# Too many open files in Elasticsearch

**URL:** <https://discuss.elastic.co/t/too-many-open-files-in-elasticsearch/39249>\
**Category:** Elasticsearch\
**Created:** [January 14, 2016, 4:24pm UTC](https://discuss.elastic.co/t/too-many-open-files-in-elasticsearch/39249 "2016-01-14T16:24:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![constantino](https://avatars.discourse-cdn.com/v4/letter/c/53a042/32.png) [@constantino](https://discuss.elastic.co/u/constantino)\
**Post date:** [January 14, 2016, 4:24pm UTC](https://discuss.elastic.co/t/too-many-open-files-in-elasticsearch/39249/1 "2016-01-14T16:24:10Z")

</div>

Hello, I have this problema in Elasticsearch, can't solve.

[2016-01-14 10:09:34,789][WARN][netty.channel.socket.nio.AbstractNioSelector] Failed to accept a connection.  
java.io.IOException: Too many open files  
at sun.nio.ch.ServerSocketChannelImpl.accept0(Native Method)  
at sun.nio.ch.ServerSocketChannelImpl.accept(ServerSocketChannelImpl.java:241)  
at org.elasticsearch.common.netty.channel.socket.nio.NioServerBoss.process(NioServerBoss.java:100)  
at org.elasticsearch.common.netty.channel.socket.nio.AbstractNioSelector.run(AbstractNioSelector.java:337)  
at org.elasticsearch.common.netty.channel.socket.nio.NioServerBoss.run(NioServerBoss.java:42)  
at org.elasticsearch.common.netty.util.ThreadRenamingRunnable.run(ThreadRenamingRunnable.java:108)  
at org.elasticsearch.common.netty.util.internal.DeadLockProofWorker$1.run(DeadLockProofWorker.java:42)  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)

I use this input in configuration of Logstash

input {  
file {  
type =\> 'apache'  
path =\> '/etc/httpd/logs/\*'  
}

}

Use this, because i want read file access logs of apache, this files "rotate" each day.

Help me please !!!

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [January 14, 2016, 4:49pm UTC](https://discuss.elastic.co/t/too-many-open-files-in-elasticsearch/39249/2 "2016-01-14T16:49:11Z")

</div>

You could use lsof to figure out who the culprit is. It could be either be logstash or elasticsearch.

---

<div class="post-metadata">

**Author:** ![constantino](https://avatars.discourse-cdn.com/v4/letter/c/53a042/32.png) [@constantino](https://discuss.elastic.co/u/constantino)\
**Post date:** [January 14, 2016, 5:01pm UTC](https://discuss.elastic.co/t/too-many-open-files-in-elasticsearch/39249/3 "2016-01-14T17:01:20Z")

</div>

Isof ???

I not understand°° : (

---

<div class="post-metadata">

**Author:** ![constantino](https://avatars.discourse-cdn.com/v4/letter/c/53a042/32.png) [@constantino](https://discuss.elastic.co/u/constantino)\
**Post date:** [January 14, 2016, 7:55pm UTC](https://discuss.elastic.co/t/too-many-open-files-in-elasticsearch/39249/4 "2016-01-14T19:55:47Z")

</div>

ok, i use lsof and i have this

![](https://us1.discourse-cdn.com/elastic/original/2X/d/dce694167e822022425a8658aa8bf99343fecf6d.png)

Is a file with 2000 lines, it est. Have 2000 open files.

You know why have too many files open???

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:24pm UTC](https://discuss.elastic.co/t/too-many-open-files-in-elasticsearch/39249/5 "2017-07-05T23:24:22Z")

</div>


