# Cluster Block Exception retrying failed action with response code: 403

**URL:** <https://discuss.elastic.co/t/cluster-block-exception-retrying-failed-action-with-response-code-403/362015>\
**Category:** Logstash\
**Created:** [June 25, 2024, 10:52am UTC](https://discuss.elastic.co/t/cluster-block-exception-retrying-failed-action-with-response-code-403/362015 "2024-06-25T10:52:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Simon\_Prinz](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@Simon\_Prinz](https://discuss.elastic.co/u/Simon_Prinz)\
**Post date:** [June 25, 2024, 10:52am UTC](https://discuss.elastic.co/t/cluster-block-exception-retrying-failed-action-with-response-code-403/362015/1 "2024-06-25T10:52:08Z")

</div>

Hello Dear Community,

since a Couple of days out of the Blue i get more and more:

`retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"index [Logs] blocked by: [FORBIDDEN/8/index write (api)];"})`

in my Logstash Logs and data doesnt reach the Elasticsearch instance

On every Index that this occurs on is a `index write block` which i have to manually set to `false` every day or every couple hours and after that the Logs get handled as usual.

And even when i set the Block to `false` in my Index Template it still gets overriden.

I have more than enough Storage cause that is the Explanation there is in any discussion i found on this Topic.

My Elasticsearch version is 7.17.15 and my logstash version 7.9.3.

Ty in Advance for the Help

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [June 26, 2024, 12:46pm UTC](https://discuss.elastic.co/t/cluster-block-exception-retrying-failed-action-with-response-code-403/362015/2 "2024-06-26T12:46:45Z")

</div>

Hi,

Check your cluster settings to see if the `cluster.routing.allocation.disk.watermark.low` and `cluster.routing.allocation.disk.watermark.high` values are set appropriately.

Regards

---

<div class="post-metadata">

**Author:** ![Simon\_Prinz](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@Simon\_Prinz](https://discuss.elastic.co/u/Simon_Prinz)\
**Post date:** [June 26, 2024, 1:17pm UTC](https://discuss.elastic.co/t/cluster-block-exception-retrying-failed-action-with-response-code-403/362015/3 "2024-06-26T13:17:35Z")

</div>

Hi Yago,

yes they are Sized Appropriatly:

```
      "disk" : {
        "watermark" : {
          "low" : "95%",
          "flood_stage" : "98%",
          "high" : "96%"
        }

```

I have 30% Space left in my Cluster.

Regards

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2024, 1:21pm UTC](https://discuss.elastic.co/t/cluster-block-exception-retrying-failed-action-with-response-code-403/362015/4 "2024-06-26T13:21:35Z")

</div>

What does elasticsearch log at the point where it transitions the index to read-only?

---

<div class="post-metadata">

**Author:** ![Simon\_Prinz](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@Simon\_Prinz](https://discuss.elastic.co/u/Simon_Prinz)\
**Post date:** [June 26, 2024, 1:57pm UTC](https://discuss.elastic.co/t/cluster-block-exception-retrying-failed-action-with-response-code-403/362015/5 "2024-06-26T13:57:35Z")

</div>

Hello Badger,

unfortunatly i dont see any Logs regarding the Read Only State in Elasticsearch.

The only logs i see related to the Topic are the logstash logs at the beginning of this Thread

Regards

---

<div class="post-metadata">

**Author:** ![Simon\_Prinz](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@Simon\_Prinz](https://discuss.elastic.co/u/Simon_Prinz)\
**Post date:** [June 26, 2024, 4:24pm UTC](https://discuss.elastic.co/t/cluster-block-exception-retrying-failed-action-with-response-code-403/362015/6 "2024-06-26T16:24:56Z")

</div>

Hello, i get this Info tho in my Elasticsearch Logs

```auto
2024-06-26T02:51:48,958][INFO][o.e.x.i.IndexLifecycleTransition] [Node1] moving index [Logs] from [{"phase":"warm","action":"forcemerge","name":"readonly"}] to [{"phase":"warm","action":"forcemerge","name":"forcemerge"}] in policy [Hot_warm]

```

It says in the message: name readonly

But in my ILM or Templates i nowhere define a read only phase.  
I know you can check the Box but i checked and its unchecked.
