# Packetbeat Dashboard Help

**URL:** <https://discuss.elastic.co/t/packetbeat-dashboard-help/153467>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [October 22, 2018, 7:04pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-help/153467 "2018-10-22T19:04:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Moreno](https://avatars.discourse-cdn.com/v4/letter/d/779978/32.png) [@David\_Moreno](https://discuss.elastic.co/u/David_Moreno)\
**Post date:** [October 22, 2018, 7:04pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-help/153467/1 "2018-10-22T19:04:36Z")

</div>

Hello Im trying to install a packetbeat dashboard on my ELK server. Im running the command:  
packetbeat setup --dashboards

And I get this:  
Loading dashboards (Kibana must be running and reachable)  
Exiting: Error importing Kibana dashboards: fail to import the dashboards in Kibana: Error importing directory /usr/share/packetbeat/kibana: Failed to import index-pattern: Failed to load directory /usr/share/packetbeat/kibana/6/index-pattern:  
error loading /usr/share/packetbeat/kibana/6/index-pattern/packetbeat.json: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];. Response: {"objects":[{"id":"packetbeat-\*","type":"index-pattern","error":{"message":"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"}}]}

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [October 29, 2018, 12:02pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-help/153467/2 "2018-10-29T12:02:36Z")

</div>

> [@David\_Moreno](#):
>
> FORBIDDEN/12/index read-only / allow delete

Hi,

This error usually appears because Elasticsearch detects a disk full condition and sets the index to read-only. It seems that sometimes the error condition is not cleared after disk is freed and manual action is required.

See this issue in github for suggested fix:

> <https://github.com/elastic/kibana/issues/13685>
>
> \<!--
> GitHub is reserved for bug reports and feature requests. The best place
> t…o ask a general question is at the Elastic Discourse forums at
> https://discuss.elastic.co. If you are in fact posting a bug report or
> a feature request, please include one and only one of the below blocks
> in your new issue.
> \--\>
> 
> \<!--
> If you are filing a bug report, please remove the below feature
> request block and provide responses for all of the below items.
> \--\>
> 
> \*\*Kibana version\*\*: 6.0.0-beta1
> 
> \*\*Elasticsearch version\*\*: 6.0.0-beta1
> 
> \*\*Server OS version\*\*: Ubuntu 16.04.2 LTS
> 
> \*\*Browser version\*\*: Chrome 60.0.3112.90
> 
> \*\*Browser OS version\*\*: Windows 10
> 
> \*\*Original install method (e.g. download page, yum, from source, etc.)\*\*: Official tar.gz packages
> 
> \*\*Description of the problem including expected versus actual behavior\*\*:
> 
> I'm running a single node Elasticsearch instance, logstash and Kibana. Everything runs on the same host in separate docker containers.
> 
> If the high disk watermark is exceeded on the ES host, the following is logged in the elasticsearch log:
> 
> \`\`\`
> \[2017-08-24T07:45:11,757\]\[INFO \]\[o.e.c.r.a.DiskThresholdMonitor\] \[CSOifAr\] rerouting shards: \[high disk watermark exceeded on one or more nodes\]
> \[2017-08-24T07:45:41,760\]\[WARN \]\[o.e.c.r.a.DiskThresholdMonitor\] \[CSOifAr\] flood stage disk watermark \[95%\] exceeded on \[CSOifArqQK-7PBZM\_keNoA\]\[CSOifAr\]\[/data/elasticsearch/nodes/0\] free: 693.8mb\[2.1%\], all indice
> s on this node will marked read-only
> \`\`\`
> 
> When this has occured, changes to the \`.kibana\` index will of course fail as the index cannot be written to. This can be observed by trying to change any setting under \_Management\_-\>\_Advanced Settings\_ where a change to i.e. \_search:queryLanguage\_ fails with the message \`Config: Error 403 Forbidden: blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];\`
> 
> !\[index\_read\_only\](https://user-images.githubusercontent.com/133108/29657724-d598f60c-88b8-11e7-8e0c-b647dfe5c101.png)
> 
> If more disk space now is made available, ES will log that the node has gone under the high watermark:
> \`\`\`
> \[2017-08-24T07:47:11,774\]\[INFO \]\[o.e.c.r.a.DiskThresholdMonitor\] \[CSOifAr\] rerouting shards: \[one or more nodes has gone under the high or low watermark\]
> \`\`\`
> 
> One would now assume that it would be possible to make changes to Kibana settings but trying to make a settings change still fails with the error message:
> 
> \`Config: Error 403 Forbidden: blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];\`
> 
> \*\*Steps to reproduce\*\*:
> 1. Make sure that setting changes can be performed without errors
> 2. Fill up the elasticsearch data disk so that the high disk watermark is exceeded (I used \`fallocate -l9G largefile\`)
> 3. Verify in the ES log that the high disk watermark has been exceeded and the indices has been marked read-only
> 4. Perform a setting change and verify that it fails since writes are prohibited
> 5. Resolve the high disk watermark condition (which I did with \`rm largefile\`)
> 6. Verify that the ES log states that the node has gone under the high disk watermark (and thus should be possible to write to?)
> 7. Perform a setting change and it will fail when it actually should succeed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2018, 12:10pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-help/153467/3 "2018-11-26T12:10:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
