# I can not login elastic

**URL:** <https://discuss.elastic.co/t/i-can-not-login-elastic/348450>\
**Category:** Elasticsearch\
**Created:** [December 1, 2023, 4:54pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450 "2023-12-01T16:54:07Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 1, 2023, 4:54pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/1 "2023-12-01T16:54:07Z")

</div>

hi  
my disk space is full  
and I can not login to elastic web  
how can I clear cache disk

plz help me

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 1, 2023, 5:38pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/2 "2023-12-01T17:38:51Z")

</div>

How many nodes do you have?  
What are the logs? Please [read this](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) about how to format.

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 2, 2023, 3:13am UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/3 "2023-12-02T03:13:09Z")

</div>

I have one node  
and I use net flow and filebeat

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 2, 2023, 1:00pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/4 "2023-12-02T13:00:14Z")

</div>

I have one node  
and I use net flow and filebeat

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 2, 2023, 3:11pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/5 "2023-12-02T15:11:15Z")

</div>

Hi @miladmohabati

What version of Elasticsearch?

Do you have security enabled?

Https? Authentication?

I would stop the netflow.

From the host run

```auto
curl "http://localhost:9200/_cat/nodes/?v&h=name,du,dt,dup,hp,hc,rm,rp,r"

```

and

`curl "http://localhost:9200/_cat/health"`

If you have https an authentication

Then

`curl -k -u elastic "https://..."`

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 3, 2023, 7:37am UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/6 "2023-12-03T07:37:08Z")

</div>

> [@stephenb](#):
>
> What version of Elasticsearch?

hi my friend  
my version Elasticsearch = 8.11.1  
yes https

after running curl "[http://localhost:9200/\_cat/nodes/?v&h=name,du,dt,dup,hp,hc,rm,rp,r](http://localhost:9200/_cat/nodes/?v&h=name,du,dt,dup,hp,hc,rm,rp,r)"

_**curl: (52) Empty reply from server**_

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 3, 2023, 2:26pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/7 "2023-12-03T14:26:41Z")

</div>

okay thanks. Which means security is enabled  
So in that case  
You need to use https and authentication

```auto
curl -k - u elastic "https://localhost:9200/_cat/nodes/?v&h=name,du,dt,dup,hp,hc,rm,rp,r

```

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 3, 2023, 4:57pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/8 "2023-12-03T16:57:11Z")

</div>

thanks  
and output

```auto
name du dt dup hp hc rm rp r
srvelk 25gb 95.8gb 26.08 40 3.1gb 15.6gb 99 cdfhilmrstw

curl "http://localhost:9200/_cat/health"
epoch timestamp cluster status node.total node.data shards pri relo init unassign pending_tasks max_task_wait_time active_shards_percent
1701622380 16:53:00 tooba-siem yellow 1 1 34 34 0 0 1 0 - 97.1%

```

now  
how can I clear cache?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 3, 2023, 6:40pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/9 "2023-12-03T18:40:49Z")

</div>

> [@miladmohabati](#):
>
> ```auto
> name du dt dup hp hc rm rp r
> srvelk 25gb 95.8gb 26.08 40 3.1gb 15.6gb 99 cdfhilmrstw
> 
> ```

This says that your disk is not full.... only 26% `dup (Disk Used Percent) 26%`

So why do you think your disk is full?

What OS are you on?

You can run this

`curl -k - u elastic "https://localhost:9200 /_cat/indices/*?v&s=pri.store.size:desc`

That will show your indices in descending order of size...

You can pick some indices to DELETE but I suspect this may not be the trouble

> [@miladmohabati](#):
>
> and I can not login to elastic web

This could be caused by something else do you mean you can not Log into Kibana?

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 4, 2023, 4:12am UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/10 "2023-12-04T04:12:40Z")

</div>

> [@stephenb](#):
>
> This says that your disk is not full.... only 26% `dup (Disk Used Percent) 26%`

hi my friend

oh,I forgot to say , I restore snapshot backup 🙃 But the hard drive was full

> [@stephenb](#):
>
> What OS are you on?

ubuntu server

> [@stephenb](#):
>
> curl -k - u elastic "[https://localhost:9200](https://localhost:9200) /\_cat/indices/\*?v&s=pri.store.size:desc

This command did not work

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 4, 2023, 4:22am UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/11 "2023-12-04T04:22:13Z")

</div>

Sorry, I missed the last double quote,

```auto
curl -k -u elastic "https://localhost:9200 /_cat/indices/*?v&s=pri.store.size:desc"

```

> [@miladmohabati](#):
>
> oh,I forgot to say , I restore snapshot backup 🙃 But the hard drive was full

Well, according to this

```auto
name du dt dup hp hc rm rp r
srvelk 25gb 95.8gb 26.08 40 3.1gb 15.6gb 99 cdfhilmrstw

```

your hardrive is not full.... it is only 26% full so I am not sure what your problem is.

