# ES 2.0.1 - Getting huge Translogs size which is not getting cleared up in one of default five shards. Which finally causes Out Of Memory -All Shard Failure

**URL:** <https://discuss.elastic.co/t/es-2-0-1-getting-huge-translogs-size-which-is-not-getting-cleared-up-in-one-of-default-five-shards-which-finally-causes-out-of-memory-all-shard-failure/93639>\
**Category:** Elasticsearch\
**Created:** [July 18, 2017, 5:46pm UTC](https://discuss.elastic.co/t/es-2-0-1-getting-huge-translogs-size-which-is-not-getting-cleared-up-in-one-of-default-five-shards-which-finally-causes-out-of-memory-all-shard-failure/93639 "2017-07-18T17:46:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![susmita](https://avatars.discourse-cdn.com/v4/letter/s/f07891/32.png) [@susmita](https://discuss.elastic.co/u/susmita)\
**Post date:** [July 18, 2017, 5:46pm UTC](https://discuss.elastic.co/t/es-2-0-1-getting-huge-translogs-size-which-is-not-getting-cleared-up-in-one-of-default-five-shards-which-finally-causes-out-of-memory-all-shard-failure/93639/1 "2017-07-18T17:46:08Z")

</div>

We have default configurations in YML file , Among five shards ,One of the Shard is having trans logs size around 148 GB which is filling up the disk space now.

To be noted our indexing operations are write heavy.

Tried externally force Flush operations (rerun flush API) , still the trans logs didn't cleared up. No changes in trans logs size. It seems default Flush is not working and external flush is also not taking effects.

Now getting all shards failure - Out of memory issue due to uncleared large amount of trans log size.

Please help on this -

---

<div class="post-metadata">

**Author:** ![susmita](https://avatars.discourse-cdn.com/v4/letter/s/f07891/32.png) [@susmita](https://discuss.elastic.co/u/susmita)\
**Post date:** [July 18, 2017, 8:48pm UTC](https://discuss.elastic.co/t/es-2-0-1-getting-huge-translogs-size-which-is-not-getting-cleared-up-in-one-of-default-five-shards-which-finally-causes-out-of-memory-all-shard-failure/93639/2 "2017-07-18T20:48:27Z")

</div>

It seems one of the trans logs get corrupted . While trying to recover the index data got below exception-

cluster.service ] [ise-rcrt2] processing [shard-failed ([ise][4], node[P\_KdYBMqQjaRJFZ7tlYLng], [P], v[57], s[INITIALIZING], a[id=Iy9mqlhfRZutKkwXYcHKbA], unassigned\_info[[reason=ALLOCATION\_FAIL  
ED], at[2017-07-18T18:31:41.806Z], details[failed recovery, failure IndexShardRecoveryException[failed to recovery from gateway]; nested: EngineCreationFailureException[failed to recover from translog]; nested: EngineException[failed to  
recover from translog]; nested: ElasticsearchException[unexpected exception reading from translog snapshot of /opt/CSCOcpm/elasticsearch/data/ise-elasticsearch/nodes/0/indices/ise/4/translog/translog-211.tlog]; nested: EOFException[rea  
d past EOF. pos [46722580] length: [4] end: [46722580]]; ]]), message [failed recovery]]: took 40ms done applying updated cluster\_state (version: 212, uuid: UUlkU70lQcWYwkYTC1MAiA)

Below is the shards details after running the cat command for ISE index-  
ise 2 p STARTED 5084471 684.3mb 10.201.230.102 ise-rcrt2  
ise 2 r UNASSIGNED  
ise 1 p STARTED 5084818 738.2mb 10.201.230.102 ise-rcrt2  
ise 1 r UNASSIGNED  
ise 3 p STARTED 5083592 797.7mb 10.201.230.102 ise-rcrt2  
ise 3 r UNASSIGNED  
ise 4 p UNASSIGNED  
ise 4 r UNASSIGNED  
ise 0 p STARTED 5085913 689.6mb 10.201.230.102 ise-rcrt2  
ise 0 r UNASSIGNED

Why this trans logs grows so much and how to solve if can someone help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2017, 8:48pm UTC](https://discuss.elastic.co/t/es-2-0-1-getting-huge-translogs-size-which-is-not-getting-cleared-up-in-one-of-default-five-shards-which-finally-causes-out-of-memory-all-shard-failure/93639/3 "2017-08-15T20:48:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
