# Questions about \[FORBIDDEN/12/index read-only

**URL:** <https://discuss.elastic.co/t/questions-about-forbidden-12-index-read-only/196731>\
**Category:** Elasticsearch\
**Created:** [August 26, 2019, 8:47am UTC](https://discuss.elastic.co/t/questions-about-forbidden-12-index-read-only/196731 "2019-08-26T08:47:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [August 26, 2019, 8:47am UTC](https://discuss.elastic.co/t/questions-about-forbidden-12-index-read-only/196731/1 "2019-08-26T08:47:52Z")

</div>

Hi,

I have a small dev cluster running in kubernetes.  
Since I have quite limited diskspace elasticsearch is often throwing the following error to indexing applications like logstash or kibana:

```
... blocked by: [FORBIDDEN/12/index read-only / allow delete (api)]

```

I have following questions about it:

1. how can I configure different watermarks?
2. why are my cluster and indices shown as green in monitoring tab although my indices are currently read\_only?
3. what is the easiest way to check write ability of indices? I don't want to import all logs of logstash, kibana, elasticsearch if not needed.

Thanks, Andreas

---

<div class="post-metadata">

**Author:** ![ariemenschneider](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ariemenschneider/32/33564_2.png) [@ariemenschneider](https://discuss.elastic.co/u/ariemenschneider)\
**Post date:** [August 26, 2019, 12:05pm UTC](https://discuss.elastic.co/t/questions-about-forbidden-12-index-read-only/196731/2 "2019-08-26T12:05:46Z")

</div>

Hi,

You can change the watermark settings with

```
PUT _cluster/settings
{
  "persistent" : {
    "cluster.routing.allocation.disk.watermark.flood_stage": "98%",
    "cluster.routing.allocation.disk.watermark.low": "90%",
    "cluster.routing.allocation.disk.watermark.high": "96%"
  }
}

```

That the index has been put into read-only/allow delete mode suggests that You've reached the flood\_stage.

The index / cluster health is an indication if all data is redundant / available to Elasticsearch. When the configured redundancy level is reached, Elasticsearch health is "green". If all data is available, but the redundancy is degraded, it is "yellow" and if some index shards are not available it is "red".

When You reach a watermark, Elasticsearch puts a log entry in the logfiles:

```
[o.e.c.r.a.DiskThresholdMonitor] [xxxxdb05.yyy.zz] low disk watermark [95%] exceeded on [tNXqbk9YTOq9MeNhW5eS6g][xxxxdb04.yyy.zz][/var/lib/elasticsearch/nodes/0] free: 23.4gb[4.5%], replicas will not be assigned to this node

```

Regards,  
Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2019, 12:06pm UTC](https://discuss.elastic.co/t/questions-about-forbidden-12-index-read-only/196731/3 "2019-09-23T12:06:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
