# There were 204,800 failed indexing attempts

**URL:** <https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786>\
**Category:** Graylog Central (peer support)\
**Created:** [June 4, 2020, 2:00pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786 "2020-06-04T14:00:37Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 4, 2020, 2:00pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/1 "2020-06-04T14:00:37Z")

</div>

Hi

We run Graylog 3.2.4 (Private Build 1.8.0\_242 on Linux 4.15.0-91-generic)

we have 1 node

in the web interface I read **there were 204,800 failed indexing attempts in the last 24 hours.**

looks like 6 GB free on the disk

I see a lot of messages saying: Graylog deflector is pointing to not the newest one

How to solve the issue ?

Many thanks for your time

Kind regards

Olivier

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 5, 2020, 7:54am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/2 "2020-06-05T07:54:00Z")

</div>

he @servicedesk

check your Graylog server log - the rotation of indices was not done proper. You need to find out why that did not happen.

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 5, 2020, 7:54am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/3 "2020-06-05T07:54:49Z")

</div>

where to begin checking ?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 5, 2020, 8:11am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/4 "2020-06-05T08:11:18Z")

</div>

[https://docs.graylog.org/en/3.2/pages/configuration/file\_location.html](https://docs.graylog.org/en/3.2/pages/configuration/file_location.html)

the location depends on your OS

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 5, 2020, 8:12am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/5 "2020-06-05T08:12:19Z")

</div>

2020-06-05T07:11:01.849+02:00 WARN [Messages] Failed to index message: index=\<graylog\_0\> id= error=\<{“type”:“cluster\_block\_exception”,“reason”:“blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];”}

What is the command to add the permissions ?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 5, 2020, 8:19am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/6 "2020-06-05T08:19:59Z")

</div>

please use the search in this community.

Your Elasticsearch is running in high/low/flood watermark what means you have not enough space anymore. This is why it is read only. Add more space, delete data and make it read/write again.

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 5, 2020, 8:32am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/7 "2020-06-05T08:32:13Z")

</div>

I have tried some commands to make it read write again and they failed…

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 5, 2020, 9:23am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/8 "2020-06-05T09:23:17Z")

</div>

curl -XPUT -H “Content-Type: application/json” [https://localhost:9200/\_all/\_settings](https://localhost:9200/_all/_settings) -d ‘{“index.blocks.read\_only\_allow\_delete”: null}’

gives

curl: (35) error:1408F10B:SSL routines:ssl3\_get\_record:wrong version number

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 5, 2020, 9:43am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/9 "2020-06-05T09:43:29Z")

</div>

I tried  
curl -X PUT “localhost:9200/\_all/\_settings” -H ‘Content-Type: application/json’ -d’{ “index.blocks.read\_only” : false } }’

command is accepted but I don’t see any change

no more deflector error. but nothing to show in the gui

maybe I need to wait a certain time for it to show again in the gui ?

I cant find any errors

any help is appreciated

thanks

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 6, 2020, 8:50am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/10 "2020-06-06T08:50:55Z")

</div>

Waitng paid off. I still don’t know the command. In the end I restored the vm and resized the disk. Waited for the next rotation and the messages reappeared in the gui.

I still would like to know if we can do one of these

curl -X PUT “localhost:9200/\_all/\_settings” -H ‘Content-Type: application/json’ -d’{ “index.blocks.read\_only” : false } }’

or

curl -X PUT “localhost:9200/\_all/\_settings” -H ‘Content-Type: application/json’ -d’{ “index.blocks.read\_only” : null } }’

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 8, 2020, 6:37am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/11 "2020-06-08T06:37:52Z")

</div>

after you have enough disk space you can use the following command.

```auto
curl -X PUT "localhost:9200/_all/_settings" -H 'Content-Type: application/json' -d'{ "index.blocks.read_only" : false } }'

```

---

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [June 8, 2020, 12:10pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/12 "2020-06-08T12:10:30Z")

</div>

I suggest use a monitoring system, to monitor the numbers of index failures. In this case, you will get notification after a few problems.

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 8, 2020, 1:10pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/13 "2020-06-08T13:10:17Z")

</div>

That is a good plan! I will Try to have Nagios Read the server log and look for these lines !

Thanks macko003

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 8, 2020, 1:24pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/14 "2020-06-08T13:24:08Z")

</div>

he @servicedesk

you can query the Graylog server API for that information … check the API-Browser for the endpoints you want to monitor.

---

<div class="post-metadata">

**Author:** ![rfinney](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/rfinney/32/961_2.png) [@rfinney](https://community.graylog.org/u/rfinney)\
**Post date:** [June 9, 2020, 1:50am UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/15 "2020-06-09T01:50:24Z")

</div>

Make sure to check out the Nagios plugin, it also works on Librenms.

You can use the warn and critical flags I added a while ago. I usually set them a few thousand higher than the current levels.

> **[Graylog](https://marketplace.graylog.org/addons/9ee98819-804e-41c3-b0ac-6ca7975c1a48)**
>
> Graylog

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 9, 2020, 12:23pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/17 "2020-06-09T12:23:35Z")

</div>

Thanks rfinney… installing it now !

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 9, 2020, 1:11pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/18 "2020-06-09T13:11:00Z")

</div>

how to install it ? I have installed go and can do a version check. When running the check command it gives  
./check\_graylog2: line 6: syntax error near unexpected token `newline' ./check_graylog2: line 6: `’

---

<div class="post-metadata">

**Author:** ![rfinney](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/rfinney/32/961_2.png) [@rfinney](https://community.graylog.org/u/rfinney)\
**Post date:** [June 9, 2020, 1:26pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/19 "2020-06-09T13:26:43Z")

</div>

Should be

```auto
$ go get github.com/catinello/nagios-check-graylog2
$ mv $GOPATH/bin/nagios-check-graylog2 check_graylog2

```

> **[Graylog](https://marketplace.graylog.org/addons/9ee98819-804e-41c3-b0ac-6ca7975c1a48)**
>
> Graylog

I’m not familiar with the Nagios side after that. I use it in Librenms.

---

<div class="post-metadata">

**Author:** ![servicedesk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Post date:** [June 9, 2020, 1:38pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/20 "2020-06-09T13:38:44Z")

</div>

what is meant by : build it yourself using the go-tools ? Do I need to use the build command ?

---

<div class="post-metadata">

**Author:** ![rfinney](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/rfinney/32/961_2.png) [@rfinney](https://community.graylog.org/u/rfinney)\
**Post date:** [June 9, 2020, 1:56pm UTC](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786/21 "2020-06-09T13:56:04Z")

</div>

If I recall correctly go get is all you need. But it’s been a while since I’ve used it.

[Next page](https://community.graylog.org/t/there-were-204-800-failed-indexing-attempts/15786.md?page=2)
