# Indices blocked

**URL:** <https://community.graylog.org/t/indices-blocked/26351>\
**Category:** Graylog Central (peer support)\
**Tags:** elastic\
**Created:** [October 31, 2022, 7:42am UTC](https://community.graylog.org/t/indices-blocked/26351 "2022-10-31T07:42:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PustyB](https://avatars.discourse-cdn.com/v4/letter/p/c67d28/32.png) [@PustyB](https://community.graylog.org/u/PustyB)\
**Post date:** [October 31, 2022, 7:42am UTC](https://community.graylog.org/t/indices-blocked/26351/1 "2022-10-31T07:42:44Z")

</div>

**1. Describe your incident:**

Hi. I have a problem with Blocked Indices. Recently my disk was overflowing and I deleted several GB of stored data. Now the disk is 50% full, but the logs are not writing at all, because there is a problem like the one at the bottom in the picture. How to “unlock” Indices?

**2. Describe your environment:**

- OS Information: Ubuntu 20.04.4 LTS

- Package Version: Graylog 4.3.3+86369d3 on graylog (Private Build 1.8.0\_312 on Linux 5.4.0-122-generic)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/31705bede250e49cea92a3baa27f16d9561fe363.png)

---

<div class="post-metadata">

**Author:** ![patrickmann](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/patrickmann/32/9091_2.png) [@patrickmann](https://community.graylog.org/u/patrickmann)\
**Post date:** [October 31, 2022, 8:49am UTC](https://community.graylog.org/t/indices-blocked/26351/2 "2022-10-31T08:49:18Z")

</div>

Elastic Search has set the indices to read\_only due to exceeding high disk water mark.  
You can find a number of threads in the forum discussing this, e.g.

> [@Graylog stopped with timeout](https://community.graylog.org/t/graylog-stopped-with-timeout/21834/9):
>
> This depends on if your Graylog server resides on physical hardware or if its on a virtual machine. If its hardware either you need a new HDD and clone you graylog server to the larger drive, if your current dive has more space you can extend the portion. If your Graylog server is on a virtual machine it easy to add more space to the drive. Once you increase the volume you then need to add it to the correct portion on the Graylog server. [https://help.ubuntu.com/stable/ubuntu-help/disk-res…](https://help.ubuntu.com/stable/ubuntu-help/disk-resize.html.en)

---

<div class="post-metadata">

**Author:** ![PustyB](https://avatars.discourse-cdn.com/v4/letter/p/c67d28/32.png) [@PustyB](https://community.graylog.org/u/PustyB)\
**Post date:** [October 31, 2022, 8:56am UTC](https://community.graylog.org/t/indices-blocked/26351/3 "2022-10-31T08:56:52Z")

</div>

Thanks.

curl -XPUT -H “Content-Type: application/json” [https://localhost:9200/\_all/\_settings](https://localhost:9200/_all/_settings) -d ‘{“index.blocks.read\_only\_allow\_delete”: null}’

after clearing the disk, this command allowed me to unlock the indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 14, 2022, 8:57am UTC](https://community.graylog.org/t/indices-blocked/26351/4 "2022-11-14T08:57:14Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
