# RuleDataWriteDisabledError ELK v8.5

**URL:** <https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031>\
**Category:** Endpoint Security\
**Tags:** detection-rules\
**Created:** [November 29, 2022, 10:30am UTC](https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031 "2022-11-29T10:30:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [November 29, 2022, 10:30am UTC](https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031/1 "2022-11-29T10:30:26Z")

</div>

getting this error

> Bulk Indexing of signals failed: RuleDataWriteDisabledError: Rule registry writing is disabled due to an error during Rule Data Client initialization.

After I updated ELK from 8.4 to 8.5

 ![chrome_5J8FxwFShT](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d6b2c09ec1d5e446674b4de20e7c62145b8abeab.png)

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [December 1, 2022, 4:52pm UTC](https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031/2 "2022-12-01T16:52:28Z")

</div>

Try updating to version 8.5.2 and see if the issue still occurs. There were some improvements:

> **[Check out the latest from Elastic | Elasticsearch Platform and Solutions...](https://www.elastic.co/guide/en/welcome-to-elastic/8.5/new.html)**

---

<div class="post-metadata">

**Author:** ![John\_Perkins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_perkins/32/80780_2.png) [@John\_Perkins](https://discuss.elastic.co/u/John_Perkins)\
**Post date:** [December 1, 2022, 8:22pm UTC](https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031/3 "2022-12-01T20:22:45Z")

</div>

We are getting this too after upgrading from 8.3.3 to 8.5.2.

---

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [December 2, 2022, 7:20am UTC](https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031/4 "2022-12-02T07:20:06Z")

</div>

Thanks for the response guys

![VirtualBoxVM_dvFZYp9lpO](https://us1.discourse-cdn.com/elastic/original/3X/3/3/33e90b5daa7a89e57c0214b2ae0459b4ee36dbb6.png)

Already on 8.5.2  
The issue started when I updated ELK from 8.4 to 8.5.2

---

<div class="post-metadata">

**Author:** ![John\_Perkins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_perkins/32/80780_2.png) [@John\_Perkins](https://discuss.elastic.co/u/John_Perkins)\
**Post date:** [December 5, 2022, 1:15pm UTC](https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031/5 "2022-12-05T13:15:09Z")

</div>

We found a solution. Elastic support gets credit they figured it out for us. Here is a copy paste of their response.

"....due to custom mapping change on .alerts-security.alerts-_-index-template, some existing .alerts-_ indices don’t have standard mappings. After a new version of Kibana has started up, as soon as an alerting rule tries to write an alert to a `.alert-*` index it will run some bootstrapping logic. This bootstrapping logic will update a few alert component templates, and the index template for the relevant alerts. After doing this, the algorithm will iterate through each existing index that matches the index template and update the old indices with the new mappings. If this bootstrap logic fails, that error would occur."

For us, there was only one older .alerts index with a nonstandard mapping. We did not need that index and so we deleted it. Rebooted kibana. Issue resolved.

If you have any index templates applying such custom mappings you will need to address it there to avoid continuing to recreate the problem AND then also delete on any indices that already have the custom mappings.

---

<div class="post-metadata">

**Author:** ![theacodes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theacodes/32/113779_2.png) [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Post date:** [December 16, 2022, 5:05am UTC](https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031/6 "2022-12-16T05:05:54Z")

</div>

Thanks a lot. This worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2023, 5:06am UTC](https://discuss.elastic.co/t/ruledatawritedisablederror-elk-v8-5/320031/7 "2023-01-13T05:06:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
