# High disk watermark

**URL:** <https://discuss.elastic.co/t/high-disk-watermark/208130>\
**Category:** Elasticsearch\
**Created:** [November 15, 2019, 7:54pm UTC](https://discuss.elastic.co/t/high-disk-watermark/208130 "2019-11-15T19:54:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [November 15, 2019, 7:54pm UTC](https://discuss.elastic.co/t/high-disk-watermark/208130/1 "2019-11-15T19:54:07Z")

</div>

I deleted indexes in Kibana the first time I got this error and then my console showed me low disk watermark. But with 800000 docs on index, I keep getting high disk watermark! How can I fix this for future as I intend on ingesting real time logs?

```auto
[2019-11-15T11:44:59,440][INFO][o.e.c.r.a.DiskThresholdMonitor] [mehak-VirtualBox] low disk watermark [2gb] exceeded on [uszTm_0tR26zJa0KI9beBw][mehak-VirtualBox][/home/mehak/Documents/elasticsearch-7.4.0/data/nodes/0] free: 1gb[7.7%], replicas will not be assigned to this node
[2019-11-15T11:45:44,230][INFO][o.e.m.j.JvmGcMonitorService] [mehak-VirtualBox] [gc][18074] overhead, spent [284ms] collecting in the last [1s]
[2019-11-15T11:45:54,239][INFO][o.e.m.j.JvmGcMonitorService] [mehak-VirtualBox] [gc][18084] overhead, spent [432ms] collecting in the last [1s]
[2019-11-15T11:45:59,472][WARN][o.e.c.r.a.DiskThresholdMonitor] [mehak-VirtualBox] high disk watermark [1gb] exceeded on [uszTm_0tR26zJa0KI9beBw][mehak-VirtualBox][/home/mehak/Documents/elasticsearch-7.4.0/data/nodes/0] free: 878.2mb[6.3%], shards will be relocated away from this node
[2019-11-15T11:45:59,472][INFO][o.e.c.r.a.DiskThresholdMonitor] [mehak-VirtualBox] rerouting shards: [high disk watermark exceeded on one or more nodes]
[2019-11-15T11:46:59,517][WARN][o.e.c.r.a.DiskThresholdMonitor] [mehak-VirtualBox] high disk watermark [1gb] exceeded on [uszTm_0tR26zJa0KI9beBw][mehak-VirtualBox][/home/mehak/Documents/elasticsearch-7.4.0/data/nodes/0] free: 799.3mb[5.8%]

```

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [November 15, 2019, 9:55pm UTC](https://discuss.elastic.co/t/high-disk-watermark/208130/2 "2019-11-15T21:55:02Z")

</div>

Of course the obvious answer is to deploy more storage capacity.

There are some helpful tips in [Tune for disk usage](https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-disk-usage.html).

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [November 18, 2019, 7:55pm UTC](https://discuss.elastic.co/t/high-disk-watermark/208130/3 "2019-11-18T19:55:32Z")

</div>

Following the page, I ran this to remove the "\_type" : "\_doc"

```auto
PUT filebeat-7.4.0-2019.11.08-000001 
{
  "mappings": {
    "properties": {
      "_type": {
        "type": "text",
        "index": false
      }
    }
  }
}

```

but I got this error--

```auto

  "error": {
    "root_cause": [
      {
        "type": "resource_already_exists_exception",
        "reason": "index [filebeat-7.4.0-2019.11.08-000001/lMcCHhWuT9ecTfsI4OyGEA] already exists",
        "index_uuid": "lMcCHhWuT9ecTfsI4OyGEA",
        "index": "filebeat-7.4.0-2019.11.08-000001"
      }
    ],
    "type": "resource_already_exists_exception",
    "reason": "index [filebeat-7.4.0-2019.11.08-000001/lMcCHhWuT9ecTfsI4OyGEA] already exists",
    "index_uuid": "lMcCHhWuT9ecTfsI4OyGEA",
    "index": "filebeat-7.4.0-2019.11.08-000001"
  },
  "status": 400

```

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [November 18, 2019, 8:16pm UTC](https://discuss.elastic.co/t/high-disk-watermark/208130/4 "2019-11-18T20:16:21Z")

</div>

It isn't possible to change the mapping of an existing field in an index.

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [November 18, 2019, 8:19pm UTC](https://discuss.elastic.co/t/high-disk-watermark/208130/5 "2019-11-18T20:19:59Z")

</div>

Oh, got it. So I should create a new index and only in it I can change these values?

```auto
yellow open filebeat-7.4.0-2019.11.08-000001 lMcCHhWuT9ecTfsI4OyGEA 1 1 9076656 0 866.3mb

```

What can i do to fix the current index I have? Can i not delete the 50000 out of 9076656 docs on this index? Please help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2019, 8:20pm UTC](https://discuss.elastic.co/t/high-disk-watermark/208130/6 "2019-12-16T20:20:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
