# Opensearch Startup ERROR \[o.o.p.c.e.EventLogFileHandler\] \[node-1\] Error writing entry 'NOT\_INITIALIZED'

**URL:** <https://forum.opensearch.org/t/opensearch-startup-error-o-o-p-c-e-eventlogfilehandler-node-1-error-writing-entry-not-initialized/16575>\
**Category:** OpenSearch\
**Tags:** configure\
**Created:** [November 7, 2023, 9:46am UTC](https://forum.opensearch.org/t/opensearch-startup-error-o-o-p-c-e-eventlogfilehandler-node-1-error-writing-entry-not-initialized/16575 "2023-11-07T09:46:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_free](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/_free/32/6381_2.png) [@\_free](https://forum.opensearch.org/u/_free)\
**Post date:** [November 7, 2023, 9:46am UTC](https://forum.opensearch.org/t/opensearch-startup-error-o-o-p-c-e-eventlogfilehandler-node-1-error-writing-entry-not-initialized/16575/1 "2023-11-07T09:46:33Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser): 2.9.0

**Describe the issue** : Start the single node **opensearch1.3.1.tar** version node-2 first, and then add a data node nodes-1 of **opensearch2.9.0.rpm** version. It was found that the data node node-1 reported an error. Please refer to the errorlog for details

**Errorlog** :  
[2023-11-07T17:05:46,005][ERROR][o.o.p.c.e.EventLogFileHandler] [node-1] Error writing entry ‘NOT\_INITIALIZED’. Cause:  
java.nio.file.AccessDeniedException: _ **/dev/shm/performanceanalyzer/1699347945000.tmp** _  
at sun.nio.fs.UnixException.translateToIOException(UnixException.java:90) ~[?:?]  
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:106) ~[?:?]  
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:111) ~[?:?]  
at sun.nio.fs.UnixFileSystemProvider.newByteChannel(UnixFileSystemProvider.java:218) ~[?:?]  
at java.nio.file.spi.FileSystemProvider.newOutputStream(FileSystemProvider.java:484) ~[?:?]  
at java.nio.file.Files.newOutputStream(Files.java:228) ~[?:?]  
at org.opensearch.performanceanalyzer.commons.event\_process.EventLogFileHandler.writeTmpFileWithPrivilege(EventLogFileHandler.java:80) [performance-analyzer-commons-1.0.0.jar:?]  
at org.opensearch.performanceanalyzer.commons.event\_process.EventLogFileHandler.lambda$writeTmpFile$0(EventLogFileHandler.java:47) [performance-analyzer-commons-1.0.0.jar:?]  
at org.opensearch.performanceanalyzer.commons.util.Util.lambda$invokePrivileged$1(Util.java:57) [performance-analyzer-commons-1.0.0.jar:?]  
at java.security.AccessController.doPrivileged(AccessController.java:318) [?:?]  
at org.opensearch.performanceanalyzer.commons.util.Util.invokePrivileged(Util.java:53) [performance-analyzer-commons-1.0.0.jar:?]  
at org.opensearch.performanceanalyzer.commons.event\_process.EventLogFileHandler.writeTmpFile(EventLogFileHandler.java:47) [performance-analyzer-commons-1.0.0.jar:?]  
at org.opensearch.performanceanalyzer.writer.EventLogQueueProcessor.purgeQueueAndPersist(EventLogQueueProcessor.java:152) [opensearch-performance-analyzer-2.9.0.0.jar:2.9.0.0]  
at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:539) [?:?]  
at java.util.concurrent.FutureTask.runAndReset(FutureTask.java:305) [?:?]  
at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:305) [?:?]  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1136) [?:?]  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635) [?:?]  
at java.lang.Thread.run(Thread.java:833) [?:?]

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/8/8f0649ed4278e738c411b01a567ec07fa32247cd.png)

**Reason for error reporting** ：Permission issues

The account used for the 1.3.0 version of Node-2 that was first launched is: elk  
The account used for the newly added data node version 2.9.0 of node-1 is: opensearch

After investigation, it was found that the error path of node-1,/dev/shm/performanceanalyzer, belongs to elk. (Previously, an elk account was used to launch a test node for a tar package, resulting in the directory belonging to elk.) Modify the corresponding directory to belong to opensearch, or modify the startup account number of node-1 to elk and simultaneously modify the data, log, and configuration directories to belong to elk

**Solution** ：  
Scheme two I used.

**Scheme one：**  
chown -R opensearch:opensearch _ **performanceanalyzer** _

**Scheme two：**

chwon -R elk:elk /etc/opensearch/  
chwon -R elk:elk /var/log/opensearch/  
chwon -R elk:elk /var/lib/opensearch/

OK

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [November 10, 2023, 12:29pm UTC](https://forum.opensearch.org/t/opensearch-startup-error-o-o-p-c-e-eventlogfilehandler-node-1-error-writing-entry-not-initialized/16575/2 "2023-11-10T12:29:26Z")

</div>

@_free What’s the reason for mixing the versions? According to your description, node-1 has version 2.9.0 and node-2 1.3.1.

---

<div class="post-metadata">

**Author:** ![\_free](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/_free/32/6381_2.png) [@\_free](https://forum.opensearch.org/u/_free)\
**Post date:** [November 10, 2023, 2:27pm UTC](https://forum.opensearch.org/t/opensearch-startup-error-o-o-p-c-e-eventlogfilehandler-node-1-error-writing-entry-not-initialized/16575/3 "2023-11-10T14:27:35Z")

</div>

Upgrade version ，The node name was not modified during previous testing

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [November 22, 2023, 7:10pm UTC](https://forum.opensearch.org/t/opensearch-startup-error-o-o-p-c-e-eventlogfilehandler-node-1-error-writing-entry-not-initialized/16575/4 "2023-11-22T19:10:09Z")

</div>

@_free Just to clarify. Are you reporting an issue here or a solution you’ve discovered?  
Any folders that OpenSeach need to write read should belong to OpenSearch user and group or user and group with ID 1000:1000.

---

<div class="post-metadata">

**Author:** ![\_free](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/_free/32/6381_2.png) [@\_free](https://forum.opensearch.org/u/_free)\
**Post date:** [November 30, 2023, 7:03am UTC](https://forum.opensearch.org/t/opensearch-startup-error-o-o-p-c-e-eventlogfilehandler-node-1-error-writing-entry-not-initialized/16575/5 "2023-11-30T07:03:21Z")

</div>

solution
