# Logstash-Elastic problems

**URL:** <https://discuss.elastic.co/t/logstash-elastic-problems/119844>\
**Category:** Elasticsearch\
**Created:** [February 14, 2018, 4:30pm UTC](https://discuss.elastic.co/t/logstash-elastic-problems/119844 "2018-02-14T16:30:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ninoslav](https://avatars.discourse-cdn.com/v4/letter/n/edb3f5/32.png) [@Ninoslav](https://discuss.elastic.co/u/Ninoslav)\
**Post date:** [February 14, 2018, 4:30pm UTC](https://discuss.elastic.co/t/logstash-elastic-problems/119844/1 "2018-02-14T16:30:53Z")

</div>

Hi gys,

I am using ELK stack 6.0, and it worked nice, till 2 day before, I have obviosuly done something rly wrong,  
and my logstash is not working correctly.

My logstash log got flooded with logs like:

> [2018-02-14T17:15:36,862][INFO][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=\>"cluster\_block\_exception", "reason"=\>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})  
> [2018-02-14T17:15:36,862][INFO][logstash.outputs.elasticsearch] Retrying individual bulk actions that failed or were rejected by the previous bulk request. {:count=\>10}

It is been like 3 GB of data in log, and 0 data in elasctic search.

Is someone could point me what to do.  
From log it seems like some index is marked as read only, but i cant remember ever doing something like that.

Thanks in advance.

Cheers.

Ninoslav.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2018, 4:31pm UTC](https://discuss.elastic.co/t/logstash-elastic-problems/119844/2 "2018-03-14T16:31:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
