# Disk space almost filled

**URL:** <https://discuss.elastic.co/t/disk-space-almost-filled/212413>\
**Category:** Elasticsearch\
**Created:** [December 18, 2019, 10:20pm UTC](https://discuss.elastic.co/t/disk-space-almost-filled/212413 "2019-12-18T22:20:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![piyush0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush0/32/86063_2.png) [@piyush0](https://discuss.elastic.co/u/piyush0)\
**Post date:** [December 18, 2019, 10:20pm UTC](https://discuss.elastic.co/t/disk-space-almost-filled/212413/1 "2019-12-18T22:20:27Z")

</div>

Hi I have a remote elasticsearch server set up with 1 node (I cannot ssh into this)

The disk space (Total 50GB) is almost filled. Only about 1.5GB are left. But when I run `_cat/indices?v&s=store.size:desc` I can see that the indices only take up about 2GB.

My cluster is in red status. There are 1000s of unassigned shards. I know this is wrong. I want to delete red indices but every delete operation times out.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [December 18, 2019, 10:37pm UTC](https://discuss.elastic.co/t/disk-space-almost-filled/212413/2 "2019-12-18T22:37:38Z")

</div>

How much disk is allocated and do you know if elasticsearch is on it's own mount? It could be something besides elastic data filling your disk.

Elalsticsearch doesn't do log rotation, once you start getting a sick node, it will tend to write messages to /var/log/elasticsearch until that disk is full.

Without SSH, you [probably can't do "du -sh /\* | grep G" to see what is using disk 🙂

---

<div class="post-metadata">

**Author:** ![piyush0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush0/32/86063_2.png) [@piyush0](https://discuss.elastic.co/u/piyush0)\
**Post date:** [December 18, 2019, 10:42pm UTC](https://discuss.elastic.co/t/disk-space-almost-filled/212413/3 "2019-12-18T22:42:21Z")

</div>

> [@rugenl](#):
>
> How much disk is allocated and do you know if elasticsearch is on it's own mount? It could be something besides elastic data filling your disk.

How can I find this out? (Although I am very sure anything else is not installed in this machine)

I don't really care about the data now. I just want to clean up this cluster. Any advice on what can I do?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [December 18, 2019, 10:58pm UTC](https://discuss.elastic.co/t/disk-space-almost-filled/212413/4 "2019-12-18T22:58:17Z")

</div>

You need a command line and probably root access. Then if my "du" command above shows /var being the largest user, repeat with "du -sh /var/\* | grep G" and drill down.

---

<div class="post-metadata">

**Author:** ![piyush0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush0/32/86063_2.png) [@piyush0](https://discuss.elastic.co/u/piyush0)\
**Post date:** [December 18, 2019, 11:00pm UTC](https://discuss.elastic.co/t/disk-space-almost-filled/212413/5 "2019-12-18T23:00:45Z")

</div>

Thanks!

Any ideas about clearing up the cluster without taking it down?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2020, 11:00pm UTC](https://discuss.elastic.co/t/disk-space-almost-filled/212413/6 "2020-01-15T23:00:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
