Graylog not processing messages after crash (ran out of space)

I’m not sure if Elasticsearch does this everytime, but it sounds like Elasticsearch made all of its indices read only.

Check this thread on some insight.

In my experience, the journal will fill to about 104%, but then it will start purging messages… oldest first to free up room for the newest messages. you can expand your journal size, but it sounds like once you reenable write on your elasticsearch indices, you should be fine.

hth

1 Like