# \[FORBIDDEN/12/index read-only / allow delete (api)\];"})

**URL:** <https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113>\
**Category:** Elasticsearch\
**Created:** [December 26, 2018, 8:24am UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113 "2018-12-26T08:24:35Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [December 26, 2018, 8:24am UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/1 "2018-12-26T08:24:35Z")

</div>

Can someone please let me know where I can exactly apply these settings in 6.5, as I'm totally new to ELK :

> [@FORBIDDEN/12/index read-only / allow delete (api)\]](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/110282/4):
>
> I tried doing that with powershell WebRequest but it still gives me this error. I mean this very same command yields the error 'FORBIDDEN/12/index-read-only'

> [@Locked/read only indices](https://discuss.elastic.co/t/locked-read-only-indices/144850/7):
>
> Thank you so much for your help. I ran the following command to disable the threshold: PUT /\_cluster/settings { "persistent" : { "cluster.routing.allocation.disk.threshold\_enabled" : false } } After that I restarted the elasticsearch and Kibana services, ran the following command: PUT .kibana/\_settings { "index": { "blocks": { "read\_only\_allow\_delete": false } } } Now it works again.

And are these steps applicable on 6.5 version ?

Thank you

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 26, 2018, 8:51am UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/2 "2018-12-26T08:51:23Z")

</div>

This typically indicates that you are running out of disk space and have exceeded the 95% flood stage watermark.

---

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [December 26, 2018, 9:35am UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/3 "2018-12-26T09:35:28Z")

</div>

Yes Christian, I do know that. But I need to know where is the settings to be done exactly. I don't have any clue.

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [December 26, 2018, 11:30am UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/4 "2018-12-26T11:30:11Z")

</div>

Hello,

You need to increase your disk space to eliminate the issue. No need to change any settings.

Regards

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 26, 2018, 1:06pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/5 "2018-12-26T13:06:56Z")

</div>

You need to either delete data or add capacity. Once you are below the watermark you can follow the instructions available [here](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/disk-allocator.html) to unlock the indices.

---

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [December 26, 2018, 2:16pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/6 "2018-12-26T14:16:40Z")

</div>

Thanks Christian,

So I just need to add below settings to elaticsearch.yml file and restart service :

PUT your\_index\_name/\_settings  
{  
"index": {  
"blocks": {  
"read\_only\_allow\_delete": "false"  
}  
}  
}

Are there any specific ways to restart elastic service without crashing it down. Because in past, this had happened. As soon as I have restarted the service of elasticsearch, it crashed. I had to reinstall my system for that date !!!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 26, 2018, 2:19pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/7 "2018-12-26T14:19:02Z")

</div>

Have you freed up space or added capacity? If not it will just go back to read-only again.

I also believe this is an index setting, so it can not be applied through the `elasticsearch.yml` file. You need to change it using the API.

---

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [December 26, 2018, 2:39pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/8 "2018-12-26T14:39:47Z")

</div>

Yes, space has been freed up. Like can you just guide me to simple link, where it just specifically says which file to edit, what needs to added or removed, etc. For me it is going round and round and confusing.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 26, 2018, 2:41pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/9 "2018-12-26T14:41:34Z")

</div>

There is no file to edit. You need to use the API (as in your example) to again enable the indices. Am not sure whether or not it allows the use of wildcards when specifying the index name.

---

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [December 26, 2018, 2:46pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/10 "2018-12-26T14:46:36Z")

</div>

Sorry, to be a pain. Resolved issue by referring below link :

> [@FORBIDDEN/12/index read-only / allow delete (api)\]](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/110282/4):
>
> I tried doing that with powershell WebRequest but it still gives me this error. I mean this very same command yields the error 'FORBIDDEN/12/index-read-only'

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 23, 2019, 2:46pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113/11 "2019-01-23T14:46:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
