# Logstash Error: Retrying Failed Action With Response Code 403

**URL:** <https://discuss.elastic.co/t/logstash-error-retrying-failed-action-with-response-code-403/174864>\
**Category:** Elasticsearch\
**Created:** [April 1, 2019, 8:08pm UTC](https://discuss.elastic.co/t/logstash-error-retrying-failed-action-with-response-code-403/174864 "2019-04-01T20:08:19Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [April 1, 2019, 8:20pm UTC](https://discuss.elastic.co/t/logstash-error-retrying-failed-action-with-response-code-403/174864/2 "2019-04-01T20:20:47Z")

</div>

Proceeding on the theory that all indices somehow got set to `read_only_allow_delete`, I executed the following command iterate through all indices and reset that flag:

> _Edit: Buggy script removed_

It did not resolve the issue.

## Update

OK...a little embarassing here. As I looked back through what I posted yesterday, I noticed that I had a typo in the `curl` statement. It read: `curl -s -X PUT -H "<header>" "<json>" -d "<url>"`.

I updated it as follows:

```
#!/bin/bash
for i in $(curl -s -X GET http://localhost:9200/_cat/indices | awk -F ' ' '{print $3}' | sort)
do
    echo Updating ${i}: $(curl -s -X PUT -H "Content-Type: application/json" \
                               -d '{"index.blocks.read_only_allow_delete": null}' \
                               "http://localhost:9200/${i}/_settings")
done

```

...which unlocked my indices as expected and allowed log entries to start flowing again. I'm still uncertain why this occurred, however, as I'm unable to see any errors on the ES side of things.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-error-retrying-failed-action-with-response-code-403/174864)._