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 4, 2023, 8:19am UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/12 "2023-12-04T08:19:17Z")

</div>

> [@stephenb](#):
>
> ```auto
> curl -k - u elastic "https://localhost:9200 /_cat/indices/*?v&s=pri.store.size:desc"
> 
> ```

```auto
store.size dataset.size
yellow open .ds-filebeat-8.11.1-2023.11.16-000001 A7Y5ZlG7QheXryHgK0fQpA 1 1 23867648 0 12.9gb 12.9gb 12.9gb
green open .internal.alerts-observability.logs.alerts-default-000001 W-wiCs-7ToaRr9KjOjC0Iw 1 0 0 0 249b 249b 249b
green open .internal.alerts-observability.uptime.alerts-default-000001 NAS42JsdQbqhUTnzI6dvcw 1 0 0 0 249b 249b 249b
green open .internal.alerts-ml.anomaly-detection.alerts-default-000001 oe2borCxQ520NlD6Ok-Y2w 1 0 0 0 249b 249b 249b
green open .internal.alerts-observability.slo.alerts-default-000001 r8oGIwF-Rb-OEIHNuEPmcg 1 0 0 0 249b 249b 249b
green open .internal.alerts-observability.apm.alerts-default-000001 Wrgp26bbTlGTo6vYO3EOCQ 1 0 0 0 249b 249b 249b
green open .internal.alerts-observability.metrics.alerts-default-000001 iJ252YZ3Ty-ZWbx8MQihmA 1 0 0 0 249b 249b 249b
green open .kibana-observability-ai-assistant-conversations-000001 SbjXxyw9Q2u_WedT563dCw 1 0 0 0 249b 249b 249b
green open .internal.alerts-observability.threshold.alerts-default-000001 jLIF61xpTRieUynHu-YCMw 1 0 0 0 249b 249b 249b
green open .internal.alerts-security.alerts-default-000001 OoAsfZ4NQGWUTPRNXt1klw 1 0 0 0 249b 249b 249b
green open .kibana-observability-ai-assistant-kb-000001 wGU1lhc3ReGtaCQMYNKdkw 1 0 0 0 249b 249b 249b
green open .internal.alerts-stack.alerts-default-000001 XTeuNnW1RECTf797ioMpoQ 1 0 0 0 249b 249b 249b
```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 4, 2023, 3:22pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/13 "2023-12-04T15:22:46Z")

</div>

So you have one big index from filebeat.

And your disk does not appear to be full.

You can delete that index but you will lose all your data and I don't know that that's necessary.

So let's try to figure out why you can't log into Kibana.

Exactly what error are you getting from Kibana.?

---

<div class="post-metadata">

**Author:** ![jvalente](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jvalente](https://discuss.elastic.co/u/jvalente)\
**Post date:** [December 7, 2023, 9:06pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/14 "2023-12-07T21:06:43Z")

</div>

I’ve had the same issue as OP in the past (pro tip is really paying attention to your disk usage alarm). If my hot tier filled up, it would be impossible to log into Kibana, even with the cloud admin account. I’d need to use the API to remove or rollover an index and reboot the deployment before I could log in. I’m assuming it’s because Kibana can’t write to an index it needs (I have not seen it happen with warm nodes) but that’s a wild guess.

