I disabled selinux in an affort to get Kibana started. It worked initially, but the kibana service fails to start. I checked /var/log/kibana/kibana.stderr. The following log entry is present:
"FATAL Error: Port 5601 is already in use. Another instance of Kibana may be running!"
Here are the logs from /var/log/kibana/kibana.stdout
{"type":"log","@timestamp":"2019-10-09T16:20:33Z","tags":["fatal","root"],"pid":2191,"message":"Error: Port 5601 is already in use. Another instance of Kibana may be running!\n at Root.shutdown (/usr/share/kibana/src/core/server/root/index.js:67:18)\n at Root.setup (/usr/share/kibana/src/core/server/root/index.js:46:18)\n at process._tickCallback (internal/process/next_tick.js:68:7)"}
{"type":"log","@timestamp":"2019-10-09T16:38:16Z","tags":["fatal","root"],"pid":2100,"message":"Error: Port 5601 is already in use. Another instance of Kibana may be running!\n at Root.shutdown (/usr/share/kibana/src/core/server/root/index.js:67:18)\n at Root.setup (/usr/share/kibana/src/core/server/root/index.js:46:18)\n at process._tickCallback (internal/process/next_tick.js:68:7)"}
{"type":"log","@timestamp":"2019-10-09T17:31:44Z","tags":["fatal","root"],"pid":2299,"message":"Error: Port 5601 is already in use. Another instance of Kibana may be running!\n at Root.shutdown (/usr/share/kibana/src/core/server/root/index.js:67:18)\n at Root.setup (/usr/share/kibana/src/core/server/root/index.js:46:18)\n at process._tickCallback (internal/process/next_tick.js:68:7)"}
{"type":"log","@timestamp":"2019-10-10T15:38:14Z","tags":["info","plugins-system"],"pid":3079,"message":"Setting up [4] plugins: [security,translations,inspector,data]"}
{"type":"log","@timestamp":"2019-10-10T15:38:14Z","tags":["info","plugins","security"],"pid":3079,"message":"Setting up plugin"}
{"type":"log","@timestamp":"2019-10-10T15:38:14Z","tags":["warning","plugins","security","config"],"pid":3079,"message":"Generating a random key for xpack.security.encryptionKey. To prevent sessions from being invalidated on restart, please set xpack.security.encryptionKey in kibana.yml"}
{"type":"log","@timestamp":"2019-10-10T15:38:14Z","tags":["warning","plugins","security","config"],"pid":3079,"message":"Session cookies will be transmitted over insecure connections. This is not recommended."}
{"type":"log","@timestamp":"2019-10-10T15:38:14Z","tags":["info","plugins","translations"],"pid":3079,"message":"Setting up plugin"}
{"type":"log","@timestamp":"2019-10-10T15:38:14Z","tags":["info","plugins","data"],"pid":3079,"message":"Setting up plugin"}
{"type":"log","@timestamp":"2019-10-10T15:38:14Z","tags":["info","plugins-system"],"pid":3079,"message":"Starting [3] plugins: [security,translations,data]"}
{"type":"log","@timestamp":"2019-10-10T15:38:21Z","tags":["plugin","warning"],"pid":3079,"path":"/usr/share/kibana/src/legacy/core_plugins/metric_vis","message":"Skipping non-plugin directory at /usr/share/kibana/src/legacy/core_plugins/metric_vis"}
{"type":"log","@timestamp":"2019-10-10T15:38:21Z","tags":["plugin","warning"],"pid":3079,"path":"/usr/share/kibana/src/legacy/core_plugins/table_vis","message":"Skipping non-plugin directory at /usr/share/kibana/src/legacy/core_plugins/table_vis"}
{"type":"log","@timestamp":"2019-10-10T15:38:21Z","tags":["plugin","warning"],"pid":3079,"path":"/usr/share/kibana/src/legacy/core_plugins/tagcloud","message":"Skipping non-plugin directory at /usr/share/kibana/src/legacy/core_plugins/tagcloud"}
{"type":"log","@timestamp":"2019-10-10T15:38:21Z","tags":["plugin","warning"],"pid":3079,"path":"/usr/share/kibana/src/legacy/core_plugins/vega","message":"Skipping non-plugin directory at /usr/share/kibana/src/legacy/core_plugins/vega"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:kibana@7.4.0","info"],"pid":3079,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:elasticsearch@7.4.0","info"],"pid":3079,"state":"yellow","message":"Status changed from uninitialized to yellow - Waiting for Elasticsearch","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:xpack_main@7.4.0","info"],"pid":3079,"state":"yellow","message":"Status changed from uninitialized to yellow - Waiting for Elasticsearch","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:telemetry@7.4.0","info"],"pid":3079,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:graph@7.4.0","info"],"pid":3079,"state":"yellow","message":"Status changed from uninitialized to yellow - Waiting for Elasticsearch","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:monitoring@7.4.0","info"],"pid":3079,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:spaces@7.4.0","info"],"pid":3079,"state":"yellow","message":"Status changed from uninitialized to yellow - Waiting for Elasticsearch","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:security@7.4.0","info"],"pid":3079,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:searchprofiler@7.4.0","info"],"pid":3079,"state":"yellow","message":"Status changed from uninitialized to yellow - Waiting for Elasticsearch","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:ml@7.4.0","info"],"pid":3079,"state":"yellow","message":"Status changed from uninitialized to yellow - Waiting for Elasticsearch","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2019-10-10T15:38:23Z","tags":["status","plugin:tilemap@7.4.0","info"],"pid":3079,"state":"yellow","message":"Status changed from uninitialized to yellow - Waiting for Elasticsearch","prevState":"uninitialized","prevMsg":"uninitialized"}
I checked for running processes and only found one. I ran lsof -i :5601 to find this info. Output below:
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
node 886 kibana 30u IPv4 20823 0t0 TCP localhost:esmagent (LISTEN)
I am attemping to stand of services and beats for use with ElasticSIEM and this is slowing me down big time. Any help fixing this nagging issue is appreciated.