# Enhanced respone to fsnotify queue overflow errors

**URL:** <https://discuss.elastic.co/t/enhanced-respone-to-fsnotify-queue-overflow-errors/342555>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [September 7, 2023, 9:19pm UTC](https://discuss.elastic.co/t/enhanced-respone-to-fsnotify-queue-overflow-errors/342555 "2023-09-07T21:19:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![James\_Nelson1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/james_nelson1/32/121690_2.png) [@James\_Nelson1](https://discuss.elastic.co/u/James_Nelson1)\
**Post date:** [September 7, 2023, 9:19pm UTC](https://discuss.elastic.co/t/enhanced-respone-to-fsnotify-queue-overflow-errors/342555/1 "2023-09-07T21:19:51Z")

</div>

Hi Auditbeat folks. I'm considering a feature request, or maybe even a PR to enhance Auditbeat's file\_integrity behavior on Linux platforms when the "fsnotify queue overflow" message is encountered. See eventreader\_fsnotify.go#L165-L170

The current behavior of Auditbeat is to log the message and then carry on as-is. I'd like to propose a non-default configuration option that would cause auditbeat to perform it's "scan-on-start" behavior when this overflow message is encountered. The reason for this is that file changes that were unable to be pushed into the underlying inotify queue will not be noticed by auditbeat until either the file is changed again, or until the auditbeat service is restarted. While the event(s) that didn't make it into the queue initially are well and truly gone, this new behavior would at least capture the fact that some change occurred.

This isn't a critical need, imo, as there are operational workarounds, e.g. detect the problem via log inspection and manually restart the audtibeat service, modify OS settings to increase queue size thereby minimizing the likelihood of the overflow, etc. The point would be to reduce the need for such workarounds in the first place. Also, I have no idea how useful this would be to the broader community. But it would indeed be handy for us.

Does anyone have thoughts/opinions/ideas? I'd love to hear them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2023, 11:20pm UTC](https://discuss.elastic.co/t/enhanced-respone-to-fsnotify-queue-overflow-errors/342555/2 "2023-10-05T23:20:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
