# Filebeat and disk space

**URL:** <https://discuss.elastic.co/t/filebeat-and-disk-space/62246>\
**Category:** Beats\
**Created:** [October 5, 2016, 9:04am UTC](https://discuss.elastic.co/t/filebeat-and-disk-space/62246 "2016-10-05T09:04:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![orubin](https://avatars.discourse-cdn.com/v4/letter/o/ba8739/32.png) [@orubin](https://discuss.elastic.co/u/orubin)\
**Post date:** [October 5, 2016, 9:04am UTC](https://discuss.elastic.co/t/filebeat-and-disk-space/62246/1 "2016-10-05T09:04:26Z")

</div>

Hi,  
I'm using filebeat 1.2.3-1 and it generally works fine on most of our servers.  
Some of our servers log files using log4j and its log rotation mechanism. It looks like filebeat never closes the file handle for the last file in the logrotation. Meaning - if the rotation is for 7 files for example, the seventh file which is being deleted is always kept open by filebeat:

lr-x------ 1 root root 64 Sep 26 07:06 14 -\> /home/XXX/logs/XX.log.7 (deleted)  
lr-x------ 1 root root 64 Sep 26 07:06 14 -\> /home/XXX/logs/XX.log.7 (deleted)  
lr-x------ 1 root root 64 Sep 26 07:06 14 -\> /home/XXX/logs/XX.log.7 (deleted)  
lr-x------ 1 root root 64 Sep 26 07:06 14 -\> /home/XXX/logs/XX.log.7 (deleted)

This list keeps growing all the time

This happens even when the following parameters are set as follows:  
ignore\_older: 20m  
close\_older: 30m

These are linux servers, I didn't want to set the parameter: force\_close\_files to true.

As a result, our disk usage keeps growing continuously until the disk is full.  
I didn't find any solution online for this issue besides the parameters mentioned above which didn't help.

Thanks for your advice!  
Ofer

P.S - can an upgrade to filebeat 5.0 beta1 solve this issue? I didn't see anything related in the release notes.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 5, 2016, 6:34pm UTC](https://discuss.elastic.co/t/filebeat-and-disk-space/62246/2 "2016-10-05T18:34:03Z")

</div>

There are some cases in which in 1.x version in can come to race conditions which can also lead to open file handlers. All these should be solved in the 5.0 release as the state handling and open file handling was rewritten to solve all this issues. Upgrading to the 5.0 release should definitively solve these issues.

---

<div class="post-metadata">

**Author:** ![orubin](https://avatars.discourse-cdn.com/v4/letter/o/ba8739/32.png) [@orubin](https://discuss.elastic.co/u/orubin)\
**Post date:** [October 6, 2016, 11:03am UTC](https://discuss.elastic.co/t/filebeat-and-disk-space/62246/3 "2016-10-06T11:03:58Z")

</div>

Thanks!  
I will upgrade to 5.0 and see if that solves the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 26, 2016, 9:04am UTC](https://discuss.elastic.co/t/filebeat-and-disk-space/62246/4 "2016-10-26T09:04:31Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
