I’m an running Greylog 3.0.2 as an appliance. In the last few days I noticed there are no messages that are being captured as a result of index failures.
The error messages are:
There were 203,523 failed indexing attempts in the last 24 hours.
the calculation of index rotation might not be right for the available disk space. That is not done automatically. You need to calculate and configure on your own.
After you have released disk space the posted command is the right that elasticsearch accept messages again.
What the right solution for you is - add more disk space or change watermark settings highly depends on your needs. That can’t someone without your knowledge answer.
with the current version you need to adjust the watermark configuration from the command line - or set this is in the elasticsearch configuration file.