Error starting Metricbeat

Hi there

I'm having trouble getting Metricbeat running on a Linux VM. Filebeat was installed six months ago by a colleague and works perfectly fine. We are only using the Elasticsearch and Filebeat parts of the stack. We would like to use Metricbeat as well.

I did need to sudo chmod 644 the /etc/metricbeat/metricbeat.yml file.

My current problem is when I try to run "sudo service metricbeat start", the command does not succeed.

Looking in /var/log/metricbeat/metricbeat reveals the error to be: "Exiting: Error importing Kibana dashboards: fail to import the dashboards in Kibana: Error importing directory /usr/share/metricbeat/kibana: Failed to import index-pattern: Failed to load directory /usr/share/metricbeat/kibana/6/index-pattern:
error loading /usr/share/metricbeat/kibana/6/index-pattern/metricbeat.json: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];. Response: {"objects":[{"id":"metricbeat-*","type":"index-pattern","error":{"message":"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"}}]}"

Is this error actually indicative of the disk being full? "df -h /var" informs me that the /var/ is only 60% full.

Can anyone please shed some light on what is going wrong?


I can think of two causes for this.

Are you using any Security features? (Do you have a security section under Management, in Kibana?) Access restrictions can be forbidding metricbeat to access the .kibana index.

Another cause can be a problem as described in this post:

For which the solution is to run this command in Kibana -> Dev Tools -> Console:

PUT .kibana/_settings
"index": {
"blocks": {
"read_only_allow_delete": "false"


There's no Security section under Management in Kibana. Using Kibana version 6.0.1.

I'll try the PUT and report back.


The PUT was the solution.

Thank you very much!

