# Kibana login Issue due to space full

**URL:** <https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153>\
**Category:** Kibana\
**Created:** [March 21, 2023, 9:59am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153 "2023-03-21T09:59:16Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticlog](https://avatars.discourse-cdn.com/v4/letter/e/77aa72/32.png) [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Post date:** [March 21, 2023, 9:59am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/1 "2023-03-21T09:59:16Z")

</div>

Hello Expert,

We have created the Kibana and Elasticsearch with filebeat. Below are the details.  
Kibana version: 7.14.1.  
running in Kubernetes.

Issue:  
Not able to login to Kibana as Elasticsearch space is full. but when i deleted the space and try to restart the pod at that time the Kibana pod is not coming up.

Kindly do the needful help as it making more trouble.

which indices should i delete or is there any other way to resolve this issue.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 21, 2023, 9:21pm UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/2 "2023-03-21T21:21:19Z")

</div>

Welcome to our community! 😃

> [@elasticlog](#):
>
> Kibana version: 7.14.1.

This is a really old version. You should be running 8.6 as the latest, but if you need to run 7 then use 7.17.

> [@elasticlog](#):
>
> Not able to login to Kibana as Elasticsearch space is full. but when i deleted the space and try to restart the pod at that time the Kibana pod is not coming up.

You will need to share more information for us to be able to help. Take a look at [Dec 10th, 2022: [EN] Asking top notch technical questions to get you help quicker!](https://discuss.elastic.co/t/dec-10th-2022-en-asking-top-notch-technical-questions-to-get-you-help-quicker/320300) and then update this topic with some extra info.

---

<div class="post-metadata">

**Author:** ![elasticlog](https://avatars.discourse-cdn.com/v4/letter/e/77aa72/32.png) [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Post date:** [March 23, 2023, 4:46am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/3 "2023-03-23T04:46:17Z")

</div>

> [@elasticlog](#):
>
> 7.14.1

Thank you @warkolm for suggestion.  
if we upgrade the version. but the disk full is going to come on that situation also. What are the precaution should we take to over come with this issue. Below is the error msg in logs we found.

logs of Kibana pod:  
{"type":"log","@timestamp":"2023-03-21T09:32:00+00:00","tags":["info","plugins","security","routes"],"pid":1209,"message":"Logging in with provider "basic" (basic)"}  
{"type":"log","@timestamp":"2023-03-21T09:32:01+00:00","tags":["error","plugins","security","session","index"],"pid":1209,"message":"Failed to create session value: cluster\_block\_exception: [cluster\_block\_exception] Reason: index [.kibana\_security\_session\_1] blocked by: [TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block];"}  
{"type":"log","@timestamp":"2023-03-21T09:32:01+00:00","tags":["error","http"],"pid":1209,"message":"ResponseError: cluster\_block\_exception: [cluster\_block\_exception] Reason: index [.kibana\_security\_session\_1] blocked by: [TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block];\n at onBody (/usr/share/kibana/node\_modules/@elastic/elasticsearch/lib/Transport.js:349:23)\n at IncomingMessage.onEnd (/usr/share/kibana/node\_modules/@elastic/elasticsearch/lib/Transport.js:275:11)\n at IncomingMessage.emit (events.js:412:35)\n at endReadableNT (internal/streams/readable.js:1317:12)\n at processTicksAndRejections (internal/process/task\_queues.js:82:21) {\n meta: {\n body: { error: [Object], status: 429 },\n statusCode: 429,\n headers: {\n 'x-elastic-product': 'Elasticsearch',\n 'content-type': 'application/json; charset=UTF-8',\n 'content-length': '435'\n },\n meta: {\n context: null,\n request: [Object],\n name: 'elasticsearch-js',\n connection: [Object],\n attempts: 0,\n aborted: false\n }\n }\n}"}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 23, 2023, 4:47am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/4 "2023-03-23T04:47:19Z")

</div>

Did you free up space on the Elasticsearch host?

