# Security for Elasticsearch

**URL:** <https://discuss.elastic.co/t/security-for-elasticsearch/269210>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 5, 2021, 7:40am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210 "2021-04-05T07:40:31Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 5, 2021, 7:40am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/1 "2021-04-05T07:40:31Z")

</div>

I have followed everything on YouTube: [Getting Star](https://www.youtube.com/watch?v=nMh1HWWe6B4)

but I just made 1 elastic not 2 as requested. is that a problem?

I have made the cert in / config and also I have followed everything I made the xpack in elasticsearch.yml right on my run

I get an error like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1df77b9aabfc879ed74cb8d1deca652a4c8fe90.png)  
i used basic and free license  
what should i do?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 5, 2021, 9:45am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/2 "2021-04-05T09:45:34Z")

</div>

Please don't post images of text as they are hard to read, may not display correctly for everyone, and are not searchable.

Instead, paste the text and format it with `</>` icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted before posting it. This makes it more likely that your question will receive a useful answer.

It would be great if you could update your post to solve this.

Your error message say:

> can not run elasticsearch as root.

You need to run `bin/elasticsearch` while logged in as another user, not `root`

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 5, 2021, 10:11am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/3 "2021-04-05T10:11:11Z")

</div>

okay i'm sorry,

how i'm not used root if use other user permission denied

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 5, 2021, 10:22am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/4 "2021-04-05T10:22:47Z")

</div>

> [@alipujaistopo](#):
>
> how i'm not used root if use other user permission denied

Hi again, please take the time to write your questions fully. Add details as:

- What _exactly_ are you trying to do.
- What happens instead
- What is the _exact_ error message you are seeing.

It will greatly increase the chance of someone wanting / being able to help you, if they don't have to guess what you are trying to ask!

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 5, 2021, 11:30am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/5 "2021-04-05T11:30:28Z")

</div>

i want to using elastic security, when i follow the tutorial it's different i got some error. and the error i already attach the image up there

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 5, 2021, 12:42pm UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/6 "2021-04-05T12:42:45Z")

</div>

Apologies,but I have already answered that question. You need to run elasticsearch as another user, **not** root.

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 5, 2021, 4:46pm UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/7 "2021-04-05T16:46:36Z")

</div>

but when i used not root, the permission is denied

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 5, 2021, 4:59pm UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/8 "2021-04-05T16:59:07Z")

</div>

You need to answer the questions that @ikakavas asked if you want help.

> [@ikakavas](#):
>
> Hi again, please take the time to write your questions fully. Add details as:
> 
> - What _exactly_ are you trying to do.
> - What happens instead
> - What is the _exact_ error message you are seeing.

Also I'd recommend following the installation guide.

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 6, 2021, 2:13am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/9 "2021-04-06T02:13:09Z")

</div>

i've followed from youtube

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 6, 2021, 2:40am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/10 "2021-04-06T02:40:53Z")

</div>

That isn't anywhere near enough information for us to help you.

Do not try to run as root - it will not work, it is not intended to work, the error you get is intentional.

When you try to run as another user:

- which user _exactly_ are you trying to run as?
- what is the exact command did you use to start elasticsearch?
- what is the exact error message that you see?

If you aren't willing to put in the time to explain your problem in sufficient detail for us to understand the problem, then you cannot reasonably expect us to be able to help you.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 6, 2021, 2:49am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/11 "2021-04-06T02:49:00Z")

</div>

Instead, start again from scratch from here: [Installing Elasticsearch | Elasticsearch Guide [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/install-elasticsearch.html)

If one of the steps does not work for you, tell which step, what exact command from the guide you ran and what is the exact output.

