# Filebeat - 7.10.2 - Flooding Syslog with CIFS Errors

**URL:** <https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 8, 2021, 11:18am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587 "2021-02-08T11:18:29Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![scott\_stash](https://avatars.discourse-cdn.com/v4/letter/s/c89c15/32.png) [@scott\_stash](https://discuss.elastic.co/u/scott_stash)\
**Post date:** [February 8, 2021, 11:18am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587/1 "2021-02-08T11:18:29Z")

</div>

Previously I was running Filebeat 7.5 on Ubuntu 18.04. I have installed Filebeat 7.10.2 on Ubuntu 20, and now my syslog is flooded with this message while filebeat is running:

```auto
CIFS VFS: Close unmatched open

```

The configurations are the same, and the way I mount the share in /etc/fstab is Identical. I have 15-20 filebeat yml files in /etc/filebeat/inputs.d using a blob pattern.. like /nfsshare/\*\*/\_sharetype/_LOGFILE_.log

Everything appears to be working, not sure if this is an issue I need to worry about or not.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 8, 2021, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587/2 "2021-02-08T14:13:43Z")

</div>

Hi!

Not sure where this one comes from but from a quick search I see that it should be a message from kernel that has to do with volume mounts, filesharing etc.

Do you see this specific error only when running Filebeat or if you stop Filebeat the error will go away?

C.

---

<div class="post-metadata">

**Author:** ![scott\_stash](https://avatars.discourse-cdn.com/v4/letter/s/c89c15/32.png) [@scott\_stash](https://discuss.elastic.co/u/scott_stash)\
**Post date:** [February 8, 2021, 11:12pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587/3 "2021-02-08T23:12:26Z")

</div>

The messages only occur while Filebeat is running. Once I stop Filebeat they stop right away.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 9, 2021, 1:48pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587/4 "2021-02-09T13:48:28Z")

</div>

All right.

Does Filebeat run natively as process on your system or its containerised? Do you have any special mounts or shared filesystems that Filebeat access?

---

<div class="post-metadata">

**Author:** ![scott\_stash](https://avatars.discourse-cdn.com/v4/letter/s/c89c15/32.png) [@scott\_stash](https://discuss.elastic.co/u/scott_stash)\
**Post date:** [February 10, 2021, 12:16pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587/5 "2021-02-10T12:16:39Z")

</div>

It is running as a system service in a pretty bare OS. (Not containerized). It is scanning files from a network share that is mounted as a cifs share in /etc/fstab.

Filebeat 7.10.2 on Ubuntu 18.04 does not appear to have this issue.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 10, 2021, 3:31pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587/6 "2021-02-10T15:31:24Z")

</div>

Well, it should be related to the `cifs` share then, maybe because of a library change or sth. If you don't see Filebeat failing then I think you can ignore that error. Please raise an issue if you see Filebeat failing or losing events. Thanks!

---

<div class="post-metadata">

**Author:** ![scott\_stash](https://avatars.discourse-cdn.com/v4/letter/s/c89c15/32.png) [@scott\_stash](https://discuss.elastic.co/u/scott_stash)\
**Post date:** [February 18, 2021, 2:27am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587/7 "2021-02-18T02:27:19Z")

</div>

Tried the older version of CIFS same issue, kernel upgrade was done and the error went away.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2021, 4:27am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-flooding-syslog-with-cifs-errors/263587/8 "2021-03-18T04:27:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
