Searchguard 7.10.2 With Elastic Windows Service

If you think it is a bug report or you have a technical issue, please answer the following questions. For general questions, you can delete these questions.

Elasticsearch version: 7.10.2

Server OS version: Windows Server 2019

Describe the issue: Elasticsearch fails to stop the windows service. I can see in the logs that the elastic service is stopped but the windows service gets stuck on “stopping”. The only way to fix this is to stop the elasticsearch-service-x64.exe process. When i uninstall the searchguard plugin, i don’t have problems with the service.

Any help is appreciated.

Hi @powershell
I have never experienced this. Is it a big problem for you? Do you need to stop the service frequently? If you need to do it frequently, why? In short, please describe the use case.

Use the Analyze Wait Chain feature to investigate what child process prevents Elasticsearch stop https://techcommunity.microsoft.com/t5/ask-the-performance-team/alternative-tools-for-application-hangs/ba-p/1685245

Hi @srgbnd
When the service i started and normally working, it had elasticsearch-service-x64.exe had 6 threads under the wait chain. When i stopped the service and it got stuck on stopping, it had 2 threads remaining that refused to stop.

I am not seeing this issue on elastic and searchguard version 7.10.1. I will use this version.

You can close this thread.

Thank you for the help :grinning:

So it looks like this is also happening on 7.10.1. I testing on 6.8.10 and i did not get any problems.

The only thing that looks off is the cluster allocation results:

Can you try to edit your elasticsearch.yml file and add this?

signals.enabled: false

In case this does not make a difference, it would be helpful if you get a dump of the running Java thread stack traces when ES is stuck during shutdown.

See here for details how to create such a thread dump:

signals.enabled: false

Worked perfectly!

Thank you!

Glad it worked. Please note that this is just a workaround, as with this change, the Signal Alerting feature in Search Guard is not available.

We are looking into it to find and fix the actual cause.

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.