I am running 3.0.2. My server lvm became full and so my graylog server stopped working. The web page would not even come up because it was on the same lvm that was full. I deleted one really large elasticsearch log file to free up space. Now I can access the webpage but no logs are being shown despite graylog reporting in the GUI that it is receiving messages and the inputs are running.
I want to delete some of my indices to free up space but I don’t understand how to do that or even which ones to delete graylog_0, graylog_1, … graylog_6?
I looked at the documentation at this link:
I don’t see the same options to work with indices though. The link shows these options:
But this is what I see:
No logs being shown…
I know there is a command line way to delete the indices but I just don’t know which ones to delete.
graylog-server]# curl http://localhost:9200/_cat/indices
green open graylog_6 c08EFCCQSfCOUOHlI-FMGQ 1 0 15351294 0 22.7gb 22.7gb
green open graylog_1 w8YmAdDNQ6e8-ua2XGhOmQ 1 0 178 0 143.6kb 143.6kb
green open graylog_3 cackD1YeR46BN0ixyN3Hgg 1 0 20000769 0 31.9gb 31.9gb
green open graylog_4 yXfNafLjT4WLKBS2zGuH1A 1 0 20000030 0 31.1gb 31.1gb
green open graylog_5 cjh0Yy36TE6NvH0ykMG31g 1 0 20000015 0 30.7gb 30.7gb
green open graylog_0 bUU9D9HiSWmvT4uPugKJkw 1 0 1229 0 1.2mb 1.2mb
green open graylog_2 11DsiTZLQ5eGMwy6kc5X6w 1 0 20000043 0 26.9gb 26.9gb
Any idea where I should look to see why logs are no longer showing?