# High Disk Watermark exceeded on one or more nodes

**URL:** https://discuss.elastic.co/t/high-disk-watermark-exceeded-on-one-or-more-nodes/21282
**Category:** Elasticsearch
**Created:** [December 16, 2014, 10:28pm UTC](https://discuss.elastic.co/t/high-disk-watermark-exceeded-on-one-or-more-nodes/21282 "2014-12-16T22:28:44Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Pauline\_Kelly](https://avatars.discourse-cdn.com/v4/letter/p/f0a364/32.png) [@Pauline\_Kelly](https://discuss.elastic.co/u/Pauline_Kelly)
#### Post date: [December 16, 2014, 10:28pm UTC](https://discuss.elastic.co/t/high-disk-watermark-exceeded-on-one-or-more-nodes/21282/1 "2014-12-16T22:28:44Z")

</div>

I'm running an elk + redis stack on this machine, and just started  
collecting eventlogs via GELF from a windows server.

I had a look at the logs recently, and this came up:

[2014-12-17 09:31:03,820][WARN][cluster.routing.allocation.decider]  
[logstash test] high disk watermark [10%] exceeded on  
[7drCr113QgSM8wcjNss\_Mg][Blur] free: 632.3mb[8.4%], shards will be  
relocated away from this node

[2014-12-17 09:31:03,820][INFO][cluster.routing.allocation.decider]  
[logstash test] high disk watermark exceeded on one or more nodes,  
rerouting shards

I had a look at the size of Elasticsearches logs in /var/ and it's about  
23gb -  
I see that Elasticsearch has it's own memory heuristics but I'm not  
entirely sure how that works, or whether it's affecting this- but the logs  
aren't deleting after a week as I thought they should.

Could someone explain to me a bit more about what is going on here?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/9e132f09-1fa6-4401-af53-7167fe15c781%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9e132f09-1fa6-4401-af53-7167fe15c781%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 17, 2014, 6:48am UTC](https://discuss.elastic.co/t/high-disk-watermark-exceeded-on-one-or-more-nodes/21282/2 "2014-12-17T06:48:09Z")

</div>

It looks like this -

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

What is your actual disk usage? Can you run a curl -XGET  
localhost:9200/\_cluster/settings and see if it mentions those settings?

On 16 December 2014 at 23:28, Pauline Kelly [pauline.m.kelly1@gmail.com](mailto:pauline.m.kelly1@gmail.com)  
wrote:

> I'm running an elk + redis stack on this machine, and just started  
> collecting eventlogs via GELF from a windows server.
> 
> I had a look at the logs recently, and this came up:
> 
> [2014-12-17 09:31:03,820][WARN][cluster.routing.allocation.decider]  
> [logstash test] high disk watermark [10%] exceeded on  
> [7drCr113QgSM8wcjNss\_Mg][Blur] free: 632.3mb[8.4%], shards will be  
> relocated away from this node
> 
> [2014-12-17 09:31:03,820][INFO][cluster.routing.allocation.decider]  
> [logstash test] high disk watermark exceeded on one or more nodes,  
> rerouting shards
> 
> I had a look at the size of Elasticsearches logs in /var/ and it's about  
> 23gb -  
> I see that Elasticsearch has it's own memory heuristics but I'm not  
> entirely sure how that works, or whether it's affecting this- but the logs  
> aren't deleting after a week as I thought they should.
> 
> Could someone explain to me a bit more about what is going on here?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/9e132f09-1fa6-4401-af53-7167fe15c781%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9e132f09-1fa6-4401-af53-7167fe15c781%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/9e132f09-1fa6-4401-af53-7167fe15c781%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/9e132f09-1fa6-4401-af53-7167fe15c781%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X\_yDVNDNW3Pkyibji6Mxau1kwK95SYCOek39g5OzH19-A%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X_yDVNDNW3Pkyibji6Mxau1kwK95SYCOek39g5OzH19-A%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 12:43am UTC](https://discuss.elastic.co/t/high-disk-watermark-exceeded-on-one-or-more-nodes/21282/3 "2017-07-06T00:43:19Z")

</div>


