Virgin install of Open Distro elasticsearch crashes on startup

522 views
Skip to first unread message

J J Sloan

unread,
Feb 16, 2021, 2:51:01 PM2/16/21
to Wazuh mailing list
Installed on brand new centos 8 box. Crash message below:

[2021-02-11T15:43:54,703][ERROR][o.e.b.Bootstrap          ] [elk] Exception
java.lang.IllegalArgumentException: Could not load codec 'Lucene87'.  Did you forget to add lucene-backward-codecs.jar?

Any ideas as to whether this is quickly fixable?

J J 


Gabriel Wassan

unread,
Feb 17, 2021, 7:26:41 AM2/17/21
to Wazuh mailing list
Hello J J, 
Could you give us more information about how you did the installation? What guide did you use?
Other useful info is what version of ODFE, Wazuh, and Kibana are you using.

Regards.

J J Sloan

unread,
Feb 17, 2021, 1:03:58 PM2/17/21
to Wazuh mailing list
Hi Gabriel, 

Wazuh 4.0.1 was installed on another box, but the host in question was elk stack only.

I installed a single node elk stack by the book, using the following procedure:

https://documentation.wazuh.com/4.0/installation-guide/open-distro/distributed-deployment/unattended/unattended-elasticsearch-cluster-installation.html

It installed the versions that were on github as of Feb 13th, and elasticsearch crashed on startup with the message about missing lucene-backward-codecs

Hope this helps,

J J 

J J Sloan

unread,
Mar 4, 2021, 4:23:59 PM3/4/21
to Wazuh mailing list
I'm happy to report that starting over with a brand new centos VM yielded a successful unattended install.

J J 

Gabriel Wassan

unread,
Mar 10, 2021, 1:34:52 PM3/10/21
to Wazuh mailing list
I'm glad I could help you, if everything is resolved I'll close the Issue.
If you have any further questions, please do not hesitate to reopen the Issue or use our [slack channel](https://wazuh.com/community/join-us-on-slack/), our [Google group](https://groups.google.com/forum/#!forum/wazuh)
Regards
Reply all
Reply to author
Forward
0 new messages