# FileBeat consumes free disk space until restart

**URL:** <https://discuss.elastic.co/t/filebeat-consumes-free-disk-space-until-restart/148460>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 13, 2018, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-consumes-free-disk-space-until-restart/148460 "2018-09-13T13:26:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dns](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@dns](https://discuss.elastic.co/u/dns)\
**Post date:** [September 13, 2018, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-consumes-free-disk-space-until-restart/148460/1 "2018-09-13T13:26:22Z")

</div>

Hello!  
Could you please help with Filebeat configuration.  
Now we have a group of servers with the same Linux version (Ubuntu xenial) and the same **FileBeat 5.5.1**.  
Zabbix sometimes handles empty disk space at one server from those group.  
It happens not continuously and make some troubles until I restart filebeat service manually.  
size of logs per hour is about **3.5Gb.**

Filebeat configuration:

```auto
filebeat.prospectors:
- input_type: log
  paths:
    - /var/log/nginx/access.json.log
  exclude_lines: ["HEAD"]
  document_type: nginx-access-cdn-json

#----------------------------- Logstash output --------------------------------
output.logstash:
  hosts: ["example.com:5044"]
  compression_level: 3
  ssl.certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

logging:
  level: info

```

LogRate config for nginx:

```auto
/var/log/nginx/*.log {
	maxsize 2G
        rotate 12
        hourly
        missingok
        compress
        delaycompress
        create 0640 www-data adm
        sharedscripts
        prerotate
                if [-d /etc/logrotate.d/httpd-prerotate]; then \
                        run-parts /etc/logrotate.d/httpd-prerotate; \
                fi \
        endscript
        postrotate
	        kill -USR1 $(cat /var/run/nginx.pid)
	        sleep 1
        endscript
}

```

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 14, 2018, 9:26am UTC](https://discuss.elastic.co/t/filebeat-consumes-free-disk-space-until-restart/148460/2 "2018-09-14T09:26:45Z")

</div>

What is the output of `lsof -c filebeat`? I assume your problem is that Filebeat does not let go of file descriptors.

You could add `close_*` options to your prospector configuration. This instructs Filebeat to close files e.g when they are deleted or renamed, etc. See more on these config options: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-close-options](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-close-options)

Let me know if you need further help.

---

<div class="post-metadata">

**Author:** ![dns](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@dns](https://discuss.elastic.co/u/dns)\
**Post date:** [September 14, 2018, 10:13am UTC](https://discuss.elastic.co/t/filebeat-consumes-free-disk-space-until-restart/148460/3 "2018-09-14T10:13:36Z")

</div>

Actually i tried option close\_timeout = 2h, but it did not help me.  
Thanks for `lsof`, I am monitoring it now (works properly without any `close_*` options) and when it happens again.  
Anyway I will post a result of my investigation 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2018, 10:13am UTC](https://discuss.elastic.co/t/filebeat-consumes-free-disk-space-until-restart/148460/4 "2018-10-12T10:13:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
