# \*\*\* SOLVED \*\*\* Forbidden to create Index Pattern in Kibana 7.2

**URL:** <https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947>\
**Category:** Kibana\
**Created:** [July 17, 2019, 9:54am UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947 "2019-07-17T09:54:05Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [July 17, 2019, 9:54am UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/1 "2019-07-17T09:54:05Z")

</div>

Hi guys,

is there any simple solution how to fix Forbidden Error while creating index pattern in Kibana? I am still getting this error when trying to create a new index pattern.

```
Error: Forbidden
      _construct@https://hostname/bundles/commons.bundle.js:3:1609071
Wrapper@https://hostname/bundles/commons.bundle.js:3:1608183
KFetchError@https://hostname/bundles/commons.bundle.js:3:1609714
kfetch/<@https://hostname/bundles/commons.bundle.js:3:1605400
run@https://hostname/built_assets/dlls/vendors.bundle.dll.js:92:797402
notify/<@https://hostname/built_assets/dlls/vendors.bundle.dll.js:92:797642
flush@https://hostname/built_assets/dlls/vendors.bundle.dll.js:250:1512804

```

Thanks

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 17, 2019, 12:36pm UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/2 "2019-07-17T12:36:52Z")

</div>

Hi,  
May be you have reached high watermark disk? Elasticsearch's index is made read-only and never set back when disk watermark reached high.

To unlock all indexes manually:

`curl -XPUT -H "Content-Type: application/json" https://[YOUR_ELASTICSEARCH_ENDPOINT]:9200/_all/_settings -d '{"index.blocks.read_only_allow_delete": null}'`

Try this. Else plz post detailed steps as to how you hit this error. It would be easier to debug.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [July 17, 2019, 2:00pm UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/3 "2019-07-17T14:00:11Z")

</div>

Hi,

no, it didn't help. Even i have a lot of disk space. I created a new VM, installed ELK 7.2, configure input/output to process netflow data. Index for that was automatically created in logstash and i can see docs are increasing. Then i went to Kibana to create an index pattern. Kibana recognize it, but when i click on the last step/button to create it i got this error.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [July 18, 2019, 5:16pm UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/4 "2019-07-18T17:16:49Z")

</div>

@thirty2 would you mind running the following using Dev Tools and providing us the response?

> GET \_security/user/\_privileges

---

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [July 22, 2019, 10:56am UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/5 "2019-07-22T10:56:59Z")

</div>

@Brandon_Kobel here you are:

> {  
> "error": {  
> "root\_cause": [  
> {  
> "type": "exception",  
> "reason": "Security must be explicitly enabled when using a [basic] license. Enable security by setting [xpack.security.enabled] to [true] in the elasticsearch.yml file and restart the node."  
> }  
> ],  
> "type": "exception",  
> "reason": "Security must be explicitly enabled when using a [basic] license. Enable security by setting [xpack.security.enabled] to [true] in the elasticsearch.yml file and restart the node."  
> },  
> "status": 500  
> }

When i set this:

> xpack.security.enabled: true

in config i am not able to start Kibana then. Getting message in gui, then Kibana is not ready yet.

What esle should be configured?  
Thanks

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [July 24, 2019, 5:00pm UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/6 "2019-07-24T17:00:31Z")

</div>

You don't have to enabled security in Elasticsearch to be able to create index patterns in Kibana.

Would you mind running the following queries in Dev Tools and replying with their responses?

```auto
GET _cat/aliases
GET _cat/indices
GET _all/_settings

```

---

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [July 26, 2019, 7:44am UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/7 "2019-07-26T07:44:57Z")

</div>

Here you are:

> .kibana .kibana\_1 - - -  
> logstash logstash-2019.07.17-000001 - - -

> green open .monitoring-es-7-2019.07.21 rRysXjkoQqGsznb-1TcBgg 1 1 146926 224588 192.9mb 96.9mb  
> green open .monitoring-es-7-2019.07.22 uBmo\_NDnQP2wcOPEqcN2Jw 1 1 75324 120 80.5mb 40.3mb  
> green open .monitoring-kibana-7-2019.07.22 DZFcKeGxTkmeHXjSktF3fw 1 1 3959 0 1.7mb 842.4kb  
> green open .monitoring-es-7-2019.07.20 R8kXKeCzSsm\_qy5mNxcL8g 1 1 129641 190036 134.5mb 84.7mb  
> green open .kibana\_1 X\_bMFJWzS-iU6EzFrEXX\_A 1 1 5 3 77.8kb 38.9kb  
> green open .kibana\_task\_manager C-yrCUgfRj2Ah67Xn-xs5g 1 1 2 0 42.8kb 21.4kb  
> green open netflow\_test1 Mp3aajeNQZyGQ80dXXjy8w 1 1 2512387 0 898mb 359.6mb  
> green open .monitoring-kibana-7-2019.07.21 oo1OZVx\_TCKRmctv2prNzg 1 1 8639 0 3.4mb 1.7mb  
> green open test P-DgXP1LRkCIyMeekt9C\_w 1 1 3 1 16.2kb 6.1kb  
> green open .monitoring-kibana-7-2019.07.20 R\_T46TswRQeehBVybcqoqw 1 1 8640 0 3.3mb 1.6mb  
> green open logstash-2019.07.17-000001 TRjBlU-dQ9asp2J4fe-Y0g 1 1 217643 0 47.9mb 23.9mb