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 10, 2023, 5:53am UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/15 "2023-12-10T05:53:52Z")

</div>

> [@stephenb](#):
>
> curl -k - u elastic "[https://localhost:9200](https://localhost:9200) /\_cat/indices/\*?v&s=pri.store.size:desc

my disk is full

```auto
df -h
Filesystem Size Used Avail Use% Mounted on
tmpfs 1.6G 1.3M 1.6G 1% /run
/dev/mapper/ubuntu--vg-ubuntu--lv 96G 92G 0 **100%** /
tmpfs 7.9G 0 7.9G 0% /dev/shm
tmpfs 5.0M 0 5.0M 0% /run/lock
/dev/sda2 2.0G 129M 1.7G 8% /boot
tmpfs 1.6G 4.0K 1.6G 1% /run/user/0

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 10, 2023, 5:57am UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/16 "2023-12-10T05:57:51Z")

</div>

Which disk is the Elastic Data on? `/dev/mapper/ubuntu--vg-ubuntu--lv`

your `tmpfs` is also full...

So you only have 1 big index

`yellow open .ds-filebeat-8.11.1-2023.11.16-000001 A7Y5ZlG7QheXryHgK0fQpA 1 1 23867648 0 12.9gb 12.9gb 12.9gb `

So you can delete that if you want but you will lose all your data...

There must be other items on your disk. Elastic only takes ~13GB. Perhaps you can clean something else log files... something else?

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 10, 2023, 8:52am UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/17 "2023-12-10T08:52:12Z")

</div>

curl -k -u elastic "[https://localhost:9200/\_cat/indices/\*?v&s=pri.store.size:desc](https://localhost:9200/_cat/indices/*?v&s=pri.store.size:desc)"  
Enter host password for user 'elastic':  
curl: (7) Failed to connect to localhost port 9200 after 1 ms: Connection refused

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 10, 2023, 3:11pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/18 "2023-12-10T15:11:42Z")

</div>

So the command that worked above no longer works?

I can't help much when you justs run a command and show me the results with no other explanation.

I would check to see if elasticsearch is still running

`sudo systemctl status elasticsearch`

Also, if your file system has 96 GB and elastic is only taking up. 13 GB I would see if there's something else on that file system that you could clean up.

---

<div class="post-metadata">

**Author:** ![miladmohabati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miladmohabati/32/128573_2.png) [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Post date:** [December 10, 2023, 5:20pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/19 "2023-12-10T17:20:05Z")

</div>

systemctl status elasticsearch.service  
× elasticsearch.service - Elasticsearch  
Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)  
Active: failed (Result: exit-code) since Sun 2023-12-10 09:21:53 +0330; 11h ago  
Docs: [https://www.elastic.co](https://www.elastic.co)  
Process: 1589 ExecStart=/usr/share/elasticsearch/bin/systemd-entrypoint -p ${PID\_DIR}/elasticsearch.pid --quiet (code=exited, status=1/FAILUR\>  
Main PID: 1589 (code=exited, status=1/FAILURE)  
CPU: 2.417s

Dec 10 09:21:53 srvelk systemd-entrypoint[1589]: at java.base/java.nio.file.Files.createTempDirectory(Files.java:1017)  
Dec 10 09:21:53 srvelk systemd-entrypoint[1589]: at org.elasticsearch.server.cli.ServerProcess.createTempDirectory(ServerProcess.java:268)  
Dec 10 09:21:53 srvelk systemd-entrypoint[1589]: at org.elasticsearch.server.cli.ServerProcess.setupTempDir(ServerProcess.java:260)  
Dec 10 09:21:53 srvelk systemd-entrypoint[1589]: at org.elasticsearch.server.cli.ServerProcess.createProcess(ServerProcess.java:203)  
Dec 10 09:21:53 srvelk systemd-entrypoint[1589]: at org.elasticsearch.server.cli.ServerProcess.start(ServerProcess.java:104)  
Dec 10 09:21:53 srvelk systemd-entrypoint[1589]: ... 7 more  
Dec 10 09:21:53 srvelk systemd[1]: elasticsearch.service: Main process exited, code=exited, status=1/FAILURE  
Dec 10 09:21:53 srvelk systemd[1]: elasticsearch.service: Failed with result 'exit-code'.  
Dec 10 09:21:53 srvelk systemd[1]: Failed to start Elasticsearch.  
Dec 10 09:21:53 srvelk systemd[1]: elasticsearch.service: Consumed 2.417s CPU time.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [December 10, 2023, 10:48pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450/20 "2023-12-10T22:48:26Z")

</div>

You can use the command to find 5 largest dirs:  
`du -h / | sort -rh | head -5`

[Next page](https://discuss.elastic.co/t/i-can-not-login-elastic/348450.md?page=2)
