# High disk watermark in elastcisearch

**URL:** <https://discuss.elastic.co/t/high-disk-watermark-in-elastcisearch/2666>\
**Category:** Elasticsearch\
**Created:** [June 15, 2015, 6:40am UTC](https://discuss.elastic.co/t/high-disk-watermark-in-elastcisearch/2666 "2015-06-15T06:40:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [June 15, 2015, 6:40am UTC](https://discuss.elastic.co/t/high-disk-watermark-in-elastcisearch/2666/1 "2015-06-15T06:40:16Z")

</div>

Hello,  
I am running ELK 1.5.2 n RHEL 6.  
Everything was fine before I see below error in elasticsearch.log  
Now there are no logs coming on Kibana.  
My question are.  
Are those logs going to some other location? Do I need to configure kibana to read from that index?  
OR are those logs lost due to disk space issue?

Error stacktrace:

[2015-06-15 09:21:38,755][INFO][cluster.routing.allocation.decider] [Mother Superior] high disk watermark exceeded on one or more nodes, rerouting shards  
[2015-06-15 09:22:08,756][WARN][cluster.routing.allocation.decider] [Mother Superior] high disk watermark [10%] exceeded on [3EnjH2mwSKurWpz0DDXfwg][Mother Superior] free: 416.1mb[6.9%], shards will be relocated away from this node

Please guide on this.

br,  
Sunil.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 15, 2015, 8:03am UTC](https://discuss.elastic.co/t/high-disk-watermark-in-elastcisearch/2666/2 "2015-06-15T08:03:46Z")

</div>

It's likely the LS will stop processing events as ES cannot ingest anymore, so they won't be lost but you need to sort out your disk space issue.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [June 15, 2015, 9:56am UTC](https://discuss.elastic.co/t/high-disk-watermark-in-elastcisearch/2666/3 "2015-06-15T09:56:18Z")

</div>

Hello Mark,  
Can you please elaborate the issue in detail?  
What steps should I take to resolve this? I am not getting exactly what the problem is?

br,  
Sunil.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 15, 2015, 10:10pm UTC](https://discuss.elastic.co/t/high-disk-watermark-in-elastcisearch/2666/4 "2015-06-15T22:10:03Z")

</div>

As per the error - "high disk watermark exceeded....shards will be relocated away from this node" - assuming you have one node then it can never allocate new shards and data will stop flowing into ES.

Take a look at [https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules-allocation.html#disk](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules-allocation.html#disk)

You can either decrease the watermark, add more disk to ES or delete data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:07am UTC](https://discuss.elastic.co/t/high-disk-watermark-in-elastcisearch/2666/5 "2017-07-06T00:07:18Z")

</div>


