# Disk usage exceed in Elastic search after logstash upgrade

**URL:** <https://discuss.elastic.co/t/disk-usage-exceed-in-elastic-search-after-logstash-upgrade/294577>\
**Category:** Kibana\
**Created:** [January 17, 2022, 11:59am UTC](https://discuss.elastic.co/t/disk-usage-exceed-in-elastic-search-after-logstash-upgrade/294577 "2022-01-17T11:59:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![abkonr](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@abkonr](https://discuss.elastic.co/u/abkonr)\
**Post date:** [January 17, 2022, 11:59am UTC](https://discuss.elastic.co/t/disk-usage-exceed-in-elastic-search-after-logstash-upgrade/294577/1 "2022-01-17T11:59:37Z")

</div>

Hi Elastic Team,

kindly help with below issue. FYI we have seen this error after logstash upgrade. i.e 7.16.2 and upgrade has been perfomed to fix the log4j vulnerability. please suggest us to fix this problem.

**error=\>{"type"=\>"cluster\_block\_exception", "reason"=\>"index [wbpreregistrationeasttwo-2021.11] blocked by: [TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block];"}}**

_Cluster settings mentioned below_.

{  
"persistent" : {  
"cluster" : {  
"routing" : {  
"allocation" : {  
"cluster\_concurrent\_rebalance" : "2",  
"node\_concurrent\_recoveries" : "2",  
"disk" : {  
"watermark" : {  
"low" : "25.0gb",  
"flood\_stage" : "1.0gb",  
"high" : "22.0gb"  
}  
},  
"node\_initial\_primaries\_recoveries" : "4"  
}  
},  
"blocks" : {  
"create\_index" : "false"  
}  
},  
"indices" : {  
"recovery" : {  
"max\_bytes\_per\_sec" : "125mb"  
}  
},  
"opendistro" : {  
"index\_state\_management" : {  
"metadata\_migration" : {  
"status" : "1"  
},  
"template\_migration" : {  
"control" : "-1"  
},  
"allow\_list" : ["delete", "transition", "rollover", "close", "open", "read\_only", "read\_write", "replica\_count", "force\_merge", "notification", "snapshot", "index\_priority", "rollup", "cold\_migration", "cold\_delete", "warm\_migration"]  
}  
},  
"search" : {  
"max\_buckets" : "10000"  
},  
"plugins" : {  
"index\_state\_management" : {  
"allow\_list" : ["delete", "transition", "rollover", "close", "open", "read\_only", "read\_write", "replica\_count", "force\_merge", "notification", "snapshot", "index\_priority", "rollup", "cold\_migration", "cold\_delete", "warm\_migration"]  
}  
}  
},  
"transient" : {  
"cluster" : {  
"routing" : {  
"allocation" : {  
"cluster\_concurrent\_rebalance" : "2",  
"node\_concurrent\_recoveries" : "2",  
"disk" : {  
"watermark" : {  
"low" : "25.0gb",  
"flood\_stage" : "1.0gb",  
"high" : "22.0gb"  
}  
},  
"exclude" : { },  
"node\_initial\_primaries\_recoveries" : "4",  
"awareness" : { }  
}  
}  
},  
"indices" : {  
"recovery" : {  
"max\_bytes\_per\_sec" : "125mb"  
}  
}  
}  
}

Regards,  
Abhishek

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 17, 2022, 1:18pm UTC](https://discuss.elastic.co/t/disk-usage-exceed-in-elastic-search-after-logstash-upgrade/294577/2 "2022-01-17T13:18:28Z")

</div>

Your flood stage is configured to trigger when you reach 1 GB of free space, the error you are receiving means that you cluster reached this level and you cannot write on it until you free space up.

You will need to delete some data from your cluster and reset the read-only index according to the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/modules-cluster.html#disk-based-shard-allocation).

Also, take a note that you seem to be using Opendistro, which is not supported here.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 18, 2022, 8:47pm UTC](https://discuss.elastic.co/t/disk-usage-exceed-in-elastic-search-after-logstash-upgrade/294577/3 "2022-01-18T20:47:43Z")

</div>

> [@leandrojmp](#):
>
> Also, take a note that you seem to be using Opendistro, which is not supported here.

This is correct, you will need to ask aws as it's their product.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2022, 8:48pm UTC](https://discuss.elastic.co/t/disk-usage-exceed-in-elastic-search-after-logstash-upgrade/294577/4 "2022-02-15T20:48:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
