# Systemd can not start elasticsearch

**URL:** <https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765>\
**Category:** Elasticsearch\
**Created:** [September 7, 2017, 7:47pm UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765 "2017-09-07T19:47:28Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajstark123](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@ajstark123](https://discuss.elastic.co/u/ajstark123)\
**Post date:** [September 7, 2017, 7:47pm UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765/1 "2017-09-07T19:47:28Z")

</div>

We can start eleacticsearch 5.5.2 out side of systemd and it runs with out issue. But when we start eleacticsearch 5.5.2 with systemd it fails with the following error.  
[1] bootstrap checks failed  
[1]: max file descriptors [65535] for elasticsearch process is too low, increase to at least [65536]

we modified the following files to try to resolve the issue, see below:  
/etc/security/limits.conf  
/etc/security/limits.d/20-nproc.conf  
/usr/lib/systemd/system/elasticsearch  
These changes did not help. We must need a different configuration file changed. any id what that file is.

version of Linux  
Linux 3.10.0-327.13.1.el7.x86\_64 #1 SMP Mon Feb 29 13:22:02 EST 2016 x86\_64 x86\_64 x86\_64 GNU/Linux

elasticsearch.service  
[Unit]  
Description=elasticsearch  
After=network.target  
Wants=network.target

[Service]  
ExecStart=/opt/pki/elasticsearch/bin/elasticsearch -p /opt/pki/elasticsearch\_pid/pid  
Restart=on-failure  
RestartSec=20  
StartLimitInterval=20  
StartLimitBurst=5  
User=pkimd1m  
LimitNOFILE=65535

[Install]  
WantedBy=multi-user.target

/etc/security/limits.conf

- soft nofile 65536
- hard nofile 65536

/etc/security/limits.d/20-nproc.conf

- soft nofile 65536
- hard nofile 65536

/usr/lib/systemd/system/elasticsearch  
LimitNOFILE=65536  
LimitMEMLOCK=unlimited

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 8, 2017, 12:27am UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765/2 "2017-09-08T00:27:59Z")

</div>

My first question for you is why are you writing your own `systemd` unit file instead of using the RPM/Debian package which includes a tested `systemd` setup? It ships with a unit file that sets up the process to pass the OS-level bootstrap checks that we can control from the service, and we test that this works.

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 8, 2017, 12:28am UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765/3 "2017-09-08T00:28:56Z")

</div>

In particular, based on your kernel, you're on a RPM-based system that we support with our out-of-the-box `systemd` packaging.

---

<div class="post-metadata">

**Author:** ![ajstark123](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@ajstark123](https://discuss.elastic.co/u/ajstark123)\
**Post date:** [September 8, 2017, 1:49pm UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765/4 "2017-09-08T13:49:49Z")

</div>

My company has a standard way of packaging and deploying software. The elasticsearch tar file distributions fit into our home grown scheme where the RPM solution does not.

One of our requirements is to run the software as a non root user id.

Can you possible provide us with your systemd services file and what OS system files we need to change.

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 8, 2017, 2:45pm UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765/5 "2017-09-08T14:45:59Z")

</div>

> [@ajstark123](#):
>
> One of our requirements is to run the software as a non root user id.

Elasticsearch does not run as `root`; in fact, we prevent running as `root` with a hard failure at runtime if a user tries to run as `root`.

> [@ajstark123](#):
>
> Can you possible provide us with your systemd services file and what OS system files we need to change.

As I mentioned, we provide these via the RPM. I understand that you're saying you can not use this, but the only reason given was not running as `root` which I explained above. So, I'd like to try again: please try our existing packaging, it's fully supported by us.

---

<div class="post-metadata">

**Author:** ![ajstark123](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@ajstark123](https://discuss.elastic.co/u/ajstark123)\
**Post date:** [September 8, 2017, 5:23pm UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765/6 "2017-09-08T17:23:25Z")

</div>

The reason we cannot use RPM has nothing to do with root.

My company has a standard way of packaging and deploying software. The elasticsearch tar file distributions fit into our home grown scheme where the RPM solution does not. We need to place the software in a very specific directory structure on the server.

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 8, 2017, 7:05pm UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765/7 "2017-09-08T19:05:24Z")

</div>

> [@ajstark123](#):
>
> The reason we cannot use RPM has nothing to do with root.

Then it would have been better to have never mentioned it because it only adds confusion to the conversation, it's a distraction.

> [@ajstark123](#):
>
> We need to place the software in a very specific directory structure on the server.

The tradeoff here is that we support and test our `systemd` unit files, not arbitrary unit files. This is something to keep in mind.

To your problem, I note that you have this:

> [@ajstark123](#):
>
> LimitNOFILE=65535

Try changing that to `LimitNOFILE=65536`

The entries you have in `/etc/security/limits.conf` and `/etc/security/limits.d` do not make a difference, the limit on file descriptors for the process will come from the unit file when started by `systemd`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2017, 7:05pm UTC](https://discuss.elastic.co/t/systemd-can-not-start-elasticsearch/99765/8 "2017-10-06T19:05:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
