# Indices blocked

**URL:** <https://community.graylog.org/t/indices-blocked/26351>\
**Category:** Graylog Central (peer support)\
**Tags:** elastic\
**Created:** [October 31, 2022, 7:42am UTC](https://community.graylog.org/t/indices-blocked/26351 "2022-10-31T07:42:44Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![patrickmann](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/patrickmann/32/9091_2.png) [@patrickmann](https://community.graylog.org/u/patrickmann)\
**Post date:** [October 31, 2022, 8:49am UTC](https://community.graylog.org/t/indices-blocked/26351/2 "2022-10-31T08:49:18Z")

</div>

Elastic Search has set the indices to read\_only due to exceeding high disk water mark.  
You can find a number of threads in the forum discussing this, e.g.

> [@Graylog stopped with timeout](https://community.graylog.org/t/graylog-stopped-with-timeout/21834/9):
>
> This depends on if your Graylog server resides on physical hardware or if its on a virtual machine. If its hardware either you need a new HDD and clone you graylog server to the larger drive, if your current dive has more space you can extend the portion. If your Graylog server is on a virtual machine it easy to add more space to the drive. Once you increase the volume you then need to add it to the correct portion on the Graylog server. [https://help.ubuntu.com/stable/ubuntu-help/disk-res…](https://help.ubuntu.com/stable/ubuntu-help/disk-resize.html.en)

---

_[View the full topic](https://community.graylog.org/t/indices-blocked/26351)._
