# Save search in Kibana

**URL:** <https://discuss.elastic.co/t/save-search-in-kibana/154049>\
**Category:** Kibana\
**Created:** [October 25, 2018, 5:47pm UTC](https://discuss.elastic.co/t/save-search-in-kibana/154049 "2018-10-25T17:47:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohitg](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@rohitg](https://discuss.elastic.co/u/rohitg)\
**Post date:** [October 25, 2018, 5:47pm UTC](https://discuss.elastic.co/t/save-search-in-kibana/154049/1 "2018-10-25T17:47:08Z")

</div>

My ELK cluster on Windows server and have one node only.  
When trying to Save search in Kibana, I am getting below error.  
Please help how to fix it. Thanks in Advance.

Discover: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];

Less Info  
OK  
Error: Forbidden  
at \_callee$ ([http://mylogs.com/bundles/commons.bundle.js:3:426340](http://mylogs.com/bundles/commons.bundle.js:3:426340))  
at tryCatch ([http://mylogs.com/bundles/vendors.bundle.js:29:602784](http://mylogs.com/bundles/vendors.bundle.js:29:602784))  
at Generator.invoke [as \_invoke] ([http://mylogs.com/bundles/vendors.bundle.js:29:606666](http://mylogs.com/bundles/vendors.bundle.js:29:606666))  
at Generator.prototype.(anonymous function) [as next] ([http://mylogs.com/bundles/vendors.bundle.js:29:603907](http://mylogs.com/bundles/vendors.bundle.js:29:603907))  
at step ([http://mylogs.com/bundles/commons.bundle.js:3:423136](http://mylogs.com/bundles/commons.bundle.js:3:423136))  
at [http://mylogs.com/bundles/commons.bundle.js:3:423262](http://mylogs.com/bundles/commons.bundle.js:3:423262)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 25, 2018, 5:48pm UTC](https://discuss.elastic.co/t/save-search-in-kibana/154049/2 "2018-10-25T17:48:26Z")

</div>

This often means that you have exceeded 95% of available disk space, so you may need to look at whether you potentially need to do some housekeeping.

---

<div class="post-metadata">

**Author:** ![rohitg](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@rohitg](https://discuss.elastic.co/u/rohitg)\
**Post date:** [October 25, 2018, 5:50pm UTC](https://discuss.elastic.co/t/save-search-in-kibana/154049/3 "2018-10-25T17:50:11Z")

</div>

I have checked that and my windows server have more than 40% disk space available.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 25, 2018, 5:50pm UTC](https://discuss.elastic.co/t/save-search-in-kibana/154049/4 "2018-10-25T17:50:53Z")

</div>

Is there anything in the Elasticsearch logs?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2018, 5:50pm UTC](https://discuss.elastic.co/t/save-search-in-kibana/154049/5 "2018-11-22T17:50:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
