# Service fails to start, I don't know why

**URL:** <https://discuss.elastic.co/t/service-fails-to-start-i-dont-know-why/320837>\
**Category:** Elasticsearch\
**Created:** [December 8, 2022, 10:49pm UTC](https://discuss.elastic.co/t/service-fails-to-start-i-dont-know-why/320837 "2022-12-08T22:49:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ant2ne](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@ant2ne](https://discuss.elastic.co/u/ant2ne)\
**Post date:** [December 8, 2022, 10:49pm UTC](https://discuss.elastic.co/t/service-fails-to-start-i-dont-know-why/320837/1 "2022-12-08T22:49:39Z")

</div>

**When security is disabled, they are talking via tcp (10. is the remote host sending rsyslog to elk and the 3. is the elk server).....**

```auto
21:50:01.334042 tun0 Out IP 10.226.28.173.53286 > 3.133.215.55.5044: Flags [S], seq 520455032, win 64800, options [mss 1350,sackOK,TS val 1111856841 ecr 0,nop,wscale 7], length 0
21:50:01.388741 tun0 In IP 3.133.215.55.5044 > 10.226.28.173.53286: Flags [S.], seq 3257028177, ack 520455033, win 62643, options [mss 1350,sackOK,TS val 3883257497 ecr 1111856841,nop,wscale 7], length 0
21:50:01.388765 tun0 Out IP 10.226.28.173.53286 > 3.133.215.55.5044: Flags [.], ack 1, win 507, options [nop,nop,TS val 1111856896 ecr 3883257497], length 0
21:50:01.388909 tun0 Out IP 10.226.28.173.53286 > 3.133.215.55.5044: Flags [P.], seq 1:111, ack 1, win 507, options [nop,nop,TS val 1111856896 ecr 3883257497], length 110
21:50:01.449930 tun0 In IP 3.133.215.55.5044 > 10.226.28.173.53286: Flags [.], ack 111, win 489, options [nop,nop,TS val 3883257557 ecr 1111856896], length 0
21:50:01.449944 tun0 Out IP 10.226.28.173.53286 > 3.133.215.55.5044: Flags [P.], seq 111:1112, ack 1, win 507, options [nop,nop,TS val 1111856957 ecr 3883257557], length 1001
21:50:01.466175 tun0 In IP 3.133.215.55.5044 > 10.226.28.173.53286: Flags [R.], seq 1, ack 111, win 489, options [nop,nop,TS val 3883257575 ecr 1111856896], length 0

```

**But, I can't find the remote test host within kibana. I suspect I need to enable security. I will need to do it eventually anyway. But, when I enable security as per.....**

```auto
xpack.security.enabled: true
xpack.security.authc.api_key.enabled: true

```

**systemctl status elasticsearch**

```auto
× elasticsearch.service - Elasticsearch
     Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)
     Active: failed (Result: exit-code) since Thu 2022-12-08 22:27:24 UTC; 17min ago
       Docs: https://www.elastic.co
    Process: 8565 ExecStart=/usr/share/elasticsearch/bin/systemd-entrypoint -p ${PID_DIR}/elasticsearch.pid --quiet (code=exited, status=1/FAILURE)
   Main PID: 8565 (code=exited, status=1/FAILURE)
        CPU: 5.684s
Dec 08 22:27:24 ip-172-31-35-85 systemd-entrypoint[8565]: ^
Dec 08 22:27:24 ip-172-31-35-85 systemd-entrypoint[8565]: at org.yaml.snakeyaml.parser.ParserImpl$ParseBlockMappingKey.produce(ParserImpl.java:679)
Dec 08 22:27:24 ip-172-31-35-85 systemd-entrypoint[8565]: at org.yaml.snakeyaml.parser.ParserImpl.peekEvent(ParserImpl.java:185)
Dec 08 22:27:24 ip-172-31-35-85 systemd-entrypoint[8565]: at org.yaml.snakeyaml.parser.ParserImpl.getEvent(ParserImpl.java:195)
Dec 08 22:27:24 ip-172-31-35-85 systemd-entrypoint[8565]: at com.fasterxml.jackson.dataformat.yaml.YAMLParser.nextToken(YAMLParser.java:355)
Dec 08 22:27:24 ip-172-31-35-85 systemd-entrypoint[8565]: ... 14 more
Dec 08 22:27:24 ip-172-31-35-85 systemd[1]: elasticsearch.service: Main process exited, code=exited, status=1/FAILURE
Dec 08 22:27:24 ip-172-31-35-85 systemd[1]: elasticsearch.service: Failed with result 'exit-code'.
Dec 08 22:27:24 ip-172-31-35-85 systemd[1]: Failed to start Elasticsearch.
Dec 08 22:27:24 ip-172-31-35-85 systemd[1]: elasticsearch.service: Consumed 5.684s CPU time.

```

**tail -f** the logs shows nothing. nothing. like it crashes before it can write a log.

**I did a "chown** -R elasticsearch:elasticsearch /usr/share/elasticsearch" but made no difference

What else can I try?

**ubuntu 2204 fallowing this tutorial**

> **[How To Install Elasticsearch, Logstash, and Kibana (Elastic Stack) on Ubuntu...](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-20-04)**
>
> In this tutorial, we will go over the installation of the Elastic Stack on an Ubuntu 20.04 server. You will learn how to install all of the components of the…

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 8, 2022, 11:39pm UTC](https://discuss.elastic.co/t/service-fails-to-start-i-dont-know-why/320837/2 "2022-12-08T23:39:00Z")

</div>

You need to look in to the system logs, probably `/var/log/syslog`.

But from the snippet of the error you shared, probably is related to the `elasticsearch.yml` config file, maybe something is wrong.

Can you share the entire file?

---

<div class="post-metadata">

**Author:** ![ant2ne](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@ant2ne](https://discuss.elastic.co/u/ant2ne)\
**Post date:** [December 9, 2022, 10:33am UTC](https://discuss.elastic.co/t/service-fails-to-start-i-dont-know-why/320837/3 "2022-12-09T10:33:05Z")

</div>

it is mostly stock. Below is the file with the comments # removed so that only the following are uncommented lines...

```auto
sudo grep -v "#" /etc/elasticsearch/elasticsearch.yml 
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: localhost
 xpack.security.enabled: true
 xpack.security.authc.api_key.enabled: true

```

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [December 11, 2022, 11:48pm UTC](https://discuss.elastic.co/t/service-fails-to-start-i-dont-know-why/320837/4 "2022-12-11T23:48:01Z")

</div>

There are whitespaces before `xpack.security...`. You need to remove them. YAML files are indentation sensitive.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2023, 11:48pm UTC](https://discuss.elastic.co/t/service-fails-to-start-i-dont-know-why/320837/5 "2023-01-08T23:48:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
