Too many open files: how to fix it
Too many open files (EMFILE) means a process exceeded its file-descriptor limit. Either the ulimit is too low for the workload, or the app is leaking descriptors (unclosed files, sockets, or connections).What causes Too many open files
A default soft limit (often 1024) that is too low for a busy server; leaked connections (HTTP clients, DB connections, file handles never closed); or a connection pool without limits.
How to diagnose it
Check the limit: ulimit -n and cat /proc/<pid>/limits. Count open FDs: ls /proc/<pid>/fd | wc -l, and lsof -p <pid> to see what they are. Steadily rising FD count = a leak.
How to fix Too many open files
- Raise the file-descriptor limit. Increase the soft/hard limit in
/etc/security/limits.conf, the systemd unit (LimitNOFILE=), or the container runtime. - Find and fix the leak. If FDs grow without bound, use
lsofto find the leaking resource and ensure files/sockets/connections are closed (use pools and context managers). - Bound your connection pools. Cap HTTP/DB client pools so a burst can't exhaust descriptors.
Example log line
accept4: Too many open files (os error 24)
java.net.SocketException: Too many open files
How LogLens detects Too many open files
LogLens flags EMFILE bursts and correlates them with the rising-connection pattern that precedes them. LogLens AI is a free, self-hosted AI log analyzer that surfaces lines like this automatically, groups them into one incident, and explains them in plain language.
Related errors
FAQ
How do I check the open file limit?
Run ulimit -n for the shell limit, or cat /proc/
Why does the limit come back after a reboot?
ulimit changes in a shell are temporary. Set LimitNOFILE in the systemd unit or limits.conf for a persistent limit.