# Logstash open\_file handle issue For Linux

**URL:** <https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959>\
**Category:** Logstash\
**Created:** [February 19, 2019, 8:10am UTC](https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959 "2019-02-19T08:10:46Z")\
**Posts on this page:** 4\
**Page:** 2

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [February 28, 2019, 5:10pm UTC](https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959/22 "2019-02-28T17:10:22Z")

</div>

If you have 5000 files discoverable files **and** you set `max_open_files => 65535` then `close_older` is irrelevant **for the purposes of managing the "sliding window" because all the files fit in the window (it does not slide)** but it can be relevant to a lower value of file handles open at the OS level.

You might want to script periodic sampling of `lsof` on Logstash while setting `close_older` to "20s", "10s", "5s" and "2s" to see whether/when the files opened by Logstash goes below 5000.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [February 28, 2019, 5:14pm UTC](https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959/23 "2019-02-28T17:14:16Z")

</div>

Because the actual value you should use is dependent on the volume and frequency of appended content and the rate at which docs can be put into Elasticsearch (filter complexity and ES load) of **your** scenario, it is not really possible for me to say "use X".

---

<div class="post-metadata">

**Author:** ![Rocky\_RK](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@Rocky\_RK](https://discuss.elastic.co/u/Rocky_RK)\
**Post date:** [March 1, 2019, 3:14am UTC](https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959/24 "2019-03-01T03:14:21Z")

</div>

Thanks @guyboertje, this helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 3:14am UTC](https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959/25 "2019-03-29T03:14:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959.md?page=1)
