# Close\_removed does not work as expected on Windows

**URL:** <https://discuss.elastic.co/t/close-removed-does-not-work-as-expected-on-windows/164768>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 18, 2019, 10:06am UTC](https://discuss.elastic.co/t/close-removed-does-not-work-as-expected-on-windows/164768 "2019-01-18T10:06:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![CaptainAye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/captainaye/32/37271_2.png) [@CaptainAye](https://discuss.elastic.co/u/CaptainAye)\
**Post date:** [January 18, 2019, 10:06am UTC](https://discuss.elastic.co/t/close-removed-does-not-work-as-expected-on-windows/164768/1 "2019-01-18T10:06:08Z")

</div>

Hi,

I use Filebeat 6.5.4 and I have a problem with close\_removed attribute. I have an application with rotating logs hosted on Windows. When Elasticsearch is down for some time, Logstash persistent\_queue is getting full and Filebeat's output to Logstash is blocked. Then, the harvester cannot release the files. When Logger tries to rotate file, the last rotated file is not removed and whole rotation is blocked, resulting in the active file's size growing above the limit. Such situation does not seem to happen with close\_renamed file, which works as expected and closes the file once its renamed. One workaround would be to use close\_timeout, but I would like to avoid a possibility of splitting multiline event.

Is it a close\_removed bug that is locked or is there another option which can help me solving this problem?

Exception in Filebeat logs:

```auto
log/input.go:209	input state for D:\logs\app\app.log.5 was not removed: CreateFile D:\logs\app\app.log.5: Access is denied.

```

My filebeat config (I use close\_timeout at the moment but I would like to avoid it)

```auto
- type: log
  enabled: true
  close_renamed: true
  close_removed: true
  close_inactive: 30s
  close_timeout: 2m
  fields:
   application_type: application
  paths:
   - D:\logs\app\app.log*
  multiline:
    pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
    negate: true
    match: after

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2019, 10:06am UTC](https://discuss.elastic.co/t/close-removed-does-not-work-as-expected-on-windows/164768/2 "2019-02-15T10:06:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
