# SIGKILL twice to kill or use SIGINT and SIGTERM

**URL:** <https://discuss.elastic.co/t/sigkill-twice-to-kill-or-use-sigint-and-sigterm/51611>\
**Category:** Logstash\
**Created:** [June 1, 2016, 8:29pm UTC](https://discuss.elastic.co/t/sigkill-twice-to-kill-or-use-sigint-and-sigterm/51611 "2016-06-01T20:29:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![wmcdonald](https://avatars.discourse-cdn.com/v4/letter/w/f6c823/32.png) [@wmcdonald](https://discuss.elastic.co/u/wmcdonald)\
**Post date:** [June 1, 2016, 8:29pm UTC](https://discuss.elastic.co/t/sigkill-twice-to-kill-or-use-sigint-and-sigterm/51611/1 "2016-06-01T20:29:46Z")

</div>

It seems logstash (technically launched via java) traps the SIGKILL unix signal (ie. kill -9) and tries to shutdown gracefully. However, I have experienced times when it never shuts down.

I suggest that the policy be that if while handing the first SIGKILL another is received, the app simply exit with data loss. Another policy would be to property use SIGINT and/or SIGTERM instead of SIGKILL for graceful exit and SIGKILL for what it is designed for - killing the process. Otherwise, when the process hangs, I can only get rid of it by rebooting the machine.

FYI: I am running pipe plugin as a logstash input with the tail command:  
input {  
pipe {  
add\_field =\> { "source" =\> "foo.log" }  
command =\> "tail -f ./logs/foo.log"  
}  
And killing the main process leaves 4 zombies attached to the root pid, so ps -ef | grep java still shows the logstash java process even after several kill -9's.

Using logstash 2.3.1 on Solaris 10

---

<div class="post-metadata">

**Author:** ![purbon](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@purbon](https://discuss.elastic.co/u/purbon)\
**Post date:** [June 2, 2016, 9:29am UTC](https://discuss.elastic.co/t/sigkill-twice-to-kill-or-use-sigint-and-sigterm/51611/2 "2016-06-02T09:29:16Z")

</div>

Good morning,  
in logstash specifically we don't trap the SIGKILL, you can see how do we react to the different signals at [https://github.com/elastic/logstash/blob/master/logstash-core/lib/logstash/runner.rb#L368-L394](https://github.com/elastic/logstash/blob/master/logstash-core/lib/logstash/runner.rb#L368-L394)

On the other side, we don't really test in solaris, so can not help much on the behaviour there, might this be related to the way the pipe input you're using works in solaris?

see

```auto
skywalker% ps -ax | grep logstash
 1830 ttys000 0:27.88 /Library/Java/JavaVirtualMachines/jdk1.8.0_91.jdk/Contents/Home//bin/java -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+DisableExplicitGC -Djava.awt.headless=true -Dfile.encoding=UTF-8 -XX:+HeapDumpOnOutOfMemoryError -Xmx1g -Xms256m -Xss2048k -Djffi.boot.library.path=/Users/purbon/work/logstash/vendor/jruby/lib/jni -Dfile.encoding=UTF-8 -Xbootclasspath/a:/Users/purbon/work/logstash/vendor/jruby/lib/jruby.jar -classpath : -Djruby.home=/Users/purbon/work/logstash/vendor/jruby -Djruby.lib=/Users/purbon/work/logstash/vendor/jruby/lib -Djruby.script=jruby -Djruby.shell=/bin/sh org.jruby.Main --1.9 /Users/purbon/work/logstash/lib/bootstrap/environment.rb logstash/runner.rb -e 
 1957 ttys002 0:00.00 grep logstash
skywalker% kill -9 1830
skywalker% ps -ax | grep logstash
 1959 ttys002 0:00.00 grep logstash
skywalker% 

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:54am UTC](https://discuss.elastic.co/t/sigkill-twice-to-kill-or-use-sigint-and-sigterm/51611/3 "2017-07-06T04:54:51Z")

</div>


