# Disable reads from few indices of an index pattern

**URL:** <https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026>\
**Category:** Elasticsearch\
**Created:** [March 19, 2023, 4:17pm UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026 "2023-03-19T16:17:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![tarunpvss](https://avatars.discourse-cdn.com/v4/letter/t/c67d28/32.png) [@tarunpvss](https://discuss.elastic.co/u/tarunpvss)\
**Post date:** [March 19, 2023, 4:17pm UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/1 "2023-03-19T16:17:16Z")

</div>

Hi Team, I want to disable reads for few indices in an index pattern. I tried using ` index.blocks.read : true` But due to this, when I am trying to query using index pattern, getting the below error

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "cluster_block_exception",
        "reason" : "blocked by: [FORBIDDEN/7/index read (api)];"
      }
    ],
    "type" : "cluster_block_exception",
    "reason" : "blocked by: [FORBIDDEN/7/index read (api)];"
  },
  "status" : 403
}

```

Is it possible to enable search on other indices , without getting the above error. Or are there any other ways to achieve this??

---

<div class="post-metadata">

**Author:** ![jba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jba/32/118482_2.png) [@jba](https://discuss.elastic.co/u/jba)\
**Post date:** [March 19, 2023, 4:49pm UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/2 "2023-03-19T16:49:51Z")

</div>

Access to indices can be controlled by the user's role. I think you can write both "Allow read access to these indices (by alias) and "Deny access" when defining the role.

I am not sure if there is special setting for denying access, or if your use a minus sign like "- indexname" when you list the indices that the role should have access to.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 19, 2023, 11:47pm UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/3 "2023-03-19T23:47:32Z")

</div>

What's the broader context and end goal here? Could you use Security to limit access or, as pointed out above, exclude them from the query?

---

<div class="post-metadata">

**Author:** ![tarunpvss](https://avatars.discourse-cdn.com/v4/letter/t/c67d28/32.png) [@tarunpvss](https://discuss.elastic.co/u/tarunpvss)\
**Post date:** [March 20, 2023, 5:11am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/4 "2023-03-20T05:11:55Z")

</div>

Context: Currently we store 30d of data and having one index per day. We want to reduce the retention to 15d, but before doing that, we want to first mask the data \>15d (without deleting) and observe the usage patterns before we completely reduce the retention.  
Currently we are not following any user concept in our cluster. Hence checking if there is any other way

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 20, 2023, 6:22am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/5 "2023-03-20T06:22:51Z")

</div>

Are you using ILM?

---

<div class="post-metadata">

**Author:** ![tarunpvss](https://avatars.discourse-cdn.com/v4/letter/t/c67d28/32.png) [@tarunpvss](https://discuss.elastic.co/u/tarunpvss)\
**Post date:** [March 20, 2023, 6:53am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/6 "2023-03-20T06:53:16Z")

</div>

No, we use curator

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 20, 2023, 6:56am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/7 "2023-03-20T06:56:12Z")

</div>

I would create an alias that covers only 15 days worth of indices amd let the customers query through this. You would add this to all new indices through an index template and then [remove it using Curator when the index is older than 15 days](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/alias.html).

---

<div class="post-metadata">

**Author:** ![tarunpvss](https://avatars.discourse-cdn.com/v4/letter/t/c67d28/32.png) [@tarunpvss](https://discuss.elastic.co/u/tarunpvss)\
**Post date:** [March 20, 2023, 7:06am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/8 "2023-03-20T07:06:32Z")

</div>

Yes that is one way @Christian_Dahlqvist , but i have few more Indices/rather tenants which work on index patterns. Wanted to have unified thing for all tenants, hence was trying to explore if there is another way

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2023, 7:07am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026/9 "2023-04-17T07:07:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
