You may need to delete the journal too, just be aware that you'll lose any messages in there.
On Friday, 2 September 2016 18:04:28 UTC+1, [email protected] wrote: > > Here is my elasticsearch log starting from when I restarted the > elasticsearch service. http://pastebin.com/4WR3Nn5K > > On Friday, September 2, 2016 at 10:57:37 AM UTC-6, [email protected] > wrote: >> >> I had changed the path for elasticsearch data to a second HDD, but not >> the logs. Today my root HDD reached 99% as a result. I stopped Graylog, >> deleted the elasticsearch logs at /var/log/elasticsearch, and edited the >> elasticsearch.yml to point to the second HDD. I rebooted my machine and my >> HDD's now have ample space again. However, Graylog isn't processing any >> incoming messages. I have ~400k messages showing unprocessed. On the >> overview page everything is green. I've restarted, Graylog, Elasticsearch, >> and the server. No change. Any ideas on what I can do? >> >> The journal contains 406,203 unprocessed messages in 5 segments. 0 >> messages appended, 0 messages read in the last second. >> >> Thanks in advance for your help. >> > -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/graylog2/0a837532-7fdc-413a-8f4e-aa3cafde00d7%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