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 6, 2021, 4:38am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/12 "2021-04-06T04:38:27Z")

</div>

- i used a root user, because there's no another user
- i used `./bin/elasticsearch` and `systemctl start elasticsearch`. the error is same
- 

> [2021-04-06T01:30:00,001][INFO][o.e.x.m.MlDailyMaintenanceService] [bdi-uat-els] triggering scheduled [ML] maintenance tasks  
> [2021-04-06T01:30:00,021][INFO][o.e.x.m.a.TransportDeleteExpiredDataAction] [bdi-uat-els] Deleting expired data  
> [2021-04-06T01:30:00,043][INFO][o.e.x.m.j.r.UnusedStatsRemover] [bdi-uat-els] Successfully deleted [0] unused stats documents  
> [2021-04-06T01:30:00,044][INFO][o.e.x.m.a.TransportDeleteExpiredDataAction] [bdi-uat-els] Completed deletion of expired ML data  
> [2021-04-06T01:30:00,044][INFO][o.e.x.m.MlDailyMaintenanceService] [bdi-uat-els] Successfully completed [ML] maintenance task: triggerDeleteExpiredDataTask  
> [2021-04-06T01:41:11,671][INFO][o.e.c.m.MetadataMappingService] [bdi-uat-els] [winlogbeat-7.10.2-2021.04.03-000003/bOup-BKdTdem9wc-cEygrQ] update\_mapping [\_doc]  
> [2021-04-06T01:41:11,781][INFO][o.e.c.m.MetadataMappingService] [bdi-uat-els] [winlogbeat-7.10.2-2021.04.03-000003/bOup-BKdTdem9wc-cEygrQ] update\_mapping [\_doc]  
> [2021-04-06T05:08:44,149][WARN][o.e.m.f.FsHealthService] [bdi-uat-els] health check of [/var/lib/elasticsearch/nodes/0] took [5403ms] which is above the warn threshold of [5s]  
> [2021-04-06T08:30:00,005][INFO][o.e.x.s.SnapshotRetentionTask] [bdi-uat-els] starting SLM retention snapshot cleanup task  
> [2021-04-06T08:30:00,008][INFO][o.e.x.s.SnapshotRetentionTask] [bdi-uat-els] there are no repositories to fetch, SLM retention snapshot cleanup task complete  
> [2021-04-06T11:33:20,873][INFO][o.e.n.Node] [bdi-uat-els] stopping ...  
> [2021-04-06T11:33:20,878][INFO][o.e.x.w.WatcherService] [bdi-uat-els] stopping watch service, reason [shutdown initiated]  
> [2021-04-06T11:33:20,879][INFO][o.e.x.m.p.l.CppLogMessageHandler] [bdi-uat-els] [controller/25413] [Main.cc@154] ML controller exiting  
> [2021-04-06T11:33:20,879][INFO][o.e.x.w.WatcherLifeCycleService] [bdi-uat-els] watcher has stopped and shutdown  
> [2021-04-06T11:33:20,880][INFO][o.e.x.m.p.NativeController] [bdi-uat-els] Native controller process has stopped - no new native processes can be started  
> [2021-04-06T11:33:21,420][INFO][o.e.n.Node] [bdi-uat-els] stopped  
> [2021-04-06T11:33:21,421][INFO][o.e.n.Node] [bdi-uat-els] closing ...  
> [2021-04-06T11:33:21,432][INFO][o.e.n.Node] [bdi-uat-els] closed  
> [2021-04-06T11:33:24,302][INFO][o.e.n.Node] [bdi-uat-els] version[7.10.1], pid[29341], build[default/rpm/1c34507e66d7db1211f66f3513706fdf548736aa/2020-12-05T01:00:33.671820Z], OS[Linux/3.10.0-1127.el7.x86\_64/amd64], JVM[AdoptOpenJDK/OpenJDK 64-Bit Server VM/15.0.1/15.0.1+9]  
> [2021-04-06T11:33:24,305][INFO][o.e.n.Node] [bdi-uat-els] JVM home [/usr/share/elasticsearch/jdk], using bundled JDK [true]  
> [2021-04-06T11:33:24,306][INFO][o.e.n.Node] [bdi-uat-els] JVM arguments [-Xshare:auto, -Des.networkaddress.cache.ttl=60, -Des.networkaddress.cache.negative.ttl=10, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -XX:-OmitStackTraceInFastThrow, -XX:+ShowCodeDetailsInExceptionMessages, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dio.netty.allocator.numDirectArenas=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Djava.locale.providers=SPI,COMPAT, -Xms1g, -Xmx1g, -XX:+UseG1GC, -XX:G1ReservePercent=25, -XX:InitiatingHeapOccupancyPercent=30, -Djava.io.tmpdir=/tmp/elasticsearch-2685646022361486910, -XX:+HeapDumpOnOutOfMemoryError, -XX:HeapDumpPath=/var/lib/elasticsearch, -XX:ErrorFile=/var/log/elasticsearch/hs\_err\_pid%p.log, -Xlog:gc\*,gc+age=trace,safepoint:file=/var/log/elasticsearch/gc.log:utctime,pid,tags:filecount=32,filesize=64m, -XX:MaxDirectMemorySize=536870912, -Des.path.home=/usr/share/elasticsearch, -Des.path.conf=/etc/elasticsearch, -Des.distribution.flavor=default, -Des.distribution.type=rpm, -Des.bundled\_jdk=true]  
> [2021-04-06T11:33:26,208][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [aggs-matrix-stats]  
> [2021-04-06T11:33:26,208][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [analysis-common]  
> [2021-04-06T11:33:26,209][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [constant-keyword]  
> [2021-04-06T11:33:26,209][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [flattened]  
> [2021-04-06T11:33:26,209][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [frozen-indices]  
> [2021-04-06T11:33:26,209][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [ingest-common]  
> [2021-04-06T11:33:26,209][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [ingest-geoip]  
> [2021-04-06T11:33:26,209][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [ingest-user-agent]  
> [2021-04-06T11:33:26,209][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [kibana]  
> [2021-04-06T11:33:26,210][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [lang-expression]  
> [2021-04-06T11:33:26,210][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [lang-mustache]  
> [2021-04-06T11:33:26,210][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [lang-painless]  
> [2021-04-06T11:33:26,210][INFO][o.e.p.PluginsService] [bdi-uat-els] loaded module [mapper-extras]

