# Logstash close\_older in tail mode

**URL:** <https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896>\
**Category:** Logstash\
**Created:** [March 3, 2023, 1:30am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896 "2023-03-03T01:30:23Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2023, 3:13am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896/5 "2023-03-03T03:13:05Z")

</div>

On UNIX anyone who has permission to write to a directory can remove the directory entry (which is what a lot of folk mean by deleting the file). If it is the only directory entry and there are no file handles that have the file open then the file is deleted. So an external process can delete the file logstash is reading. logstash will continue to read the file, when close\_older kicks in and logstash's file handle is closed then the space occupied by the file will be freed if there are no other file handles or directory entries pointing to it. See [here](https://discuss.elastic.co/t/logstash-still-holding-onto-deleted-logstash-application-logs/325479/3) for more colour.

Windows does not work that way.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896)._
