# Security error after re-install of ElasticSearch

**URL:** <https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593>\
**Category:** SIEM\
**Created:** [October 25, 2021, 2:53pm UTC](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593 "2021-10-25T14:53:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [October 25, 2021, 2:53pm UTC](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593/1 "2021-10-25T14:53:52Z")

</div>

Good Morning I have been receiving multiple messages that read

```auto
Error: [object Object]: shard_not_found_exception
    at http://10.12.36.50:5601/41022/bundles/plugin/data/kibana/data.plugin.js:1:361224
    at async index_patterns_IndexPatternsService.refreshFieldSpecMap (http://10.12.36.50:5601/41022/bundles/plugin/data/kibana/data.plugin.js:1:527636)
    at async index_patterns_IndexPatternsService.getSavedObjectAndInit (http://10.12.36.50:5601/41022/bundles/plugin/data/kibana/data.plugin.js:1:530353)

```

This has the effect that I cannot see any data in the Discover or Dashboard.  
I tried restarting the Elasticsearch service this morning without success.

Is there something that can be done in Dev Tools? Any help or direction is much appreciated.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 25, 2021, 10:20pm UTC](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593/2 "2021-10-25T22:20:58Z")

</div>

Is there anything in your Elasticsearch logs?  
What does a request to `ES-HOSTNAME-IP:9200` return?

---

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [October 26, 2021, 12:07pm UTC](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593/3 "2021-10-26T12:07:20Z")

</div>

Thank you for the reply Mark. When you ask what does a request to the ES-hostname-ip:9200 return with, you are refering to a curl -XGET, correct?

The response to a curl -XGET is a proper ES response ending in "tagline" : "You know, for search"

I will check the ES logs and let you know what I see.

---

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [October 26, 2021, 1:09pm UTC](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593/4 "2021-10-26T13:09:33Z")

</div>

The ES log shows the following:

```auto
[WARN] [o.e.i.s.RetentionLeaseSyncAction] [es:domain] [.apm-custom-link][0] retention lease sync failed
search.transport.RemoteTransportException: [es.domain][IP:9200][indices:admin/seq_no/retention_lease_background_sync[p]]
Caused by: org.elasticsearch.gateway.WriteStateException: failed to write state to the first location tmp file /var/lib/elasticsearch/nodes/0/indices/MRLsvQkyTvqffVa2vEpTw/0/retention-leases-75.st.tmp
     at org.elasticsearch.gateway.MetadataStateFormat.writeStatetoFirstLocation(MetadataStateFormat.java:116) ~[elasticsearch-7.13.4.jar.7.13.4]
     at org.elasticsearch.gateway.MetadataStateFormat.write(MetedataStateFormat.java:232) ~[elasticsearch-7.13.4.jar:7.13.4}
   at org.elasticsearch.gateway.MetadataStateFormat.writeAndCleanup(MetadataStateFormat.java.174) ~[elasticsearch-7.13.4.jar:7.13.4]
  at org.elasticsearch.index.shard.IndexShard.persistRetentionLease(IndexShard.java:2370) ~[elasticsearch-7.13.4.jar:7.13.4]

```

There are other lines in the log that pertain to ActionListner and IndexShardOperationPermits.acquire.

I can grab more of the log if needed. it is a lot to type out.

Thank you for any assistance you can supply.

---

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [October 27, 2021, 12:16pm UTC](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593/5 "2021-10-27T12:16:37Z")

</div>

It seems that using simply the tail command on the logs you do miss quite a lot of information. When going through the full Elasticsearch log there was a space issue going on. After moving the /var/lib/Elasticsearch and /var/log/Elasticsearch files to a larger mount point all has been corrected.

For others who may come across this, do not take the easy route, go through the entire log no matter how large it is.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2021, 12:17pm UTC](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593/6 "2021-11-24T12:17:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
