# Elastic too many open files

**URL:** https://discuss.elastic.co/t/elastic-too-many-open-files/148549
**Category:** Elasticsearch
**Created:** [September 14, 2018, 3:49am UTC](https://discuss.elastic.co/t/elastic-too-many-open-files/148549 "2018-09-14T03:49:31Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Ilyas\_Ahsan](https://avatars.discourse-cdn.com/v4/letter/i/4af34b/32.png) [@Ilyas\_Ahsan](https://discuss.elastic.co/u/Ilyas_Ahsan)
#### Post date: [September 14, 2018, 3:49am UTC](https://discuss.elastic.co/t/elastic-too-many-open-files/148549/1 "2018-09-14T03:49:32Z")

</div>

Hai,

I have several problem after upgrading to elasticsearch, kibana, logstash v 5.6.0.  
and one of issue cannot assign unassign shard because to many open files. i have incresea open files limit to 20480 and set vm.max\_map\_count=262144 and still cannot assign .

i have read: [https://www.elastic.co/guide/en/elasticsearch/guide/master/\_file\_descriptors\_and\_mmap.html](https://www.elastic.co/guide/en/elasticsearch/guide/master/_file_descriptors_and_mmap.html)

what should i do? should i restart elasticsearch after increase limit open files?

Thank you

---

<div class="post-metadata">

### Author: ![markuchi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markuchi/32/35534_2.png) [@markuchi](https://discuss.elastic.co/u/markuchi)
#### Post date: [September 14, 2018, 4:29am UTC](https://discuss.elastic.co/t/elastic-too-many-open-files/148549/2 "2018-09-14T04:29:41Z")

</div>

We had to add "elasticsearch - nofile 65536" into /etc/security/limits.conf for centos to fix issues we had.  
[https://www.elastic.co/guide/en/elasticsearch/reference/master/setting-system-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/setting-system-settings.html)

The session for elasticsearch user will only take the new setting on the next session so elasticsearch service restart will be required.

Also this thread [After adding "elasticsearch - nofile 65536" still not enough threads are allocated](https://discuss.elastic.co/t/after-adding-elasticsearch-nofile-65536-still-not-enough-threads-are-allocated/74796)  
Says that need nproc not nofile but this conflicts with the documentation...

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [September 14, 2018, 5:09am UTC](https://discuss.elastic.co/t/elastic-too-many-open-files/148549/3 "2018-09-14T05:09:39Z")

</div>

How much data and how many shards do you have in the cluster?

---

<div class="post-metadata">

### Author: ![Ilyas\_Ahsan](https://avatars.discourse-cdn.com/v4/letter/i/4af34b/32.png) [@Ilyas\_Ahsan](https://discuss.elastic.co/u/Ilyas_Ahsan)
#### Post date: [September 14, 2018, 6:15am UTC](https://discuss.elastic.co/t/elastic-too-many-open-files/148549/4 "2018-09-14T06:15:23Z")

</div>

hi cris,

we have around 3.500 indices and 30.000 shards in cluster with 2 nodes.

---

<div class="post-metadata">

### Author: ![Ilyas\_Ahsan](https://avatars.discourse-cdn.com/v4/letter/i/4af34b/32.png) [@Ilyas\_Ahsan](https://discuss.elastic.co/u/Ilyas_Ahsan)
#### Post date: [September 14, 2018, 6:17am UTC](https://discuss.elastic.co/t/elastic-too-many-open-files/148549/5 "2018-09-14T06:17:16Z")

</div>

there is another way than restart ES?  
because we have so many shards and we stuck on 54%

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [September 14, 2018, 6:33am UTC](https://discuss.elastic.co/t/elastic-too-many-open-files/148549/6 "2018-09-14T06:33:21Z")

</div>

> [@Ilyas\_Ahsan](#):
>
> we have around 3.500 indices and 30.000 shards in cluster with 2 nodes.

That is far too much. Please read [this blog post with guidance on shards and sharding](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster), and then try to reduce that dramatically by deleting and/or reindexing data. Restoring that many shards will take time, and I am not aware of any way to speed it up, so suspect you will have to wait.

Once the cluster is back up you can try to temporarily close some indices in order to make the cluster easier to work with.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 12, 2018, 6:40am UTC](https://discuss.elastic.co/t/elastic-too-many-open-files/148549/7 "2018-10-12T06:40:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
