# \[2.2.0\] CLOSE\_WAIT sockets/file descriptors multiplying until system crash

**URL:** <https://discuss.elastic.co/t/2-2-0-close-wait-sockets-file-descriptors-multiplying-until-system-crash/41235>\
**Category:** Logstash\
**Created:** [February 9, 2016, 2:22am UTC](https://discuss.elastic.co/t/2-2-0-close-wait-sockets-file-descriptors-multiplying-until-system-crash/41235 "2016-02-09T02:22:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikanderson753](https://avatars.discourse-cdn.com/v4/letter/e/ecd19e/32.png) [@erikanderson753](https://discuss.elastic.co/u/erikanderson753)\
**Post date:** [February 9, 2016, 2:22am UTC](https://discuss.elastic.co/t/2-2-0-close-wait-sockets-file-descriptors-multiplying-until-system-crash/41235/1 "2016-02-09T02:22:06Z")

</div>

We are currently testing out Elasticsearch 2.2.0, Logstash 2.2.0, and Kibana 4.4.0 on Ubuntu 14.04

In the past few days we have begun to have an issue with too many file descriptors being opened with the Logstash process, specifically with TCP CLOSE\_WAIT sockets . After a few minutes there are more than 600k CLOSE\_WAIT showing with: `sudo lsof | grep CLOSE_WAIT | wc -l`

To give a little background on our setup. We have all nodes configured to send their logs to a single server running logstash which then connects to our ES cluster through an nginx proxy.

I just updated to the latest Java 8 but the issue is persisting.

Has anyone had similar issues in the past that can point me in the right direction?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 10, 2016, 6:22am UTC](https://discuss.elastic.co/t/2-2-0-close-wait-sockets-file-descriptors-multiplying-until-system-crash/41235/2 "2016-02-10T06:22:48Z")

</div>

Providing your config may help resolve this 🙂

---

<div class="post-metadata">

**Author:** ![erikanderson753](https://avatars.discourse-cdn.com/v4/letter/e/ecd19e/32.png) [@erikanderson753](https://discuss.elastic.co/u/erikanderson753)\
**Post date:** [February 15, 2016, 8:25pm UTC](https://discuss.elastic.co/t/2-2-0-close-wait-sockets-file-descriptors-multiplying-until-system-crash/41235/3 "2016-02-15T20:25:22Z")

</div>

We think it had something to do with our use of an internal HAproxy on that node.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:11am UTC](https://discuss.elastic.co/t/2-2-0-close-wait-sockets-file-descriptors-multiplying-until-system-crash/41235/4 "2017-07-06T05:11:21Z")

</div>


