# \[SOLVED\] Filebeat keeps open files forever

**URL:** <https://discuss.elastic.co/t/solved-filebeat-keeps-open-files-forever/40098>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 26, 2016, 8:31am UTC](https://discuss.elastic.co/t/solved-filebeat-keeps-open-files-forever/40098 "2016-01-26T08:31:03Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 26, 2016, 3:16pm UTC](https://discuss.elastic.co/t/solved-filebeat-keeps-open-files-forever/40098/2 "2016-01-26T15:16:25Z")

</div>

Filebeat should latest close a file after ignore\_older, in your case 5 minutes. With the next major release we will introduce close\_older as ignore\_older was having to different purposes which could have conflicted: [https://github.com/elastic/beats/pull/718](https://github.com/elastic/beats/pull/718)

The file is kept open as filebeat doesn't know, if the file only was renamed and it will continue reading, if the file was actually deleted or it just disappeared for a moment.

About force\_close\_files: The important part is in the second part of the documentation. If you use force\_close\_files rotated files are only picked up again after scan\_frequency. If the file was removed in the meantime and not all log lines were read before rotating, these log lines are lost.

Which filebeat version are you using?

---

_[View the full topic](https://discuss.elastic.co/t/solved-filebeat-keeps-open-files-forever/40098)._
