# Filebeat is not closig the file descriptor and the file descriptors are dangling, when the file is deleted/renamed

**URL:** https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-and-the-file-descriptors-are-dangling-when-the-file-is-deleted-renamed/123600
**Category:** Beats
**Tags:** filebeat
**Created:** [March 12, 2018, 5:19pm UTC](https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-and-the-file-descriptors-are-dangling-when-the-file-is-deleted-renamed/123600 "2018-03-12T17:19:15Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![swethamahesh](https://avatars.discourse-cdn.com/v4/letter/s/8c91f0/32.png) [@swethamahesh](https://discuss.elastic.co/u/swethamahesh)
#### Post date: [March 12, 2018, 5:19pm UTC](https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-and-the-file-descriptors-are-dangling-when-the-file-is-deleted-renamed/123600/1 "2018-03-12T17:19:15Z")

</div>

Hi,

We are still facing same issue that file descriptors are dangling.

for reference:

> [@Filebeat is not closig the file descriptor once the file is deleted/renamed](https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-once-the-file-is-deleted-renamed/104077/23):
>
> Few last filebeat statistic strings: 2017-11-10T13:40:12Z INFO Non-zero metrics in the last 1m0s: filebeat.harvester.open\_files=1 filebeat.harvester.running=1 filebeat.harvester.started=1 libbeat.logstash.call\_count.PublishEvents=21 libbeat.logstash.publish.read\_bytes=126 libbeat.logstash.publish.write\_bytes=6709789 libbeat.logstash.published\_and\_acked\_events=42844 libbeat.publisher.published\_events=42839 publish.events=43008 registrar.states.update=43008 registrar.writes=21 2017-11-10T13:41:…

> [@Filebeat is not closig the file descriptor, when the file is deleted/renamed](https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-when-the-file-is-deleted-renamed/115819/2):
>
> Hi @swethamahesh, Could you share the logs of filebeat for the period where you do the file renaming? Please run it with these parameters: -d prospector -v

Do we have to update the logstash version from logstash-5.2.1-1.noarch to logstash-5.6

Need your assistance on this issue.

Thanks in Advance,  
Swetha.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [March 14, 2018, 8:33am UTC](https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-and-the-file-descriptors-are-dangling-when-the-file-is-deleted-renamed/123600/2 "2018-03-14T08:33:36Z")

</div>

I think to really get to the bottom of this problem we need the full config file you use and the debug log as requested previously.

In general if you want to "force close" files where reading was not finished, you can use the `close_timeout` config option [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#close-timeout](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#close-timeout)

---

<div class="post-metadata">

### Author: ![swethamahesh](https://avatars.discourse-cdn.com/v4/letter/s/8c91f0/32.png) [@swethamahesh](https://discuss.elastic.co/u/swethamahesh)
#### Post date: [March 14, 2018, 5:30pm UTC](https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-and-the-file-descriptors-are-dangling-when-the-file-is-deleted-renamed/123600/3 "2018-03-14T17:30:34Z")

</div>

Hi,

We can share the config file.

do you want both filebeat and logstash config file.

Thanks,  
Swetha. M

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [March 15, 2018, 12:29pm UTC](https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-and-the-file-descriptors-are-dangling-when-the-file-is-deleted-renamed/123600/4 "2018-03-15T12:29:10Z")

</div>

So far I would focus on the once from Filebeat. The important part here are the log files.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 12, 2018, 12:29pm UTC](https://discuss.elastic.co/t/filebeat-is-not-closig-the-file-descriptor-and-the-file-descriptors-are-dangling-when-the-file-is-deleted-renamed/123600/5 "2018-04-12T12:29:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
