# Issue in filebeat when file got rollover and deleted

**URL:** <https://discuss.elastic.co/t/issue-in-filebeat-when-file-got-rollover-and-deleted/61369>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 23, 2016, 11:02am UTC](https://discuss.elastic.co/t/issue-in-filebeat-when-file-got-rollover-and-deleted/61369 "2016-09-23T11:02:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![santhu227](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@santhu227](https://discuss.elastic.co/u/santhu227)\
**Post date:** [September 23, 2016, 11:02am UTC](https://discuss.elastic.co/t/issue-in-filebeat-when-file-got-rollover-and-deleted/61369/1 "2016-09-23T11:02:13Z")

</div>

Hi all.,  
We are using filebeat to push log to elastic search via logstash. Under heavy load the log is rolling over for every half an hour later once it crossed the number of files specified in log4j ( for say max rollover number for file is 100) the older files are getting deleted by log4j.  
But our filebeat service is still **keep on holding those files** as open even though all log are moved to elastic search and also the files got deleted in the file system. So this is leading us to **filesystem space issue**.

EX: **filebeat 30507 root 274r REG 253,8 52429356 1444109 sample.log**  
**filebeat 30507 root 275r REG 253,8 52450263 1443105 sample1.log(deleted)**  
**filebeat 30507 root 276r REG 253,8 52428841 1445076 sample2.log(deleted)**

---

<div class="post-metadata">

**Author:** ![santhu227](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@santhu227](https://discuss.elastic.co/u/santhu227)\
**Post date:** [September 26, 2016, 6:10am UTC](https://discuss.elastic.co/t/issue-in-filebeat-when-file-got-rollover-and-deleted/61369/2 "2016-09-26T06:10:02Z")

</div>

Any updates on this. I am completely blocked because of this issue.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 26, 2016, 7:34pm UTC](https://discuss.elastic.co/t/issue-in-filebeat-when-file-got-rollover-and-deleted/61369/3 "2016-09-26T19:34:33Z")

</div>

The [`close_older` option](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_close_older) should be what you're looking for. What's somewhat surprising is that it defaults to 60 minutes, so with a 30 minute rotation you shouldn't see more than two files open at the same time.

> Any updates on this. I am completely blocked because of this issue.

Do not expect people to answer questions during weekends.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 2, 2016, 7:43pm UTC](https://discuss.elastic.co/t/issue-in-filebeat-when-file-got-rollover-and-deleted/61369/4 "2016-10-02T19:43:00Z")

</div>

Which filebeat version are you using? Can you share your config file?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2016, 11:02am UTC](https://discuss.elastic.co/t/issue-in-filebeat-when-file-got-rollover-and-deleted/61369/5 "2016-10-14T11:02:43Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
