# Failed to accept a connection

**URL:** <https://discuss.elastic.co/t/failed-to-accept-a-connection/37338>\
**Category:** Elasticsearch\
**Created:** [December 16, 2015, 10:43am UTC](https://discuss.elastic.co/t/failed-to-accept-a-connection/37338 "2015-12-16T10:43:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [December 16, 2015, 10:43am UTC](https://discuss.elastic.co/t/failed-to-accept-a-connection/37338/1 "2015-12-16T10:43:05Z")

</div>

Hi,

when I am running elasticsearch along with around 10 logstash config files .  
I am getting an error \> Failed to accept a connection.

> java.io.IOException: Too many open files

and elasticsearch stops running after that.

I have already increased the ulimit to 155500  
But still getting the same error...  
How to resolve this

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 16, 2015, 11:01am UTC](https://discuss.elastic.co/t/failed-to-accept-a-connection/37338/2 "2015-12-16T11:01:52Z")

</div>

1st guess: you have a lot of shards per node?

---

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [December 17, 2015, 6:02am UTC](https://discuss.elastic.co/t/failed-to-accept-a-connection/37338/3 "2015-12-17T06:02:58Z")

</div>

> [@dadoonet](#):
>
> you have a lot of shards per node

I am using client node for indexing the data and 1 master and 2 data node . I have around 15 indexes available each of them having 5 shards and 1 replica

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 17, 2015, 7:37am UTC](https://discuss.elastic.co/t/failed-to-accept-a-connection/37338/4 "2015-12-17T07:37:20Z")

</div>

Unless you really need 5 shards per index, I'd reduce this number ideally to 1.

That said, the number of shards you have is not that big. Did you check that ulimit has been applied correctly (using nodes info API)?

---

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [December 18, 2015, 5:42pm UTC](https://discuss.elastic.co/t/failed-to-accept-a-connection/37338/5 "2015-12-18T17:42:11Z")

</div>

Thanks David  
I have checked the ulimit and it is applied correctly..  
(How to figure it out with node info api )

So when large number of conf file is running simultaneously, master is going down.  
Is it something that each transaction in logstash to es treated as opening a file ?

What if I will run all the conf file and send the output to Kafka and then a centralize logstash will get the data from Kafka and will send to es ? Would it be a better solution ?

---

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [December 22, 2015, 12:47pm UTC](https://discuss.elastic.co/t/failed-to-accept-a-connection/37338/6 "2015-12-22T12:47:18Z")

</div>

when I run all the conf file and send the output to Kafka and then a centralize logstash will get the data from Kafka and will send to es . It is running fine .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:29pm UTC](https://discuss.elastic.co/t/failed-to-accept-a-connection/37338/7 "2017-07-05T23:29:19Z")

</div>


