# Elasticsearch: Too many open files error even with 64K max file descriptor set

**URL:** <https://discuss.elastic.co/t/elasticsearch-too-many-open-files-error-even-with-64k-max-file-descriptor-set/27196>\
**Category:** Elasticsearch\
**Created:** [August 11, 2015, 3:22pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-open-files-error-even-with-64k-max-file-descriptor-set/27196 "2015-08-11T15:22:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lhorsky1](https://avatars.discourse-cdn.com/v4/letter/l/b2d939/32.png) [@lhorsky1](https://discuss.elastic.co/u/lhorsky1)\
**Post date:** [August 11, 2015, 3:22pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-open-files-error-even-with-64k-max-file-descriptor-set/27196/1 "2015-08-11T15:22:13Z")

</div>

I have a 3 node cluster (2 data/master and 1 master/no data. It is being fed by 2 logstash servers. I have everything tuned based on the production setting suggestions (max file descriptors set to 64K, setting ES Heap Size, turning off swap, enabling mlockall). Everything was running fine until it just seemingly locked up and I started getting "Too many open files" messages in the elasticsearch.log.

Is there a way to tell what pushed the data servers over the edge? Are there other performance settings to look at?

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [August 11, 2015, 5:56pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-open-files-error-even-with-64k-max-file-descriptor-set/27196/2 "2015-08-11T17:56:04Z")

</div>

Maybe you have an insanely high number of shards on your machine?

---

<div class="post-metadata">

**Author:** ![lhorsky1](https://avatars.discourse-cdn.com/v4/letter/l/b2d939/32.png) [@lhorsky1](https://discuss.elastic.co/u/lhorsky1)\
**Post date:** [August 11, 2015, 6:08pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-open-files-error-even-with-64k-max-file-descriptor-set/27196/3 "2015-08-11T18:08:37Z")

</div>

These are the current statistics:

status" : "green",  
"timed\_out" : false,  
"number\_of\_nodes" : 6,  
"number\_of\_data\_nodes" : 2,  
"active\_primary\_shards" : 281,  
"active\_shards" : 562,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 0,  
"number\_of\_pending\_tasks" : 0

Is that too many shards?

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [August 11, 2015, 6:16pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-open-files-error-even-with-64k-max-file-descriptor-set/27196/4 "2015-08-11T18:16:14Z")

</div>

This is a bit high but not insane. I'm very surprised that you manage to reach the max number of file descriptors with that many shards. Any chance that you can count how many files you have in your data directories? Also can you tell us the maximum number of file descriptors as seen by elasticsearch? [https://www.elastic.co/guide/en/elasticsearch/guide/current/\_file\_descriptors\_and\_mmap.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/_file_descriptors_and_mmap.html)

---

<div class="post-metadata">

**Author:** ![lhorsky1](https://avatars.discourse-cdn.com/v4/letter/l/b2d939/32.png) [@lhorsky1](https://discuss.elastic.co/u/lhorsky1)\
**Post date:** [August 11, 2015, 6:37pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-open-files-error-even-with-64k-max-file-descriptor-set/27196/5 "2015-08-11T18:37:19Z")

</div>

"process" : {  
"refresh\_interval\_in\_millis" : 1000,  
"id" : 1418,  
"max\_file\_descriptors" : 64000,  
"mlockall" : true

find '/usr/local/elasticsearch/data/' -type f | wc -l  
12400

Which is below the 64000 limit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:56pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-open-files-error-even-with-64k-max-file-descriptor-set/27196/6 "2017-07-05T23:56:23Z")

</div>


