# Config: Error 403 Forbidden: blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];: \[cluster\_block\_exception\] blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];

**URL:** <https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361>\
**Category:** Kibana\
**Created:** [December 27, 2017, 8:12pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361 "2017-12-27T20:12:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [December 27, 2017, 8:12pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/1 "2017-12-27T20:12:46Z")

</div>

Config: Error 403 Forbidden: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];

Kibana not able to retrieve old data.

I have enabled one of the device it started logging huge data, after some time Elastic Search and Kibana not showing data, i have restarted, but no luck, i see below errors

syslog-ng ---elasticksearch--kibana is my setup

[2017-12-27T20:07:44.841332] Outgoing message; message='Dec 27 20:07:44 ES6 kibana[7035]: {"type":"error","@timestamp":"2017-12-27T20:07:44Z","tags":["error","monitoring-ui"],"pid":7035,"level":"error","error":{"message":"[export\_exception] Exception when closing export bulk","name":"Error","stack":"[export\_exception] Exception when closing export bulk :: {"path":"/\_xpack/monitoring/\_bulk","query":{"system\_id":"kibana","system\_api\_version":"6","interval":"10000ms"},"body":"{\"index\":{\"\_type\":\"kibana\_settings\"}}\n{\"kibana\_uuid\":\"65539add-f049-4084-800e-62ebe31172c5\",\"xpack\":{\"default\_admin\_email\":null}}\n{\"index\":{\"\_type\":\"kibana\_stats\"}}\n{\"kibana\":{\"uuid\":\"65539add-f049-4084-800e-62ebe31172c5\",\"name\":\"ES6\",\"index\":\".kibana\",\"host\":\"ES6\",\"transport\_address\":\"192.168.1.75:5601\",\"version\":\"6.0.1\",\"snapshot\":false,\"status\":\"green\"},\"concurrent\_connections\":393,\"os\":{\"load\":{\"1m\":0.03564453125,\"5m\":0.23828125,\"15m\":0.458984375},\"memory\":{\"total\_in\_bytes\":8371228672,\"free\_in\_bytes\":1713790976,\"used\_in\_bytes\":6657437696},\"uptime\_in\_millis\":1458957000},\"process\":{\"event\_loop\_delay\":97.87312602996826,\"memory\":{\"heap\":{\"total\_in\_bytes\":120438784,\"used\_in\_bytes\":102224128,\"size\_limit\":1501560832},\"resident\_set\_size\_in\_bytes\":161980416},\"uptime\_in\_millis\":482334},\"requests\":{\"disconnects\":0,\"total\":205,\"status\_codes\":{\"200\":109,\"304\":77,\"403\":14,\"404\":5}},\"response\_times\":{\"average\":95,\"max\":699},\"timestamp\":\"2017-12-27T20:07:39.449Z\"}\n","statusCode":500,"response":"{\"took\":38,\"errors\":true,\"error\":{\"type\":\"export\_exception\",\"reason\":\"Exception when closing export bulk\",\"caused\_by\":{\"type\":\"export\_exception\",\"reason\":\"failed to flush export bulks\",\"caused\_by\\x0a'  
[2017-12-27T20:07:44.841386] Outgoing message; message='Dec 27 20:07:44 ES6 kibana[7035]: ":{\"type\":\"export\_exception\",\"reason\":\"bulk [default\_local] reports failures when exporting documents\",\"exceptions\":[{\"type\":\"export\_exception\",\"reason\":\"ClusterBlockException[blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];]\",\"caused\_by\":{\"type\":\"cluster\_block\_exception\",\"reason\":\"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];\"}},{\"type\":\"export\_exception\",\"reason\":\"ClusterBlockException[blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];]\",\"caused\_by\":{\"type\":\"cluster\_block\_exception\",\"reason\":\"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];\"}}]}}}}"}\n at respond (/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:295:15)\n at checkRespForFailure (/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:254:7)\n at HttpConnector. (/usr/share/kibana/node\_modules/elasticsearch/src/lib/connectors/http.js:159:7)\n at IncomingMessage.bound (/usr/share/kibana/node\_modules/elasticsearch/node\_modules/lodash/dist/lodash.js:729:21)\n at emitNone (events.js:91:20)\n at IncomingMessage.emit (events.js:185:7)\n at endReadableNT (\_stream\_readable.js:974:12)\n at \_combinedTickCallback (internal/process/next\_tick.js:80:11)\n at process.\_tickDomainCallback (internal/process/next\_tick.js:128:9)"},"message":"[export\_exception] Exception when closing export bulk"}\x0a'

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [December 27, 2017, 8:30pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/2 "2017-12-27T20:30:07Z")

</div>

Can you verify that there's disk space available? ES will go into read only mode once a threshold is hit.

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [December 27, 2017, 8:36pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/3 "2017-12-27T20:36:28Z")

</div>

Yes i have 2+GB available free, when i see that first i checked space.

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [December 27, 2017, 8:36pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/4 "2017-12-27T20:36:48Z")

</div>

/dev/mapper/ES6--vg-root 12G 5.5G 5.3G 52% /

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [December 27, 2017, 8:54pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/5 "2017-12-27T20:54:06Z")

</div>

Can you share your elasticsearch logs? We're looking for anything related to blocking writes. If there's no red flags there it's possible the index got put into a read only state for some other reason, you can reverse this by

```auto
curl -XPUT -H "Content-Type: application/json" http://localhost:9200/.monitoring-*/_settings -d '{"index.blocks.read_only_allow_delete": null}'

```

[https://www.elastic.co/guide/en/elasticsearch/reference/6.x/disk-allocator.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.x/disk-allocator.html) has more info on this reset.

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [December 27, 2017, 9:36pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/6 "2017-12-27T21:36:54Z")

</div>

> [@jbudz](#):
>
> curl -XPUT -H "Content-Type: application/json" [http://localhost:9200/.monitoring-\*/\_settings](http://localhost:9200/.monitoring-*/_settings) -d '{"index.blocks.read\_only\_allow\_delete": null}'

Sorry i was impatient, so i have deleted all indexes, see if that resolve the issue, after deleting all and started creating new one. if the problem persists i will post the output here.

is there any way i can specifies index ( nodes) different custom folder.

from /var/lib/elasticsearch/nodes/ to /var/syslog-ng/lib/elasticsearch/nodes/ ?

appreciated your quick help

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [December 27, 2017, 9:59pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/7 "2017-12-27T21:59:02Z")

</div>

Yep, in elasticsearch.yml set `path.data` to `/var/syslog-ng/lib/elasticsearch/nodes/`. You'll probably want to stop elasticsearch, move your current data directory, and then reconfigure.

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [December 28, 2017, 8:44am UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/8 "2017-12-28T08:44:43Z")

</div>

Thank you for your reply, i have solution for now, we can close this discussion.

In the future if i come across new issue i will open another one to discuss.

It is good product.

R!

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [December 28, 2017, 6:50pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/9 "2017-12-28T18:50:55Z")

</div>

No problem. If you get a chance can you share your solution?

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [December 28, 2017, 7:31pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/10 "2017-12-28T19:31:42Z")

</div>

Sure,

As i was mentioned, i have deleted the data and re-created, but if i see further issue i can follow your instruction to produce more logs, it will be helpfull if any bugs

Appreciate your help.

R!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2018, 7:31pm UTC](https://discuss.elastic.co/t/config-error-403-forbidden-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/113361/11 "2018-01-25T19:31:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
