# Filewatch.tailmode.handlers.createinitial open\_file OPEN\_WARN\_INTERVAL is 300

**URL:** <https://discuss.elastic.co/t/filewatch-tailmode-handlers-createinitial-open-file-open-warn-interval-is-300/138175>\
**Category:** Logstash\
**Created:** [July 2, 2018, 10:42am UTC](https://discuss.elastic.co/t/filewatch-tailmode-handlers-createinitial-open-file-open-warn-interval-is-300/138175 "2018-07-02T10:42:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![usrjph](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usrjph/32/32866_2.png) [@usrjph](https://discuss.elastic.co/u/usrjph)\
**Post date:** [July 2, 2018, 10:42am UTC](https://discuss.elastic.co/t/filewatch-tailmode-handlers-createinitial-open-file-open-warn-interval-is-300/138175/1 "2018-07-02T10:42:19Z")

</div>

Hi, Logstash has started outputting the following message sometimes:

```
[2018-07-02T **10:19** :11,155][WARN][filewatch.tailmode.handlers.createinitial] open_file OPEN_WARN_INTERVAL is '300'                         
...
[2018-07-02T10:29:12,677][WARN][filewatch.tailmode.handlers.createinitial] failed to open /ssd/staging/etc/messages-20180627: #<Errno::EACCES: Permission denied - /ssd/staging/logs/etc/messages-20180627>, ["org/jruby/RubyFile.java:366:in `initialize'", "org/jruby/RubyIO.java:1154:in `open'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-file-4.1.3/lib/filewatch/watched_file.rb:73:in `open'"]                                                                                                                                   
...
[2018-07-02T **10:30** :03,804][WARN][filewatch.tailmode.handlers.createinitial] open_file OPEN_WARN_INTERVAL is '300'

```

I have corrected the permissions on the file which failed, but the fact that message appeared after hundreds of the OPEN\_WARN\_INTERVAL tells me that it is spending all that time reading the files in that input

I suspect it is caused by the number of files I have listed in my file input:

```
> /etc/logstash/conf.d/inputs.conf
file {
    path => ["/ssd/staging/ **/** / **/*", "/ssd/staging/** /**/*"]
    start_position => "beginning"
    exclude => ["*.gz", "*.xz"]
  }

> find /ssd/staging/ | wc -l
1681

```

Is there a setting to either suppress the message, increase the open file limit of the `filewatch.tailmode` program, or is the file input just not intended to watch so many files?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2018, 10:42am UTC](https://discuss.elastic.co/t/filewatch-tailmode-handlers-createinitial-open-file-open-warn-interval-is-300/138175/2 "2018-07-30T10:42:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