here's the complete error i got in elasticsearch.log

●\> elasticsearch.service - Elasticsearch

> Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled)  
> Active: failed (Result: exit-code) since Tue 2021-04-06 11:33:29 WIB; 3min 24s ago  
> Docs: [https://www.elastic.co](https://www.elastic.co)  
> Process: 29341 ExecStart=/usr/share/elasticsearch/bin/systemd-entrypoint -p ${PID\_DIR}/elasticsearch.pid --quiet (code=exited, status=1/FAILURE)  
> Main PID: 29341 (code=exited, status=1/FAILURE)
> 
> Apr 06 11:33:29 bdi-uat-els systemd-entrypoint[29341]: at java.base/java.util.stream.ReferencePipeline.collect(ReferencePipeline.java:578)  
> Apr 06 11:33:29 bdi-uat-els systemd-entrypoint[29341]: at org.elasticsearch.node.Node.(Node.java:557)  
> Apr 06 11:33:29 bdi-uat-els systemd-entrypoint[29341]: at org.elasticsearch.node.Node.(Node.java:289)  
> Apr 06 11:33:29 bdi-uat-els systemd-entrypoint[29341]: at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:227)  
> Apr 06 11:33:29 bdi-uat-els systemd-entrypoint[29341]: \<\<\>\>  
> Apr 06 11:33:29 bdi-uat-els systemd-entrypoint[29341]: For complete error details, refer to the log at /var/log/elasticsearch/elasticsearch.log  
> Apr 06 11:33:29 bdi-uat-els systemd[1]: elasticsearch.service: main process exited, code=exited, status=1/FAILURE  
> Apr 06 11:33:29 bdi-uat-els systemd[1]: Failed to start Elasticsearch.  
> Apr 06 11:33:29 bdi-uat-els systemd[1]: Unit elasticsearch.service entered failed state.  
> Apr 06 11:33:29 bdi-uat-els systemd[1]: elasticsearch.service failed.

and this with` systemctl status elasticsearch`

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 6, 2021, 4:39am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/13 "2021-04-06T04:39:23Z")

</div>

the elastic is fine, till i wanna try use elasticsearch security there's some error

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 6, 2021, 5:52am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/14 "2021-04-06T05:52:21Z")

</div>

Read [Scripting and security | Elasticsearch Guide [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.12/modules-scripting-security.html#_do_not_run_as_root)

> First and foremost, never run Elasticsearch as the `root` user as this would allow any successful effort to circumvent the other security layers to do **anything** on your server. **Elasticsearch will refuse to start** if it detects that it is running as `root` but this is so important that it is worth double and triple checking.

