# Error OPERATION\_NOT\_ALLOWED

**URL:** <https://discuss.elastic.co/t/error-operation-not-allowed/230644>\
**Category:** Elasticsearch\
**Created:** [April 30, 2020, 10:33pm UTC](https://discuss.elastic.co/t/error-operation-not-allowed/230644 "2020-04-30T22:33:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rrs](https://avatars.discourse-cdn.com/v4/letter/r/d9b06d/32.png) [@rrs](https://discuss.elastic.co/u/rrs)\
**Post date:** [April 30, 2020, 10:33pm UTC](https://discuss.elastic.co/t/error-operation-not-allowed/230644/1 "2020-04-30T22:33:35Z")

</div>

We have a ELK-5.6.3 cluster with readonlyrest pro plugin and running fine. For some reasons we need to migrate to 7.6.2 as separate cluster. The new cluster also enabled with readonlyrest free and xpack disabled. When doing reindex from remote cluster, getting an error with below. When disable readonlyrest, remote reindex is working without any error. Can you help me how can we achieve it with readonlyrest enabled.

{  
"error" : {  
"root\_cause" : [  
{  
"reason" : "Sorry, Forbidden Request by Elasticsearch.",  
"due\_to" : [  
"OPERATION\_NOT\_ALLOWED"  
]  
}  
],  
"reason" : "Sorry, Forbidden Request by Elasticsearch.",  
"due\_to" : [  
"OPERATION\_NOT\_ALLOWED"  
],  
"status" : 401  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 30, 2020, 11:34pm UTC](https://discuss.elastic.co/t/error-operation-not-allowed/230644/2 "2020-04-30T23:34:38Z")

</div>

I think you should ask the authors of this project.

Why not using elasticsearch security built in feature?

---

<div class="post-metadata">

**Author:** ![rrs](https://avatars.discourse-cdn.com/v4/letter/r/d9b06d/32.png) [@rrs](https://discuss.elastic.co/u/rrs)\
**Post date:** [May 3, 2020, 10:17am UTC](https://discuss.elastic.co/t/error-operation-not-allowed/230644/3 "2020-05-03T10:17:58Z")

</div>

Hi @dadoonet,

Thanks for your reply. readonlyreset is management decision as of legacy setup.

The issue solved now. I was not giving username.password while making above query. Specified the user name and password for server authentication that worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2020, 10:17am UTC](https://discuss.elastic.co/t/error-operation-not-allowed/230644/4 "2020-05-31T10:17:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
