# Filebeat too many open files error when number of log files bigger than 1024

**URL:** <https://discuss.elastic.co/t/filebeat-too-many-open-files-error-when-number-of-log-files-bigger-than-1024/59518>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 1, 2016, 8:50am UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-error-when-number-of-log-files-bigger-than-1024/59518 "2016-09-01T08:50:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vin](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@vin](https://discuss.elastic.co/u/vin)\
**Post date:** [September 1, 2016, 8:50am UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-error-when-number-of-log-files-bigger-than-1024/59518/1 "2016-09-01T08:50:36Z")

</div>

Filebeat Version : 1.2.3  
OS: CentOS 7 (Docker)  
Error Msg: 2016-09-01T08:20:48Z ERR Stop Harvesting. Unexpected file opening error: open xxx: too many open files

ulimit -a | grep "open files"  
open files (-n) **65536**

/etc/security/limits.conf:

- soft nofile 65536
- hard nofile 65536

/etc/sysctl.conf:  
fs.file-max = 655360

as 31498 is the pid of filebeat:  
cat /proc/31498/limits | grep "Max open files"  
Max open files **1024** 4096 files

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 1, 2016, 10:32am UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-error-when-number-of-log-files-bigger-than-1024/59518/2 "2016-09-01T10:32:22Z")

</div>

Just two days ago we introduce a config option to limit the number of open harvesters (=file handlers): [https://github.com/elastic/beats/pull/2417](https://github.com/elastic/beats/pull/2417) If you would like to test this you can use the nightly builds here: [https://beats-nightlies.s3.amazonaws.com/index.html?prefix=filebeat/](https://beats-nightlies.s3.amazonaws.com/index.html?prefix=filebeat/)

---

<div class="post-metadata">

**Author:** ![vin](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@vin](https://discuss.elastic.co/u/vin)\
**Post date:** [September 7, 2016, 3:34am UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-error-when-number-of-log-files-bigger-than-1024/59518/3 "2016-09-07T03:34:39Z")

</div>

Thanks for your answer.

But I want figure out why filebeat can only open 1024 files for harvesting? Is there someway to unlimit it? I changed system limit settings, but it had no effect on filebeat process.

---

<div class="post-metadata">

**Author:** ![vin](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@vin](https://discuss.elastic.co/u/vin)\
**Post date:** [September 8, 2016, 2:21am UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-error-when-number-of-log-files-bigger-than-1024/59518/4 "2016-09-08T02:21:14Z")

</div>

Finally I got the solution, in CentOS 7 / RHEL 7, SysV is replaced by Systemd, and as aresult modifying /etc/security/limits.conf has no effect on service of systemd. I modified /usr/lib/systemd/system/filebeat.service to change the open file limit:

> [Service]  
> LimitNOFILE=100000

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 8, 2016, 10:55am UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-error-when-number-of-log-files-bigger-than-1024/59518/5 "2016-09-08T10:55:26Z")

</div>

@vin Glad you found a solution and thanks for posting it here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2016, 8:50am UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-error-when-number-of-log-files-bigger-than-1024/59518/6 "2016-09-22T08:50:44Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