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 6, 2021, 7:51am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/15 "2021-04-06T07:51:43Z")

</div>

aah okay, i will try next. thanks btw

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 8, 2021, 5:02am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/16 "2021-04-08T05:02:08Z")

</div>

i just want to enable tls/https on my elasticsearch server. but i have an error like this

```
● elasticsearch.service - Elasticsearch
   Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled)
   Active: failed (Result: exit-code) since Thu 2021-04-08 11:51:19 WIB; 13s ago
     Docs: https://www.elastic.co
  Process: 6921 ExecStart=/usr/share/elasticsearch/bin/systemd-entrypoint -p ${PID_DIR}/elasticsearch.pid --quiet (code=exited, status=1/FAILURE)
Main PID: 6921 (code=exited, status=1/FAILURE)

Apr 08 11:51:19 bdi-uat-els systemd-entrypoint[6921]: at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:393)
Apr 08 11:51:19 bdi-uat-els systemd-entrypoint[6921]: at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:170)
Apr 08 11:51:19 bdi-uat-els systemd-entrypoint[6921]: at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:161)
Apr 08 11:51:19 bdi-uat-els systemd-entrypoint[6921]: at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:86)
Apr 08 11:51:19 bdi-uat-els systemd-entrypoint[6921]: <<<truncated>>>
Apr 08 11:51:19 bdi-uat-els systemd-entrypoint[6921]: For complete error details, refer to the log at /var/log/elasticsearch/elasticsearch.log
Apr 08 11:51:19 bdi-uat-els systemd[1]: elasticsearch.service: main process exited, code=exited, status=1/FAILURE
Apr 08 11:51:19 bdi-uat-els systemd[1]: Failed to start Elasticsearch.
Apr 08 11:51:19 bdi-uat-els systemd[1]: Unit elasticsearch.service entered failed state.
Apr 08 11:51:19 bdi-uat-els systemd[1]: elasticsearch.service failed.

```

why? please help

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 8, 2021, 5:20am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/17 "2021-04-08T05:20:55Z")

</div>

You need to look at the [Elasticsearch logs](https://www.elastic.co/guide/en/elasticsearch/reference/current/logging.html) to get details. Don't try and rely on the output from systemd.

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [April 8, 2021, 6:18am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/18 "2021-04-08T06:18:26Z")

