settings enable SSL for outgoing requests from the Kibana server to the browser.

#server.ssl.enabled: false  
#server.ssl.certificate: /path/to/your/server.crt  
#server.ssl.key: /path/to/your/server.key

# =================== System: Elasticsearch ===================

# The URLs of the Elasticsearch instances to use for all your queries.

elasticsearch.hosts: ["https:/\_/10.6.145.226:9200"]

# If your Elasticsearch is protected with basic authentication, these settings provide

# the username and password that the Kibana server uses to perform maintenance on the Kibana

# index at startup. Your Kibana users still need to authenticate with Elasticsearch, which

# is proxied through the Kibana server.

#elasticsearch.username: "kibana\_system"  
#elasticsearch.password: "pass"

# Kibana can also authenticate to Elasticsearch via "service account tokens".

# Service account tokens are Bearer style tokens that replace the traditional username/password based configuration.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 5, 2025, 10:49am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/3 "2025-03-05T10:49:40Z")

</div>

> [@Duong\_Hieu](#):
>
> elasticsearch.hosts: ["https:/\_/10.6.145.226:9200"]

fix the typo

You dont need/want the "\_"

```auto
elasticsearch.hosts: ["https://10.6.145.226:9200"]

```

---

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 6, 2025, 2:15am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/4 "2025-03-06T02:15:48Z")

</div>

Hi Kevin, its the "_" i put it in following the policy of website, in my yml file in the system it doesnt have "_"

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 6, 2025, 9:10am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/5 "2025-03-06T09:10:03Z")

</div>

If its your company policy?

> [@Duong\_Hieu](#):
>
> i installed kibana by rpm, it was running til i made some change to kibana.yml, after that it failed immediately. This is what I changed:

Change it back?

---

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 6, 2025, 9:26am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/6 "2025-03-06T09:26:11Z")

</div>

sorry for that, i didnt explain it clearly. Its the policies of this discuss web that we are communicating doesnt allow me to post a complete link so i have to put - in to the middle //

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 6, 2025, 9:33am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/7 "2025-03-06T09:33:19Z")

</div>

This is where we are:

You posted

I changed `some configs` and now stuff doesn't work. (providing nothing else, no log of any error, just 3 lines of configuration).

I noted that `some configs` is broken, suggested you fix it. The 3 lines of information you supplied had a clear and obvious error.

You said I really didn't change it to `some configs ` due to some obscure policy.

OK, then I suggested change `some configs` back to whatever it was before, when it was working. Did you try that?

For now, it is impossible to diagnose your problem using the information so far shared. Error messages, some context, kibana logs, ... might help.

---

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 6, 2025, 9:45am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/8 "2025-03-06T09:45:34Z")

</div>

This is what i got when i run journalctl -eu kibana

Kibana is currently running with legacy OpenSSL providers enabled! For details and instructions on how to disable see [Use Kibana in a production environment | Kibana Guide [8.14] | Elastic](https://www.elastic.co/guide/en/kibana/8.14/production.html#openssl-legacy-provider)  
{"log.level":"info","@timestamp":"2025-03-06T09:10:30.755Z","log.logger":"elastic-apm-node","ecs.version":"8.10.0","agentVersion":"4.5.0","env":{"pid":127077,"proctitle":"/usr/share/kibana/bin/../node/bin/node","os":"linux  
FATAL CLI ERROR YAMLException: can not read a block mapping entry; a multiline key may not be an implicit key at line 13, column 1:

---

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 6, 2025, 9:46am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/9 "2025-03-06T09:46:28Z")

</div>

i also check in the YML file and when i undo the config, kibana activated

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 6, 2025, 10:26am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/10 "2025-03-06T10:26:51Z")

</div>

that reads like you are just messing up when editing the file, adding (maybe invisible) characters

After editing, check and validate the kibana.yml with a tool, e.g.

> **[YAML Checker - The Best YAML Validator](https://yamlchecker.com)**
>
> A fast and easy-to-use YAML syntax validator for developers, devops, or anyone else using YAML syntax

or via command line with (eg) yamllint

This works for me:

```auto
# cat $HOME/.yamllint
extends: default

rules:
# don't fail if a line is long
 line-length: disable
 document-start: disable
 comments: disable
# yamllint /etc/elasticsearch/elasticsearch.yml
# yamllint /etc/kibana/kibana.yml
#

```

---

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 7, 2025, 1:56am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/11 "2025-03-07T01:56:48Z")

</div>

thank you so much, finally its run @@

---

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 7, 2025, 2:12am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/12 "2025-03-07T02:12:38Z")

</div>

after i delete the space in yml its run completely and i want to try your cmd line but i dont know where to put it. Sr im kinda new with Linux and stuff

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 7, 2025, 8:39am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/13 "2025-03-07T08:39:25Z")

</div>

dont worry about it, main thing is it now works.

Good luck with your project.

---

<div class="post-metadata">

**Author:** ![Duong\_Hieu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duong_hieu/32/141303_2.png) [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Post date:** [March 7, 2025, 9:06am UTC](https://discuss.elastic.co/t/my-kibana-service-failed-after-i-made-a-change-in-kibana-yml/375420/14 "2025-03-07T09:06:03Z")

</div>

u help me a lot, thank you man
