# Logstash Error 403

**URL:** <https://discuss.elastic.co/t/logstash-error-403/167917>\
**Category:** Logstash\
**Created:** [February 11, 2019, 6:54pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917 "2019-02-11T18:54:20Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![danivanrock](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@danivanrock](https://discuss.elastic.co/u/danivanrock)\
**Post date:** [February 11, 2019, 6:54pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/1 "2019-02-11T18:54:20Z")

</div>

Hi everyone  
Logstash keeps crashing with 403 error, I know this error its caused by no available space on disk, on that moment I had 30 Gb, now I attached 100 Gb on disk and keeps crashing  
I tried removing Logstash, installing another versions but keeps appering same error  
Can someone help this poor blind men?

I have:  
4 CPU  
16 VCPU  
32 GB RAM  
130 GB STORAGE  
CentOS 7

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 11, 2019, 6:58pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/2 "2019-02-11T18:58:02Z")

</div>

What does your configuration file look like, and exactly what error message are you getting?

---

<div class="post-metadata">

**Author:** ![danivanrock](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@danivanrock](https://discuss.elastic.co/u/danivanrock)\
**Post date:** [February 11, 2019, 7:02pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/3 "2019-02-11T19:02:18Z")

</div>

I have installed ElasticStack since a few months and ieverything was run perfectly  
On this week im with those errors

**Error**  
Feb 11 14:00:27 elastic-stack logstash[4197]: [2019-02-11T14:00:27,920][INFO][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=\>"cluster\_block\_exception", "reason"=\>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})

**Configuration Files**  
/etc/logstash/conf.d/02-beats-input.conf

```
input {
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
    ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  }
}

```

/etc/logstash/conf.d/10-syslog-filter.conf

filter {  
if [fileset][module] == "system" {  
if [fileset][name] == "auth" {  
grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: %{DAT$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: %{DATA:[system][auth$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: Did not receive iden$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sudo(?:[%{POSINT:[system][auth][pid]}])?: \s\*%{DATA:[system][a$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} groupadd(?:[%{POSINT:[system][auth][pid]}])?: new group: name= "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} useradd(?:\[%{POSINT:[system][auth][pid]}\])?: new user: name=%{  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} %{DATA:[system][auth][program]}(?:[%{POSINT:[system][auth][pid] pattern\_definitions =\> { "GREEDYMULTILINE"=\> "(.|\n)\*" } remove\_field =\> "message" } date { match =\> ["[system][auth][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ] } geoip { source =\> "[system][auth][ssh][ip]" target =\> "[system][auth][ssh][geoip]" } } else if [fileset][name] == "syslog" { grok { match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:\[%{POSIN  
pattern\_definitions =\> { "GREEDYMULTILINE" =\> "(.|\n)\*" }  
remove\_field =\> "message"  
}  
date {  
match =\> ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}  
}  
}  
}

/etc/logstash/conf.d/30-elasticsearch-output.conf

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

Thanks for the support

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 11, 2019, 7:12pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/4 "2019-02-11T19:12:15Z")

</div>

OK, so you ran out of disk space and elasticsearch put the indexes into read-only mode. Once you have added or freed up disk space you need to tell elasticsearch to enable read-write. See [this post](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/126067/12?u=badger) for how to do that.

---

<div class="post-metadata">

**Author:** ![danivanrock](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@danivanrock](https://discuss.elastic.co/u/danivanrock)\
**Post date:** [February 11, 2019, 7:15pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/5 "2019-02-11T19:15:43Z")

</div>

Oh dude! Thanks, Im on it!  
THANKS

---

<div class="post-metadata">

**Author:** ![danivanrock](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@danivanrock](https://discuss.elastic.co/u/danivanrock)\
**Post date:** [February 11, 2019, 7:55pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/6 "2019-02-11T19:55:01Z")

</div>

Hello again, im running next command but im receiving the next error:

**Error:**  
curl: (3) [globbing] nested braces not supported at pos 27

**Command:**  
curl -X PUT "localhost:9200/filebeat-%{[@metadata][version]}-2019.02.07/\_settings" -H 'Content-Type: application/json' -d'  
{  
"index.blocks.read\_only\_allow\_delete": null  
}  
'

Can you please tell me what im doing wrong?  
Thanks bro

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 11, 2019, 8:05pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/7 "2019-02-11T20:05:34Z")

</div>

> [@danivanrock](#):
>
> %{[@metadata][version]}

In this context, there is no metadata to do a substition from. Check your index name, it will be something like filebeat-6.6.0-2019.02.07 and use that name in the curl command.

Oh, and if filebeat-%{[@metadata][version]}-2019.02.07 really is the literal name of your index then you may need to use backslash to escape some of the characters ({} and/or []).

---

<div class="post-metadata">

**Author:** ![davegerber](https://avatars.discourse-cdn.com/v4/letter/d/7ab992/32.png) [@davegerber](https://discuss.elastic.co/u/davegerber)\
**Post date:** [February 11, 2019, 8:59pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/8 "2019-02-11T20:59:16Z")

</div>

In the event that you have to do date math, you should cast the field esteems to date types in Painless. Regularly students ask me to [do my homework for me](https://www.domyhomework4me.net/). Who interested, welcome

---

<div class="post-metadata">

**Author:** ![danivanrock](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@danivanrock](https://discuss.elastic.co/u/danivanrock)\
**Post date:** [February 12, 2019, 6:19pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/9 "2019-02-12T18:19:33Z")

</div>

Its done! Thanks bro, a lot!!!!!! \<3

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2019, 6:19pm UTC](https://discuss.elastic.co/t/logstash-error-403/167917/10 "2019-03-12T18:19:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
