# Filebeat stop to harvest for nginx log \[Solved\]

**URL:** <https://discuss.elastic.co/t/filebeat-stop-to-harvest-for-nginx-log-solved/169489>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 21, 2019, 8:53pm UTC](https://discuss.elastic.co/t/filebeat-stop-to-harvest-for-nginx-log-solved/169489 "2019-02-21T20:53:55Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Lucio\_Palmieri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucio_palmieri/32/41152_2.png) [@Lucio\_Palmieri](https://discuss.elastic.co/u/Lucio_Palmieri)\
**Post date:** [February 22, 2019, 9:22pm UTC](https://discuss.elastic.co/t/filebeat-stop-to-harvest-for-nginx-log-solved/169489/2 "2019-02-22T21:22:44Z")

</div>

Hi everyone,  
finally I solved and I share the solution hoping it can be useful to others.  
Reading [filebeat docs](https://github.com/elastic/beats/blob/99824df163863478d27688206e18ec27bc1b3ac5/filebeat/docs/how-filebeat-works.asciidoc) , I realized that the problem could be in **logstash** and then I also analyzed its log:

```
FORBIDDEN/12/index read-only / allow delete (api)]

```

so I found the answer in this [Topic](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/110282/4):

> i think my problem is **low storage**. just check your storage first. when it's low, kibana auto changes its config to read-only mode.

So I solved my problem by increasing disk space on the elasticsearch host and removing the read-only mode on the indices by running in kibana:

```
PUT _settings
{
  "index": {
    "blocks": {
      "read_only_allow_delete": "false"
    }
  }
}

```

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-stop-to-harvest-for-nginx-log-solved/169489)._
