1.root超級用戶不能正常啓動
由於elasticsearch2.0版本以後不能使用root來啓動,所以需要創建一個普通用戶來啓動。
[root@bogon ~]# groupadd elasticsearch
[root@bogon ~]# useradd elasticsearch -g elasticsearch
[root@bogon ~]# chown -R elasticsearch.elasticsearch /usr/local/elk/elasticsearch-5.2.1
[root@bogon ~]# su - elasticsearch
[elasticsearch@bogon ~]$ cd /usr/local/elk/elasticsearch-5.2.1/bin/
[elasticsearch@bogon bin]$ ./elasticsearch
- 1
- 2
- 3
- 4
- 5
- 6
- 1
- 2
- 3
- 4
- 5
- 6
由普通用戶來啓動,則可以正常啓動服務。
2.ERROR: bootstrap checks failed
max file descriptors [4096] for elasticsearch process likely too low, increase to at least [65536]
max number of threads [1024] for user [lishang] likely too low, increase to at least [2048]
解決:切換到root用戶,編輯limits.conf 添加類似如下內容
vi /etc/security/limits.conf
添加如下內容:
* soft nofile 65536
* hard nofile 131072
* soft nproc 2048
* hard nproc 4096
3.max number of threads [1024] for user [lish] likely too low, increase to at least [2048]
解決:切換到root用戶,進入limits.d目錄下修改配置文件。
vi /etc/security/limits.d/90-nproc.conf
修改如下內容:
* soft nproc 1024
#修改爲
* soft nproc 2048
4.max virtual memory areas vm.max_map_count [65530] likely too low, increase to at least [262144]
解決:切換到root用戶修改配置sysctl.conf
vi /etc/sysctl.conf
添加下面配置:
vm.max_map_count=655360
並執行命令:
sysctl -p
然後,重新啓動elasticsearch,即可啓動成功。
5.
system call filters failed to install; check the logs and fix your configuration or disable system call filters at your own risk
解決方法:在es配置中加入下面命令即可
bootstrap.system_call_filter: false