# Cluster\_block\_exception: index \[.kibana\_security\_session\_1\] blocked by: \[TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block\]

**URL:** <https://discuss.elastic.co/t/cluster-block-exception-index-kibana-security-session-1-blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/366132>\
**Category:** Kibana\
**Created:** [September 6, 2024, 5:08am UTC](https://discuss.elastic.co/t/cluster-block-exception-index-kibana-security-session-1-blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/366132 "2024-09-06T05:08:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tuanlt7](https://avatars.discourse-cdn.com/v4/letter/t/ecae2f/32.png) [@tuanlt7](https://discuss.elastic.co/u/tuanlt7)\
**Post date:** [September 6, 2024, 5:08am UTC](https://discuss.elastic.co/t/cluster-block-exception-index-kibana-security-session-1-blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/366132/1 "2024-09-06T05:08:51Z")

</div>

Dears Support Team,  
Today, I login to Elastic in Kibana but have error message

> [2024-09-06T04:49:33.914+00:00][ERROR][plugins.security.user-profile] Failed to activate user profile: {  
> "error": {  
> "root\_cause": [  
> {  
> "type": "cluster\_block\_exception",  
> "reason": "index [.security-profile-8] blocked by: [TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block];"  
> }  
> ],  
> "type": "cluster\_block\_exception",  
> "reason": "index [.security-profile-8] blocked by: [TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block];"  
> },  
> "status": 429  
> }.

I found these solutions for that:

- Solution 1: free up disk space

```auto
$ curl -XPUT -H "Content-Type: application/json" https://[YOUR_ELASTICSEARCH_ENDPOINT]:9200/_all/_settings -d '{"index.blocks.read_only_allow_delete": null}'

```

- Solution 2: change the flood stage watermark setting

```auto
PUT _cluster/settings
{
  "transient": {
    "cluster.routing.allocation.disk.watermark.low": "100gb",
    "cluster.routing.allocation.disk.watermark.high": "50gb",
    "cluster.routing.allocation.disk.watermark.flood_stage": "10gb",
    "cluster.info.update.interval": "1m"
  }
}

```

But I cannot do that because of I cannot login to system  
Can you help me any suggestion?  
Ours Elastic version: v 8.12.2

BRs,  
Tuan - VinFast

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 6, 2024, 5:19am UTC](https://discuss.elastic.co/t/cluster-block-exception-index-kibana-security-session-1-blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/366132/2 "2024-09-06T05:19:40Z")

</div>

> [@tuanlt7](#):
>
> I found these solutions for that:
> 
> - Solution 1: free up disk space
> 
> ```auto
> $ curl -XPUT -H "Content-Type: application/json" https://[YOUR_ELASTICSEARCH_ENDPOINT]:9200/_all/_settings -d '{"index.blocks.read_only_allow_delete": null}'
> 
> ```

That does not free up disk space... it just unblocks read only... which will happen automatically if you actually free up disk space on 8.12 so you do not need to run that command

What you need to do is clean up disk space by cleaning up / deleting indices you no longer need.

From curl / command line...

You need to run the `_cat/indices/?v` endpoint to see all the indices...

Then you need to run DELETE to delete some indices to free up space... (don't change the watermarks) ... and then the read only indices will self heal

`curl -k -X DELETE -u elastic https://[YOUR_ELASTICSEARCH_ENDPOINT]/myindexnametodelete`

**NOTE this will permanently delete the index... and will not be recoverable unless you have snapshots to recover from**

You can also expand the disk to provide more space...

---

<div class="post-metadata">

**Author:** ![tuanlt7](https://avatars.discourse-cdn.com/v4/letter/t/ecae2f/32.png) [@tuanlt7](https://discuss.elastic.co/u/tuanlt7)\
**Post date:** [September 6, 2024, 8:46am UTC](https://discuss.elastic.co/t/cluster-block-exception-index-kibana-security-session-1-blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/366132/4 "2024-09-06T08:46:19Z")

</div>

Thank you for your support,  
I have already deleted old indices and it worked fine

BRs,
