    I have graylog 5. and noticed that it stopped working saying that Elastick search is out of space yet I have 400 G?b available in my HyperV Machine

Indices blocked (triggered 12 hours ago)

7 indices are blocked.

  • juniper345_20: index.blocks.read_only_allow_delete
  • srx345_49: index.blocks.read_only_allow_delete
  • gl-failures_0: index.blocks.read_only_allow_delete
  • srx1500_25: index.blocks.read_only_allow_delete
  • gl-events_0: index.blocks.read_only_allow_delete
  • graylog_0: index.blocks.read_only_allow_delete
  • gl-system-events_0: index.blocks.read_only_allow_delete

Elasticsearch nodes disk usage above flood stage watermark (triggered 12 hours ago)

Elasticsearch nodes disk usage above high watermark (triggered a day ago)

I have deleted all the .gz files in both elasticsearch and graylogs logs and rebooted and still am having the same issue. No data since October 7 th

You will need to drill down into how ES is allocating space to figure out why you keep exceeding the watermark.

Please refer to these docs:

