Unable to get any data on streams

(Blason) #1

Hi there,

I am facing an issue with Graylog indices, my server HD got full hence Graylog stopped and I could not access graylog console. Since I first had to free up the disk space I had delete few old indices from Curl command line that is

curl -XDELEET and so on

After this I see the graylog has started however messages were not dumping in any of the indices however I see on the top that messages are being accepted but not sure where are those being stored.

Any clue what could have gone wrong?

(Tess) #2

I recall another recent discussion that mentioned ElasticSearch having lots of trouble after its storage space had filled up. Could be that your Elastic instance has gone tits-up.

(Blason) #3

Well I tried that but nothing worked. I guess reinstalling ES should do the trick? or any other measure you can recommend?

(Jan Doberstein) #4

what is in your Graylog server.log ? If the disk where the Graylog journal is located was full before the journal actually has grown to its max size, the journal is corrupt and you need to delete the message journal.

(Tess) #5

Reinstalling / wiping ElasticSearch is also a bit dramatic :slight_smile: Is this your DEV/TEST environment? Or worse, production data?