# Filebeat locks application logs on Windows

**URL:** <https://discuss.elastic.co/t/filebeat-locks-application-logs-on-windows/56307>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 25, 2016, 3:17pm UTC](https://discuss.elastic.co/t/filebeat-locks-application-logs-on-windows/56307 "2016-07-25T15:17:37Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 25, 2016, 5:09pm UTC](https://discuss.elastic.co/t/filebeat-locks-application-logs-on-windows/56307/2 "2016-07-25T17:09:26Z")

</div>

Filebeat does not lock the log files that it reads from. On Windows, Filebeat requests only generic read access to the file. It uses the share mode bit mask of `FILE_SHARE_READ | FILE_SHARE_WRITE | FILE_SHARE_DELETE` which can allow other applications to read/write/delete the file.

It's most likely that the application is requesting exclusive rights to the file (an empty share mode bit mask). If this is the case, Windows will prevent the application from opening the file when another application has any handle open to the file (event just for reading). Windows gives a ERROR\_SHARING\_VIOLATION in this case.

To determine the share mode bits used by your application, start the application, and then use the [Sysinternals](https://technet.microsoft.com/en-us/sysinternals/bb842062.aspx) `handle.exe` tool to see what share mode bits are set for the log file handle. For an example see this post: [File open mode](https://discuss.elastic.co/t/file-open-mode/54840)

Reference: [CreateFile function](https://msdn.microsoft.com/en-us/library/windows/desktop/aa363858(v=vs.85).aspx)

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-locks-application-logs-on-windows/56307)._
