# Disk space is 100% after running a "delete by query" in devtool in kibana

**URL:** <https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647>\
**Category:** Elasticsearch\
**Created:** [May 17, 2023, 10:12am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647 "2023-05-17T10:12:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanjeevtomar](https://avatars.discourse-cdn.com/v4/letter/s/71e660/32.png) [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Post date:** [May 17, 2023, 10:12am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647/1 "2023-05-17T10:12:45Z")

</div>

After running the query below, server space is getting full in all data nodes ( ELK cluster: 3 masters, 3 data, 1 kibana node).

POST /apic\_sandbox/\_delete\_by\_query?wait\_for\_completion=false //change index here accordingly  
{  
"query": {  
"bool": {  
"must": [  
{  
"match\_phrase": {  
"catalog\_name": "sandbox" //change catalog name accordingly  
}  
}  
],  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "2022-07-15T18:00:00+05:30", //change the timestamp for which you need to delete  
"lt": "2022-07-15T19:00:00+05:30"  
}  
}  
}  
]  
}  
kindly help!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 18, 2023, 9:21am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647/2 "2023-05-18T09:21:09Z")

</div>

I don't think that the query cause the problem.

There is a useful command for top 10 largest directories:  
`du -h / | sort -rh | head -10`  
In few iterations, for instance 1. du -h /var 2. du -h /var/logs will lead you what to clean.

If you don't need, remove/move old ES logs, then if is possible clean /tmp directory, then other unused directories. Be aware, if you delete for instance 100 MB data will have immediately -100 MB on the disk and Lucene has own internal mechanism for releasing free disk space.

---

<div class="post-metadata">

**Author:** ![sanjeevtomar](https://avatars.discourse-cdn.com/v4/letter/s/71e660/32.png) [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Post date:** [May 18, 2023, 12:24pm UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647/3 "2023-05-18T12:24:08Z")

</div>

Thanks! @Rios for reply

I think issues are with tasks or processes which are not releasing disk. These processes start to resume when I start service.  
After adding another disk to the cluster it starts consuming that disk space also.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 18, 2023, 3:07pm UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647/4 "2023-05-18T15:07:01Z")

</div>

You have multiple disks on a node?

---

<div class="post-metadata">

**Author:** ![sanjeevtomar](https://avatars.discourse-cdn.com/v4/letter/s/71e660/32.png) [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Post date:** [May 19, 2023, 4:19am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647/5 "2023-05-19T04:19:11Z")

</div>

disk added to LVM

---

<div class="post-metadata">

**Author:** ![sanjeevtomar](https://avatars.discourse-cdn.com/v4/letter/s/71e660/32.png) [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Post date:** [May 19, 2023, 5:24am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647/6 "2023-05-19T05:24:34Z")

</div>

how to stop the \_forcemerge if it is still in running condition

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2023, 5:25am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647/7 "2023-06-16T05:25:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
