# Logstash close\_older in tail mode

**URL:** <https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896>\
**Category:** Logstash\
**Created:** [March 3, 2023, 1:30am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896 "2023-03-03T01:30:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![akassabi](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Post date:** [March 3, 2023, 1:30am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/1 "2023-03-03T01:30:23Z")

</div>

Suppose we have an input file `input.dat` and we are reading it in Logstash in `tail` mode. We set `close_older` to 10 minutes.

My questions are:

1. Is the `close_older` setting deprecated? The docs say it is "retained for backward compatibility", implying that there is a new way of doing the same thing.

2. If we don't write to `input.dat` for 10 minutes, will LS close the file handle to `input.dat`? At that time, can an external process delete the file (or archive it somewhere)?

Please note: we need to use `tail` mode, not `read` mode.

Thanks,  
Ara

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2023, 2:47am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/3 "2023-03-03T02:47:19Z")

</div>

What OS are you on?

> [@akassabi](#):
>
> Is the `close_older` setting deprecated? The docs say it is "retained for backward compatibility", implying that there is a new way of doing the same thing.

No, it is not deprecated. Before "read" mode was implemented if you wanted to read a set of files, you would use a file input in tail mode with `start => beginning`. close\_older was then used to free up file handles as it finished reading the files. You can still do that (because it has backward compatibility).

The new way of doing the same thing is read mode.

---

<div class="post-metadata">

**Author:** ![akassabi](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Post date:** [March 3, 2023, 3:04am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/4 "2023-03-03T03:04:50Z")

</div>

We are on Oracle Linux (basically, a fork of Red Hat).

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2023, 3:13am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/5 "2023-03-03T03:13:05Z")

</div>

On UNIX anyone who has permission to write to a directory can remove the directory entry (which is what a lot of folk mean by deleting the file). If it is the only directory entry and there are no file handles that have the file open then the file is deleted. So an external process can delete the file logstash is reading. logstash will continue to read the file, when close\_older kicks in and logstash's file handle is closed then the space occupied by the file will be freed if there are no other file handles or directory entries pointing to it. See [here](https://discuss.elastic.co/t/logstash-still-holding-onto-deleted-logstash-application-logs/325479/3) for more colour.

Windows does not work that way.

---

<div class="post-metadata">

**Author:** ![akassabi](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Post date:** [March 3, 2023, 3:25am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/6 "2023-03-03T03:25:48Z")

</div>

Right. I knew that. We **want** LS to release the file handle as soon as `close_older` kicks in so that the file space can be cleaned up. We just weren't sure whether LS would release the file handle immediately or wait until it reached `max_open_files` or whether it just set an internal flag to ignore the file.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2023, 4:05am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/7 "2023-03-03T04:05:55Z")

</div>

Every time it processes watched files (I think this is every five seconds) the code will [check](https://github.com/logstash-plugins/logstash-input-file/blob/9fe467cdee1c87220b13ffacc14766018a94fd66/lib/filewatch/tail_mode/processor.rb#L247) if any files are closeable. If closing old files is enabled then it just [checks](https://github.com/logstash-plugins/logstash-input-file/blob/9fe467cdee1c87220b13ffacc14766018a94fd66/lib/filewatch/watched_file.rb#L413) if the last time data was read from the file was more than close\_older seconds ago. If it was it closes the file handle.

---

<div class="post-metadata">

**Author:** ![akassabi](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Post date:** [March 3, 2023, 4:17am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/8 "2023-03-03T04:17:43Z")

</div>

Oh cool. This is exactly what I needed. Thanks!

---

<div class="post-metadata">

**Author:** ![akassabi](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Post date:** [March 3, 2023, 4:26am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/9 "2023-03-03T04:26:01Z")

</div>

Wait! There is a problem. The [docs](https://www.elastic.co/guide/en/logstash/7.17/plugins-inputs-file.html#plugins-inputs-file-close_older) say that the default value of `close_older` is 1 hour, but we have seen files that were unreleased and they were older than 1 hour. Are the docs wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2023, 4:26am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/10 "2023-03-31T04:26:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
