# Reached open files limit

**URL:** <https://discuss.elastic.co/t/reached-open-files-limit/43113>\
**Category:** Logstash\
**Created:** [March 1, 2016, 12:01pm UTC](https://discuss.elastic.co/t/reached-open-files-limit/43113 "2016-03-01T12:01:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![abraham](https://avatars.discourse-cdn.com/v4/letter/a/6a8cbe/32.png) [@abraham](https://discuss.elastic.co/u/abraham)\
**Post date:** [March 1, 2016, 12:01pm UTC](https://discuss.elastic.co/t/reached-open-files-limit/43113/1 "2016-03-01T12:01:10Z")

</div>

Hi, I am new to ELK stack.  
I have been working on it for a while and it was working fine and suddenly the logs stopped loading into kibana dashboard and when i checked the log files in the logstash log file i am getting this error

**\> message=\>"Reached open files limit: 4095, set by the 'max\_open\_files' option or default, files yet to open: 16159"**

I couldn't find anything with the name **'max\_open\_files'**

---

<div class="post-metadata">

**Author:** ![mick66](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@mick66](https://discuss.elastic.co/u/mick66)\
**Post date:** [March 1, 2016, 2:59pm UTC](https://discuss.elastic.co/t/reached-open-files-limit/43113/2 "2016-03-01T14:59:24Z")

</div>

Check out the section on Open File Descriptors on this page:

[https://www.elastic.co/guide/en/elasticsearch/reference/2.2/setup-configuration.html#file-descriptors](https://www.elastic.co/guide/en/elasticsearch/reference/2.2/setup-configuration.html#file-descriptors)

It is likely that you have not set a high enough value for open files on your operating system for the user that is running ELK.

On Red Hat Linux this is set by adding soft and hard values for the nofile parameter in the /etc/security/limits.conf file, e.g.

```
username soft nofile 4096
username hard nofile 63536
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 1, 2016, 9:03pm UTC](https://discuss.elastic.co/t/reached-open-files-limit/43113/3 "2016-03-01T21:03:45Z")

</div>

What's your config look like?

---

<div class="post-metadata">

**Author:** ![abraham](https://avatars.discourse-cdn.com/v4/letter/a/6a8cbe/32.png) [@abraham](https://discuss.elastic.co/u/abraham)\
**Post date:** [March 2, 2016, 12:07pm UTC](https://discuss.elastic.co/t/reached-open-files-limit/43113/4 "2016-03-02T12:07:58Z")

</div>

Thank you It worked for me

---

<div class="post-metadata">

**Author:** ![David\_Greenshtein](https://avatars.discourse-cdn.com/v4/letter/d/ccd318/32.png) [@David\_Greenshtein](https://discuss.elastic.co/u/David_Greenshtein)\
**Post date:** [July 19, 2016, 3:55pm UTC](https://discuss.elastic.co/t/reached-open-files-limit/43113/5 "2016-07-19T15:55:58Z")

</div>

File plugin of Logstash has max\_open\_files parameter with default value 4095. See here [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-max\_open\_files](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-max_open_files)

Then to increase number of input files you need to

1. increase ulimit (operation system level) as described in one of the previous answers
2. increase LS\_OPEN\_FILES on logstash config in /etc/init.d/logstash
3. increase number of max\_open\_files on input file plugin level. max\_open\_files =\> 46000

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:47am UTC](https://discuss.elastic.co/t/reached-open-files-limit/43113/6 "2017-07-06T04:47:24Z")

</div>


