# Logstash 5.6.2 Open file limit Error

**URL:** <https://discuss.elastic.co/t/logstash-5-6-2-open-file-limit-error/106964>\
**Category:** Logstash\
**Created:** [November 9, 2017, 5:27am UTC](https://discuss.elastic.co/t/logstash-5-6-2-open-file-limit-error/106964 "2017-11-09T05:27:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![shashwat](https://avatars.discourse-cdn.com/v4/letter/s/bbe5ce/32.png) [@shashwat](https://discuss.elastic.co/u/shashwat)\
**Post date:** [November 9, 2017, 5:27am UTC](https://discuss.elastic.co/t/logstash-5-6-2-open-file-limit-error/106964/1 "2017-11-09T05:27:34Z")

</div>

Hi,

I am facing issue while running logstash. I am getting below warning in logstash logs :

"[WARN][logstash.inputs.file] Reached open files limit: 4095, set by the 'max\_open\_files' option or default, files yet to open: 1493"

How can we fix it?

Thanks,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 14, 2017, 8:01pm UTC](https://discuss.elastic.co/t/logstash-5-6-2-open-file-limit-error/106964/2 "2017-11-14T20:01:30Z")

</div>

Searching for "logstash open file limit" renders multiple results, some of which look useful.

---

<div class="post-metadata">

**Author:** ![shashwat](https://avatars.discourse-cdn.com/v4/letter/s/bbe5ce/32.png) [@shashwat](https://discuss.elastic.co/u/shashwat)\
**Post date:** [November 15, 2017, 5:28am UTC](https://discuss.elastic.co/t/logstash-5-6-2-open-file-limit-error/106964/3 "2017-11-15T05:28:44Z")

</div>

Hi Magnus,

Can you please elaborate it more? I did not get the meaning.

thanks,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 15, 2017, 6:55am UTC](https://discuss.elastic.co/t/logstash-5-6-2-open-file-limit-error/106964/4 "2017-11-15T06:55:04Z")

</div>

This topic has come up many times before. If you google "logstash open file limit" you should find useful information.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [November 15, 2017, 11:10am UTC](https://discuss.elastic.co/t/logstash-5-6-2-open-file-limit-error/106964/5 "2017-11-15T11:10:45Z")

</div>

@shashwat

1. This is a warning not an error and the frequency at which it is logged can be controlled with an ENV setting called `FILEWATCH_MAX_FILES_WARN_INTERVAL` - the default is 20 seconds. You can make this much higher once you understand the rest of this reply.
2. the limit can be increased by setting the `max_open_files` option in the plugin config.

You should not do this without understanding the internal operation because the input uses this for protection against opening and reading too many files at the same time.

Before this protection was introduced, if for example a file glob pattern yielded 1 million files then the input would open all 1 million files (or try to) and run out of file handles and this meant that the other filters or outputs could not open files or network connections.

You should see the `max_open_files` value as a sliding window of currently open files. Files are "discovered" via the glob pattern. In discovery they are not read yet, rather an internal entry is created and the files inode and size is checked against the sincedb (file based records of previous activity on an inode) if the file is new or its size has changed (up or down) the internal entry is marked for reading. Based on `max_open_files`, N number of files are added to the set of files to be read (the window). The process begins by reading a (up to) 32k chunk from each file and giving **lines** from the chunk to the file input line processing stages. When the chunk is seen to have been processed the sincedb is updated. If there are no more chunks and the `close_older` time for that file is reached the file is closed and it is removed from the window set (but not the discovered files set) - this frees up slots in the window set and so enabled the waiting files to be read.

Whether this is a problem or not depends on whether you are tailing files that are being actively written to or whether you are attempting to ingest complete files (where a repeated `stat` on the file gives the same size as the first stat).

Tailing:  
Usually the tailed files increase in size in smallish jumps and in order to responsively process these increases, all the tailed files should be in the window set. This means you should increase the `max_open_files` to be big enough for all the files you are tailing. It also means that you should consider partitioning the files so that different Logstash instances can process these files in parallel.

Read once (not tailing):  
Here the file, not seen before, is now seen to have increased in one large (and sometimes very large) jump (megabytes). These files are put in the window set and **must be read in full** before they are become eligible for the removal (via `close_older`) from the window set. Note: **eligibility is checked at the end of the window set processing loop**. This means that for very large files a small `max_open_files` (window) and a small `close_older` setting is advised. It will mean that the file input is more responsive to moving through the set of discovered files and importantly, the shutdown signal.

Further if you are using the multiline codec, a smaller window translates to a smaller working set of multiline buffers (memory usage).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2017, 11:10am UTC](https://discuss.elastic.co/t/logstash-5-6-2-open-file-limit-error/106964/6 "2017-12-13T11:10:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
