You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elasticsearch写入报错:cluster_block_exception [FORBIDDEN/12] 磁盘水位线超标

Got it, let's work through this Elasticsearch issue step by step. The error you're hitting is directly linked to the disk space warning in your logs—Elasticsearch has hit the flood stage disk watermark (95%), so it automatically locks all indices to read-only to prevent cluster instability or data loss. Here's how to fix it:

Step 1: Temporarily Disable the Read-Only Lock

First, we need to lift the read-only restriction so you can interact with your cluster normally again. Run this curl command against your Elasticsearch node:

curl -X PUT "http://<your-es-host>:<port>/_all/_settings" -H "Content-Type: application/json" -d '{"index.blocks.read_only_allow_delete": null}'

If your cluster has authentication enabled, add the -u <username>:<password> flag to the command.

⚠️ Note: This is only a temporary fix—if you don't resolve the disk space issue, Elasticsearch will re-enable the read-only lock almost immediately.

Step 2: Resolve the Root Disk Space Problem

This is the critical part. You need to free up disk space on the node(s) hitting the watermark. Here are the most common solutions:

  • Delete unused/old indices: If you have outdated indices (like daily log indices from months ago), delete them to free up space. For example:

    curl -X DELETE "http://<your-es-host>:<port>/old-logs-2023*"
    

    For long-term management, set up Index Lifecycle Management (ILM) to automatically delete or archive old indices.

  • Clean up non-Elasticsearch files: Check the server for large log files, backups, or other unrelated data taking up space. Use tools like df -h to identify which directories are full, then safely delete unnecessary files.

  • Adjust disk watermark thresholds (last resort): If you intentionally want a higher disk usage threshold (not recommended for production unless you have a solid disk management plan), you can update the watermarks dynamically without restarting the cluster:

    curl -X PUT "http://<your-es-host>:<port>/_cluster/settings" -H "Content-Type: application/json" -d '{
      "persistent": {
        "cluster.routing.allocation.disk.watermark.low": "85%",
        "cluster.routing.allocation.disk.watermark.high": "90%",
        "cluster.routing.allocation.disk.watermark.flood_stage": "92%"
      }
    }'
    

    Alternatively, you can edit these values in your elasticsearch.yml file and restart the node, but dynamic updates are preferred for live clusters.

Once you've freed up enough disk space, double-check that the read-only lock stays disabled by trying to index a test document.

内容的提问来源于stack exchange,提问作者Sean Hammond

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:18:21