# Dev Build: Visualization Editor: blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];:

**URL:** <https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197>\
**Category:** Kibana\
**Created:** [December 4, 2017, 6:25pm UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197 "2017-12-04T18:25:18Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![eugenefedoto](https://avatars.discourse-cdn.com/v4/letter/e/71e660/32.png) [@eugenefedoto](https://discuss.elastic.co/u/eugenefedoto)\
**Post date:** [December 4, 2017, 6:25pm UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/1 "2017-12-04T18:25:19Z")

</div>

I started using the dev build from GitHub. When I try to save a visualization, I get

"Visualization Editor: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"

I want to work on some issues that require a populated list of items.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 5, 2017, 4:17pm UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/2 "2017-12-05T16:17:43Z")

</div>

Hi @eugenefedoto,

does the kibana system user have write permissions on the `.kibana` index (or whatever the index name was configured to be)? Does that only happen for visualizations or also for dashboards and saved searches?

---

<div class="post-metadata">

**Author:** ![eugenefedoto](https://avatars.discourse-cdn.com/v4/letter/e/71e660/32.png) [@eugenefedoto](https://discuss.elastic.co/u/eugenefedoto)\
**Post date:** [December 5, 2017, 8:41pm UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/3 "2017-12-05T20:41:25Z")

</div>

First, here's the entire stack trace from when I'm trying to save a visualization

```
Error: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];: [cluster_block_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];
    at http://localhost:5601/twj/bundles/kibana.bundle.js?v=8467:57750:19
    at processQueue (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:47107:37)
    at http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:47151:27
    at Scope.$digest (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:48289:15)
    at Scope.$apply (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:48587:24)
    at done (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:42608:47)
    at completeRequest (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:42834:7)
    at XMLHttpRequest.requestLoaded (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:42762:9)

```

I'm using Windows 10 Home.

> does the kibana system user have write permissions on the .kibana index (or whatever the index name was configured to be)

I'm the admin of the system where Kibana is installed. The index name is logstash-0. I don't know where the index is stored on Windows.

> Does that only happen for visualizations or also for dashboards and saved searches?

This is what I get from trying to save a dashboard.

```
Error: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];: [cluster_block_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];
    at http://localhost:5601/twj/bundles/kibana.bundle.js?v=8467:57750:19
    at processQueue (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:47107:37)
    at http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:47151:27
    at Scope.$digest (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:48289:15)
    at Scope.$apply (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:48587:24)
    at done (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:42608:47)
    at completeRequest (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:42834:7)
    at XMLHttpRequest.requestLoaded (http://localhost:5601/twj/bundles/commons.bundle.js?v=8467:42762:9)

```

Not sure how to save a search, since I don't have anything to search for (also first time user, so I might not know how).

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 6, 2017, 9:56am UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/4 "2017-12-06T09:56:11Z")

</div>

This looks like your `.kibana` index is configured as read-only. You can see that by sending the following request using the Kibana devtools:

```auto
GET .kibana/_settings

```

Looking at the Elasticsearch log output might give an indication about the reason too.

---

<div class="post-metadata">

**Author:** ![keremcan](https://avatars.discourse-cdn.com/v4/letter/k/97f17d/32.png) [@keremcan](https://discuss.elastic.co/u/keremcan)\
**Post date:** [December 9, 2017, 10:23am UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/5 "2017-12-09T10:23:21Z")

</div>

I changed the my kibana settings with

`PUT .kibana/_settings`  
{  
"index": {  
"blocks": {  
"read\_only\_allow\_delete": "false\>"  
}  
}  
}

but it resets itself after each process. any suggestion?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 11, 2017, 9:41am UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/6 "2017-12-11T09:41:35Z")

</div>

Would it be possible for you to post the full index settings as returned by `GET .kibana/_settings`?

---

<div class="post-metadata">

**Author:** ![inlikefletch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inlikefletch/32/4834_2.png) [@inlikefletch](https://discuss.elastic.co/u/inlikefletch)\
**Post date:** [December 12, 2017, 5:57pm UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/7 "2017-12-12T17:57:04Z")

</div>

I am experiencing the same issue. This is a fresh install with little to no custom changes.

my kibana setting output:

{  
".kibana": {  
"settings": {  
"index": {  
"number\_of\_shards": "1",  
"blocks": {  
"read\_only\_allow\_delete": "true"  
},  
"provided\_name": ".kibana",  
"creation\_date": "1511984561925",  
"number\_of\_replicas": "1",  
"uuid": "95cOtsa8S6y83KP\_3MZ6IQ",  
"version": {  
"created": "6000099"  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 13, 2017, 1:20pm UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/9 "2017-12-13T13:20:11Z")

</div>

I can not reproduce it using the following steps:

- clone `elasic/elasticsearch` from github, check out `master` branch
- run Elasticsearch via `gradle run` in the Elasticsearch directory
- clone `elastic/kibana` from github, check out the `master` branch
- run `npm install` in the Kibana directory
- run `npm start` in the Kibana directory

Could you tell me what your git HEAD points to and whether you performed any diverging steps?

---

<div class="post-metadata">

**Author:** ![Clood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clood/32/1453_2.png) [@Clood](https://discuss.elastic.co/u/Clood)\
**Post date:** [December 16, 2017, 12:55pm UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/10 "2017-12-16T12:55:24Z")

</div>

i can reproduce  
i downloaded today last elastic6, kibana6 on windows  
try to insert data

error inserting data  
,{"update":{"\_index":"ban","\_type":"ban","\_id":"ADRNIVX\_0000000276223880","status":403,"error":{"type":"cluster\_block\_exception","reason":"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"}}}]}

error on kibana

blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 2, 2018, 9:33am UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/11 "2018-01-02T09:33:28Z")

</div>

If the read-only status is set repeatedly as you indicated before, my best guess is that Elasticsearch does not deem it safe to leave the indices in writable state. There are several conditions that can cause this, e.g. low free disk space. Could you please check the Elasticsearch log for any indication of why it set the indices to read-only?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2018, 9:33am UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197/12 "2018-01-30T09:33:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