</div>

here's the complete log

```
[2021-04-08T01:30:00,000][INFO][o.e.x.m.MlDailyMaintenanceService] [bdi-uat-els] triggering scheduled [ML] maintenance tasks
[2021-04-08T01:30:00,006][INFO][o.e.x.m.a.TransportDeleteExpiredDataAction] [bdi-uat-els] Deleting expired data
[2021-04-08T01:30:00,008][INFO][o.e.x.m.j.r.UnusedStatsRemover] [bdi-uat-els] Successfully deleted [0] unused stats documents
[2021-04-08T01:30:00,008][INFO][o.e.x.m.a.TransportDeleteExpiredDataAction] [bdi-uat-els] Completed deletion of expired ML data
[2021-04-08T01:30:00,008][INFO][o.e.x.m.MlDailyMaintenanceService] [bdi-uat-els] Successfully completed [ML] maintenance task: triggerDeleteExpiredDataTask
[2021-04-08T08:30:00,000][INFO][o.e.x.s.SnapshotRetentionTask] [bdi-uat-els] starting SLM retention snapshot cleanup task
[2021-04-08T08:30:00,002][INFO][o.e.x.s.SnapshotRetentionTask] [bdi-uat-els] there are no repositories to fetch, SLM retention snapshot cleanup task complete
[2021-04-08T10:58:43,955][INFO][o.e.n.Node] [bdi-uat-els] stopping ...
[2021-04-08T10:58:43,962][INFO][o.e.x.w.WatcherService] [bdi-uat-els] stopping watch service, reason [shutdown initiated]
[2021-04-08T10:58:43,963][INFO][o.e.x.m.p.l.CppLogMessageHandler] [bdi-uat-els] [controller/29792] [Main.cc@154] ML controller exiting
[2021-04-08T10:58:43,963][INFO][o.e.x.m.p.NativeController] [bdi-uat-els] Native controller process has stopped - no new native processes can be started
[2021-04-08T10:58:43,963][INFO][o.e.x.w.WatcherLifeCycleService] [bdi-uat-els] watcher has stopped and shutdown
[2021-04-08T10:58:44,337][INFO][o.e.n.Node] [bdi-uat-els] stopped
[2021-04-08T10:58:44,337][INFO][o.e.n.Node] [bdi-uat-els] closing ...
[2021-04-08T10:58:44,349][INFO][o.e.n.Node] [bdi-uat-els] closed
[2021-04-08T11:47:33,845][INFO][o.e.n.Node] [10.194.11.67] version[7.10.1], pid[6491], build[default/rpm/1c34507e66d7db1211f66f3513706fdf548736aa/2020-12-05T01:00:33.671820Z], OS[Linux/3.10.0-1127.el7.x86_64/amd64], JVM[AdoptOpenJDK/OpenJDK 64-Bit Server VM/15.0.1/15.0.1+9]
[2021-04-08T11:47:33,848][INFO][o.e.n.Node] [10.194.11.67] JVM home [/usr/share/elasticsearch/jdk], using bundled JDK [true]
[2021-04-08T11:47:33,848][INFO][o.e.n.Node] [10.194.11.67] JVM arguments [-Xshare:auto, -Des.networkaddress.cache.ttl=60, -Des.networkaddress.cache.negative.ttl=10, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -XX:-OmitStackTraceInFastThrow, -XX:+ShowCodeDetailsInExceptionMessages, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dio.netty.allocator.numDirectArenas=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Djava.locale.providers=SPI,COMPAT, -Xms1g, -Xmx1g, -XX:+UseG1GC, -XX:G1ReservePercent=25, -XX:InitiatingHeapOccupancyPercent=30, -Djava.io.tmpdir=/tmp/elasticsearch-539247061516994380, -XX:+HeapDumpOnOutOfMemoryError, -XX:HeapDumpPath=/var/lib/elasticsearch, -XX:ErrorFile=/var/log/elasticsearch/hs_err_pid%p.log, -Xlog:gc*,gc+age=trace,safepoint:file=/var/log/elasticsearch/gc.log:utctime,pid,tags:filecount=32,filesize=64m, -XX:MaxDirectMemorySize=536870912, -Des.path.home=/usr/share/elasticsearch, -Des.path.conf=/etc/elasticsearch, -Des.distribution.flavor=default, -Des.distribution.type=rpm, -Des.bundled_jdk=true]
[2021-04-08T11:47:35,798][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [aggs-matrix-stats]
[2021-04-08T11:47:35,798][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [analysis-common]
[2021-04-08T11:47:35,799][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [constant-keyword]
[2021-04-08T11:47:35,799][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [flattened]
[2021-04-08T11:47:35,799][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [frozen-indices]
[2021-04-08T11:47:35,799][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [ingest-common]
[2021-04-08T11:47:35,799][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [ingest-geoip]
[2021-04-08T11:47:35,799][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [ingest-user-agent]
[2021-04-08T11:47:35,800][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [kibana]
[2021-04-08T11:47:35,800][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [lang-expression]
[2021-04-08T11:47:35,800][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [lang-mustache]
[2021-04-08T11:47:35,800][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [lang-painless]
[2021-04-08T11:47:35,800][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [mapper-extras]
[2021-04-08T11:47:35,800][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [mapper-version]
[2021-04-08T11:47:35,800][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [parent-join]
[2021-04-08T11:47:35,800][INFO][o.e.p.PluginsService] [10.194.11.67] loaded module [percolator]
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2021, 6:18am UTC](https://discuss.elastic.co/t/security-for-elasticsearch/269210/19 "2021-05-06T06:18:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
