# Unprocessed Messages in Journal

**URL:** <https://community.graylog.org/t/unprocessed-messages-in-journal/2030>\
**Category:** Graylog Central (peer support)\
**Created:** [August 9, 2017, 4:11pm UTC](https://community.graylog.org/t/unprocessed-messages-in-journal/2030 "2017-08-09T16:11:41Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![GTownson](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gtownson/32/793_2.png) [@GTownson](https://community.graylog.org/u/GTownson)\
**Post date:** [August 9, 2017, 4:11pm UTC](https://community.graylog.org/t/unprocessed-messages-in-journal/2030/1 "2017-08-09T16:11:42Z")

</div>

We keep getting the issue of the journal filling with unprocessed messages. I have found the solutions of: Removing and recreating the internal ‘server.log’ text file or fully deleting the ‘journal’ file.  
What I would like to know is why does this issue keep occurring? It is not viable for us to have to go into the back-end of our Graylog each day to resolve this issue and I would like the be able to stop it all together, has anyone got any ideas as to why this occurs?

Regards,

G

---

<div class="post-metadata">

**Author:** ![HanSolo71](https://avatars.discourse-cdn.com/v4/letter/h/6a8cbe/32.png) [@HanSolo71](https://community.graylog.org/u/HanSolo71)\
**Post date:** [August 9, 2017, 4:19pm UTC](https://community.graylog.org/t/unprocessed-messages-in-journal/2030/2 "2017-08-09T16:19:00Z")

</div>

What error messages do you see in your logs?

---

<div class="post-metadata">

**Author:** ![GTownson](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gtownson/32/793_2.png) [@GTownson](https://community.graylog.org/u/GTownson)\
**Post date:** [August 9, 2017, 4:27pm UTC](https://community.graylog.org/t/unprocessed-messages-in-journal/2030/3 "2017-08-09T16:27:21Z")

</div>

I don’t believe we see anything, however I will have a look again when it goes down next.  
I will also look into the ElasticSearch logs.

Regards,

G

---

<div class="post-metadata">

**Author:** ![HanSolo71](https://avatars.discourse-cdn.com/v4/letter/h/6a8cbe/32.png) [@HanSolo71](https://community.graylog.org/u/HanSolo71)\
**Post date:** [August 9, 2017, 4:31pm UTC](https://community.graylog.org/t/unprocessed-messages-in-journal/2030/4 "2017-08-09T16:31:35Z")

</div>

Check your ES logs, I just corrected the same thing because ES was getting to many many fields for a single index (1000). Perhaps this can help you.

> [@Graylog: ES Log: Limit of total fields \[1000\] in index \[graylog\_519\] has been exceeded and no longer processing](https://community.graylog.org/t/graylog-es-log-limit-of-total-fields-1000-in-index-graylog-519-has-been-exceeded-and-no-longer-processing/2009/1):
>
> I have seen this a few times now, restarting generally fixes the issues though. I have had a couple of times now, my systems will take in messages but will not output messages anymore. [image] Output from curl -XGET localhost:9200/\_cluster/health?pretty=true { “cluster\_name” : “graylog”, “status” : “yellow”, “timed\_out” : false, “number\_of\_nodes” : 1, “number\_of\_data\_nodes” : 1, “active\_primary\_shards” : 465, “active\_shards” : 465, “relocating\_shards” : 0, “initializing\_sh…

---

<div class="post-metadata">

**Author:** ![GTownson](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gtownson/32/793_2.png) [@GTownson](https://community.graylog.org/u/GTownson)\
**Post date:** [August 10, 2017, 9:07am UTC](https://community.graylog.org/t/unprocessed-messages-in-journal/2030/5 "2017-08-10T09:07:14Z")

</div>

Checked the logs and all I could find was the disk usage was over 85% and then the disk went 100% full. I believe that this was the cause of the issue, I will give it a few hours to ensure we don’t run into this problem again.

Regards,

G

---

<div class="post-metadata">

**Author:** ![HanSolo71](https://avatars.discourse-cdn.com/v4/letter/h/6a8cbe/32.png) [@HanSolo71](https://community.graylog.org/u/HanSolo71)\
**Post date:** [August 10, 2017, 12:50pm UTC](https://community.graylog.org/t/unprocessed-messages-in-journal/2030/6 "2017-08-10T12:50:50Z")

</div>

That will absolutely cause issues. Make sure you have enough space for your journal and ES to be happy or the system will crash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 24, 2017, 1:02pm UTC](https://community.graylog.org/t/unprocessed-messages-in-journal/2030/7 "2017-08-24T13:02:28Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
