Dynamic generation of snort_agent.tcl listening ports starts at 8000 and jumps by increments of 100, which means if you have 12 or more interfaces in /etc/nsm/sensortab, that the 12th one will use 9200 which will put a tcp/9200 listener on localhost that will prevent so-elasticsearch from starting up since it needs to use that port. This will happen if the 12th sensortab entry is an active sensor interface, even if the preceding 11 entries are not configured at all.
The same issue comes up for the 12th entry in sensortab stealing listening port 9300 from Elasticsearch.
PR to fix this submitted: