# Output file rotation

**URL:** <https://discuss.elastic.co/t/output-file-rotation/26921>\
**Category:** Logstash\
**Created:** [August 5, 2015, 8:02pm UTC](https://discuss.elastic.co/t/output-file-rotation/26921 "2015-08-05T20:02:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mparthas](https://avatars.discourse-cdn.com/v4/letter/m/d78d45/32.png) [@mparthas](https://discuss.elastic.co/u/mparthas)\
**Post date:** [August 5, 2015, 8:02pm UTC](https://discuss.elastic.co/t/output-file-rotation/26921/1 "2015-08-05T20:02:05Z")

</div>

Hi,

I see that max\_size for the output file has not been implemented yet. I am finding a way where Logstash will write to an output file and close the file which then can serve as the indication that it is done with the output file. Is there a way to get this behavior ?

I am using the time format for the output file (%{+YYYY-MM-dd-HH-mm-ss}). But then it looks to me that this file can be re-opened multiple times (depending on the time of the incoming log ?) and there was no definite time where one can know that Logstash is done with it. Am i missing something ?

thanks  
mohan

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 5, 2015, 8:41pm UTC](https://discuss.elastic.co/t/output-file-rotation/26921/2 "2015-08-05T20:41:46Z")

</div>

What does "done" even mean in this context? How can Logstash possibly know when it won't receive any more messages that should be routed to the file in question?

Logstash's file output will continue writing to a file until it has been idle for a configurable amount of time, i.e. it'll basically garbage collect its open files to avoid using up all file descriptors.

---

<div class="post-metadata">

**Author:** ![mparthas](https://avatars.discourse-cdn.com/v4/letter/m/d78d45/32.png) [@mparthas](https://discuss.elastic.co/u/mparthas)\
**Post date:** [August 5, 2015, 9:11pm UTC](https://discuss.elastic.co/t/output-file-rotation/26921/3 "2015-08-05T21:11:15Z")

</div>

I need a way to specify "done". max\_size would be a good way. In the absence of that, what else can be used ?

What is that configurable time ? The problem is that if there are no activities, the file remains open and not closed. A file is closed only when there is some other activity and this file happens to remain inactive (based on my observations).

-mohan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:32am UTC](https://discuss.elastic.co/t/output-file-rotation/26921/4 "2017-07-06T05:32:47Z")

</div>