---

<div class="post-metadata">

**Author:** ![elasticlog](https://avatars.discourse-cdn.com/v4/letter/e/77aa72/32.png) [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Post date:** [March 23, 2023, 4:49am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/5 "2023-03-23T04:49:39Z")

</div>

> [@warkolm](#):
>
> 7.17.

Yes i tried manually cleaning and after we have restart the pod elastic and kibana pod. elastic pod came up but kibana pod is not coming up.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 23, 2023, 4:50am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/6 "2023-03-23T04:50:04Z")

</div>

What did you do exactly?  
What is the state of Elasticsearch? What does it respond with?

---

<div class="post-metadata">

**Author:** ![elasticlog](https://avatars.discourse-cdn.com/v4/letter/e/77aa72/32.png) [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Post date:** [March 23, 2023, 5:12am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/7 "2023-03-23T05:12:49Z")

</div>

We use exec command to get in the kibana pod and going to the location where pvc volume is define getting in to the indices and deleting the old file.  
after that the restart the pod and elastic pod came up. when i restart the elastic pod it not coming up giving below error.

this is the old pod  
Action failed with 'search\_phase\_execution\_exception: '. Retrying attempt 5 in 32 seconds."}  
{"type":"log","@timestamp":"2023-03-23T05:08:09+00:00","tags":["info","savedobjects-service"],"pid":1211,"message":"[.kibana] OUTDATED\_DOCUMENTS\_SEARCH\_OPEN\_PIT -\> OUTDATED\_DOCUMENTS\_SEARCH\_OPEN\_PIT. took: 16444ms."}

What is the state of Elasticsearch?  
Elastic search is in red health status.

What does it respond with?  
not bale to login 500 error

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 23, 2023, 7:47am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/8 "2023-03-23T07:47:36Z")

</div>

> [@elasticlog](#):
>
> e use exec command to get in the kibana pod and going to the location where pvc volume is define getting in to the indices and deleting the old file

**NEVER ever delete data directly from the disk of Elasticsearch.**

You have probably severely broken Elasticsearch and your best bet would be to delete all data from the indices using the APIs and then starting over again.

---

<div class="post-metadata">

**Author:** ![elasticlog](https://avatars.discourse-cdn.com/v4/letter/e/77aa72/32.png) [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Post date:** [March 23, 2023, 8:29am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/9 "2023-03-23T08:29:40Z")

</div>

How to delete the all the data with api as im not able to get it. Could you please help me with steps where to run that api and how to get info

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 23, 2023, 8:32am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/10 "2023-03-23T08:32:48Z")

</div>

> **[Delete API | Elasticsearch Guide \[8.6\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/docs-delete.html)**

---

<div class="post-metadata">

**Author:** ![elasticlog](https://avatars.discourse-cdn.com/v4/letter/e/77aa72/32.png) [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Post date:** [March 23, 2023, 10:30am UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/11 "2023-03-23T10:30:14Z")

</div>

Hi @warkolm

Thank you for shearing the link. im able to get the indices. which are holding spaced get with below command.

curl -X GET "localhost:9200/\_cat/indices/my-index-\*?v=true&s=index&pretty"

If i delete the index with curl command is it fine.

As i try to get the doc id but not able to get the doc id to delete. for below command.

curl -X DELETE "localhost:9200/my-index-000001/\_doc/1?routing=shard-1&pretty"

---

<div class="post-metadata">

**Author:** ![elasticlog](https://avatars.discourse-cdn.com/v4/letter/e/77aa72/32.png) [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Post date:** [March 23, 2023, 12:15pm UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/12 "2023-03-23T12:15:27Z")

</div>

Hello @warkolm

Thank you so much for guiding me. I'm able to logging after deleting the indices which consume more space.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2023, 12:16pm UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153/13 "2023-04-20T12:16:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
