Problem indexation mails to elasticsearch with logstash

hi everyone please i need your help
i got verytime this error when i run logstash i have no idea why !!

error :
"from" => "Codecademy learn@codecademy.com",
"@version" => "1",
"content-type" => "multipart/alternative; boundary=fcb686ad6f791e939fc66880e959ffbe48d2fb1c1d9be871ff7b77e7d309; charset=utf-8",
"x-antivirus-status" => "Clean",
"x-google-smtp-source" => "AIpwx49ANKbIusL8mvLkCGFxN9xUArzkc8W1ERv4tZQs0FCXsSBFB4oj1gIeXS+ZUw06iP5I0Iwk",
"x-received" => "by 2002:ac8:3fd9:: with SMTP id v25-v6mr7356283qtk.54.1524164613267; Thu, 19 Apr 2018 12:03:33 -0700 (PDT)",
"arc-seal" => "i=1; a=rsa-sha256; t=1524164613; cv=none; d=google.com; s=arc-20160816; b=x/DI9v7XmFr3PI6xUE2elN7u3wWkL2pbXQeGkISenC9quVaqw0Ih8oqpx5TYjGnDT2 BWY3CCv69rL7ryrYIIaU3KpouYe18bF9hqqKdxUT1sy+IZQGw+IT711hALofsw2by3Fw fEAkmOLwBmLaa1yDPeB5r54BoTWnup4rc/XQMrVXhsWF82ZpICiX5859KoSboNX8AmHK Fa/UfCivSmJWP19EuC2Y+bHmZqluT9b1yj7N6kIDPm67eYyfkKVEYjOZxEiUVgjHqvNA 26nLyVisRN7BL4gSGlS2SyRlB8rh/Wm9VzskNcUS1I9M3LRkfQ7KDrjYQYDD19o2tt/c HhnA==",
"x-csa-complaints" => "whitelist-complaints@eco.de",
"subject" => "Get where you're going, faster.",
"authentication-results" => "mx.google.com; dkim=pass header.i=@codecademy.com header.s=smtpapi header.b=v8zZenlx; dkim=pass header.i=@sendgrid.info header.s=smtpapi header.b=rbbYaLH3; spf=pass (google.com: domain of bounces+2018174-86d7-rouchad767=gmail.com@delivery.customeriomail.com designates 198.21.3.35 as permitted sender) smtp.mailfrom=bounces+2018174-86d7-rouchad767=gmail.com@delivery.customeriomail.com",
"x-sg-id" => "YDTqBOjidbCUo/ar1oAtZnPH/ln4ImTd/iCW7/3daTBgFa5WlvplHGczoQRaKRBBzyYK/eE5f4u2KV FsMxFMcw==",
"dkim-signature" => [
[0] "v=1; a=rsa-sha1; c=relaxed/relaxed; d=codecademy.com; h=content-type:from:list-unsubscribe:mime-version:subject:to; s=smtpapi; bh=6q/T5chYYyVUyx+TKrj+HjbICy8=; b=v8zZenlxy4u7ET/hjC MbYMKuPP+piuXB2BIg4WqDpbhx10xlsGHxoecXLj39sXNpatzVo53X8G7ZkXndQc 7mv13eNAp4anDa30fMNF1Zy2oSfOR0cN4p/RLYHXM8Sk3NAr1rVnllItb04O90Yn F4rJf6J/RNUPYDReuZFZ6WRig=",
[1] "v=1; a=rsa-sha1; c=relaxed/relaxed; d=sendgrid.info; h=content-type:from:list-unsubscribe:mime-version:subject:to:x-feedback-id; s=smtpapi; bh=6q/T5chYYyVUyx+TKrj+HjbICy8=; b=rbbYaLH3/BcQS13wQh 9ypoUHW7oPF2yDvBtl+HZKFO6MPW5i/dZid9f9X6PELwgHpu1uOrk2sSUd+67jNM dYimZ4fs7B5Iu2GxDbhkXw8u45Sg5+JVbxC4X8yaHYiAXLU4okYlyJxx1fm72Pl0 jXTXYW8GRH1p30C4R8tLeHqnk="
],
"x-sg-eid" => "hpjZFvg1a/x7FKJAyls6Hq/MiiO/omHXH3w5A8x0Gu8D3UGKTyb1Sst/as0G0v4Nv3AWwvVY+ts2El 8LM0MasKwKm9S2Q0EBkvzfgonsmT4snlBDyA7x3S/qIJ13+uV8XiVueXcLZYUxiYaFKTBvxeGkgZfd 0dYJ+WHtvmoxUZ5Jt4HxVH/1vANbIWcSd+yjfRz+L4T+8j7BANXvh7bCh8EgyX/Hz2f6ALQYk9Dknv g=",
"x-antivirus" => "Avast (VPS 180502-0, 02/05/2018), Inbound message"
}
[2018-05-02T10:47:15,853][INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})
[2018-05-02T10:47:15,925][INFO ][logstash.outputs.elasticsearch] Retrying individual bulk actions that failed or were rejected by the previous bulk request. {:count=>1}
[2018-05-02T10:47:17,330][INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})
[2018-05-02T10:47:17,339][INFO ][logstash.outputs.elasticsearch] Retrying individual bulk actions that failed or were rejected by the previous bulk request. {:count=>1}
[2018-05-02T10:47:17,552][INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [2018-05-02T11:02:18,215][WARN ][logstash.outputs.elasticsearch] You are using a deprecated config setting "document_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=>"document_type", :plugin=><LogStash::Outputs::ElasticSearch index=>"emails", document_type=>"email", hosts=>[//localhost:9200], id=>"63f64c33356aa014f4e71dab92ec26e71e174cb9d42553488e9a4cf3b01f3b9b", enable_metric=>true, codec=><LogStash::Codecs::Plain id=>"plain_22d3b27c-3302-4378-b740-a09adb79709f", enable_metric=>true, charset=>"UTF-8">, workers=>1, manage_template=>true, template_name=>"logstash", template_overwrite=>false, doc_as_upsert=>false, script_type=>"inline", script_lang=>"painless", script_var_name=>"event", scripted_upsert=>false, retry_initial_interval=>2, retry_max_interval=>64, retry_on_conflict=>1, action=>"index", ssl_certificate_verification=>true, sniffing=>false, sniffing_delay=>5, timeout=>60, pool_max=>1000, pool_max_per_route=>100, resurrect_delay=>5, validate_after_inactivity=>10000, http_compression=>false>}
[2018-05-02T11:02:18,409][INFO ][logstash.pipelineaction.reload] Reloading pipeline {"pipeline.id"=>:main}
[2018-05-02T11:02:24,162][WARN ][logstash.shutdownwatcher ] {"inflight_count"=>4, "stalling_thread_info"=>{"other"=>[{"thread_id"=>29, "name"=>nil, "current_call"=>"[...]/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:89:in sleep'"}, {"thread_id"=>30, "name"=>nil, "current_call"=>"[...]/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:89:insleep'"}, {"thread_id"=>31, "name"=>nil, "current_call"=>"[...]/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:89:in sleep'"}, {"thread_id"=>32, "name"=>nil, "current_call"=>"[...]/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:89:insleep'"}]}}
[2018-05-02T11:02:24,276][ERROR][logstash.shutdownwatcher ] The shutdown process appears to be stalled due to busy or blocked plugins. Check the logs for more information.

blocked by: [FORBIDDEN/12/index read-only / allow delete (api)]

Your index is read only. The folks in the Elasticsearch category can help you figure out why.

thank you MagnusBaeck , i will contact them

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.