# Logstash close file handles?

**URL:** <https://discuss.elastic.co/t/logstash-close-file-handles/1706>\
**Category:** Logstash\
**Created:** [June 2, 2015, 10:53am UTC](https://discuss.elastic.co/t/logstash-close-file-handles/1706 "2015-06-02T10:53:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Siddharth\_Trikha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/siddharth_trikha/32/133867_2.png) [@Siddharth\_Trikha](https://discuss.elastic.co/u/Siddharth_Trikha)\
**Post date:** [June 2, 2015, 10:53am UTC](https://discuss.elastic.co/t/logstash-close-file-handles/1706/1 "2015-06-02T10:53:43Z")

</div>

**BACKGROUND:**

We have `rsyslog` creating log files directories like: `/var/log/rsyslog/SERVER-NAME/LOG-DATE/LOG-FILE-NAME`  
So multiple servers are spilling out their logs of different dates to a central location.

Now to read these logs and store them in elasticsearch for analysing I have my logstash config file something like this:

```
file{
   path => /var/log/rsyslog/**/*.log
}

```

**ISSUE :**

Now after some time no of log files get increased to a big number. As logtsash keeps the file handle open for every file in its purview even though its of no use after reading the file as log file for a particular date will not be updated after that date.  
I have increased the file openings limit to 65K in `/etc/security/limits.conf`

Can we make logstash close the handle after some time ??

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:38am UTC](https://discuss.elastic.co/t/logstash-close-file-handles/1706/2 "2017-07-06T05:38:48Z")

</div>


