Elasticsearch写入报错:cluster_block_exception [FORBIDDEN/12] 磁盘水位线超标
Got it, let's work through this Elasticsearch issue step by step. The error you're hitting is directly linked to the disk space warning in your logs—Elasticsearch has hit the flood stage disk watermark (95%), so it automatically locks all indices to read-only to prevent cluster instability or data loss. Here's how to fix it:
First, we need to lift the read-only restriction so you can interact with your cluster normally again. Run this curl command against your Elasticsearch node:
curl -X PUT "http://<your-es-host>:<port>/_all/_settings" -H "Content-Type: application/json" -d '{"index.blocks.read_only_allow_delete": null}'
If your cluster has authentication enabled, add the -u <username>:<password> flag to the command.
⚠️ Note: This is only a temporary fix—if you don't resolve the disk space issue, Elasticsearch will re-enable the read-only lock almost immediately.
This is the critical part. You need to free up disk space on the node(s) hitting the watermark. Here are the most common solutions:
Delete unused/old indices: If you have outdated indices (like daily log indices from months ago), delete them to free up space. For example:
curl -X DELETE "http://<your-es-host>:<port>/old-logs-2023*"For long-term management, set up Index Lifecycle Management (ILM) to automatically delete or archive old indices.
Clean up non-Elasticsearch files: Check the server for large log files, backups, or other unrelated data taking up space. Use tools like
df -hto identify which directories are full, then safely delete unnecessary files.Adjust disk watermark thresholds (last resort): If you intentionally want a higher disk usage threshold (not recommended for production unless you have a solid disk management plan), you can update the watermarks dynamically without restarting the cluster:
curl -X PUT "http://<your-es-host>:<port>/_cluster/settings" -H "Content-Type: application/json" -d '{ "persistent": { "cluster.routing.allocation.disk.watermark.low": "85%", "cluster.routing.allocation.disk.watermark.high": "90%", "cluster.routing.allocation.disk.watermark.flood_stage": "92%" } }'Alternatively, you can edit these values in your
elasticsearch.ymlfile and restart the node, but dynamic updates are preferred for live clusters.
Once you've freed up enough disk space, double-check that the read-only lock stays disabled by trying to index a test document.
内容的提问来源于stack exchange,提问作者Sean Hammond