> {  
> ".kibana\_task\_manager" : {  
> "settings" : {  
> "index" : {  
> "number\_of\_shards" : "1",  
> "auto\_expand\_replicas" : "0-1",  
> "provided\_name" : ".kibana\_task\_manager",  
> "creation\_date" : "1563432784676",  
> "number\_of\_replicas" : "1",  
> "uuid" : "C-yrCUgfRj2Ah67Xn-xs5g",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> },  
> ".monitoring-es-7-2019.07.22" : {  
> "settings" : {  
> "index" : {  
> "codec" : "best\_compression",  
> "number\_of\_shards" : "1",  
> "auto\_expand\_replicas" : "0-1",  
> "provided\_name" : ".monitoring-es-7-2019.07.22",  
> "format" : "7",  
> "creation\_date" : "1563753608377",  
> "number\_of\_replicas" : "1",  
> "uuid" : "uBmo\_NDnQP2wcOPEqcN2Jw",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> },  
> "test" : {  
> "settings" : {  
> "index" : {  
> "creation\_date" : "1563432198834",  
> "number\_of\_shards" : "1",  
> "number\_of\_replicas" : "1",  
> "uuid" : "P-DgXP1LRkCIyMeekt9C\_w",  
> "version" : {  
> "created" : "7020099"  
> },  
> "provided\_name" : "test"  
> }  
> }  
> },  
> ".monitoring-kibana-7-2019.07.22" : {  
> "settings" : {  
> "index" : {  
> "codec" : "best\_compression",  
> "number\_of\_shards" : "1",  
> "auto\_expand\_replicas" : "0-1",  
> "provided\_name" : ".monitoring-kibana-7-2019.07.22",  
> "format" : "7",  
> "creation\_date" : "1563753609027",  
> "number\_of\_replicas" : "1",  
> "uuid" : "DZFcKeGxTkmeHXjSktF3fw",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> },  
> "netflow\_test1" : {  
> "settings" : {  
> "index" : {  
> "creation\_date" : "1563350174043",  
> "number\_of\_shards" : "1",  
> "number\_of\_replicas" : "1",  
> "uuid" : "Mp3aajeNQZyGQ80dXXjy8w",  
> "version" : {  
> "created" : "7020099"  
> },  
> "provided\_name" : "netflow\_test1"  
> }  
> }  
> },  
> ".monitoring-kibana-7-2019.07.21" : {  
> "settings" : {  
> "index" : {  
> "codec" : "best\_compression",  
> "number\_of\_shards" : "1",  
> "auto\_expand\_replicas" : "0-1",  
> "provided\_name" : ".monitoring-kibana-7-2019.07.21",  
> "format" : "7",  
> "creation\_date" : "1563667209651",  
> "number\_of\_replicas" : "1",  
> "uuid" : "oo1OZVx\_TCKRmctv2prNzg",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> },  
> ".monitoring-kibana-7-2019.07.20" : {  
> "settings" : {  
> "index" : {  
> "codec" : "best\_compression",  
> "number\_of\_shards" : "1",  
> "auto\_expand\_replicas" : "0-1",  
> "provided\_name" : ".monitoring-kibana-7-2019.07.20",  
> "format" : "7",  
> "creation\_date" : "1563580800069",  
> "number\_of\_replicas" : "1",  
> "uuid" : "R\_T46TswRQeehBVybcqoqw",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> },  
> ".monitoring-es-7-2019.07.20" : {  
> "settings" : {  
> "index" : {  
> "codec" : "best\_compression",  
> "number\_of\_shards" : "1",  
> "auto\_expand\_replicas" : "0-1",  
> "provided\_name" : ".monitoring-es-7-2019.07.20",  
> "format" : "7",  
> "creation\_date" : "1563580804940",  
> "number\_of\_replicas" : "1",  
> "uuid" : "R8kXKeCzSsm\_qy5mNxcL8g",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> },  
> ".monitoring-es-7-2019.07.21" : {  
> "settings" : {  
> "index" : {  
> "codec" : "best\_compression",  
> "number\_of\_shards" : "1",  
> "auto\_expand\_replicas" : "0-1",  
> "provided\_name" : ".monitoring-es-7-2019.07.21",  
> "format" : "7",  
> "creation\_date" : "1563667206639",  
> "number\_of\_replicas" : "1",  
> "uuid" : "rRysXjkoQqGsznb-1TcBgg",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> },  
> ".kibana\_1" : {  
> "settings" : {  
> "index" : {  
> "number\_of\_shards" : "1",  
> "auto\_expand\_replicas" : "0-1",  
> "provided\_name" : ".kibana\_1",  
> "creation\_date" : "1563432784928",  
> "number\_of\_replicas" : "1",  
> "uuid" : "X\_bMFJWzS-iU6EzFrEXX\_A",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> },  
> "logstash-2019.07.17-000001" : {  
> "settings" : {  
> "index" : {  
> "refresh\_interval" : "5s",  
> "number\_of\_shards" : "1",  
> "provided\_name" : "\<logstash-{now/d}-000001\>",  
> "creation\_date" : "1563362909294",  
> "number\_of\_replicas" : "1",  
> "uuid" : "TRjBlU-dQ9asp2J4fe-Y0g",  
> "version" : {  
> "created" : "7020099"  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [July 26, 2019, 2:44pm UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/8 "2019-07-26T14:44:52Z")

</div>

You don't happen to be putting a reverse-proxy (nginx/apache/etc.) in-front of Kibana/ES, are you? Have you checked your Elasticsearch logs to see if any errors are being thrown?

---

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [July 28, 2019, 3:36pm UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/9 "2019-07-28T15:36:28Z")

</div>

> [@Brandon\_Kobel](#):
>
> reverse-proxy

Yes, i am behind proxy. i can see in the apache log, that when i click on create index in Kibana i get error

> AH01797: client denied by server configuration: proxy:https:

Problem Solved. There was misconfiguration in httpd conf. Working when default httpd is listening on port 80 and virtual host is on 443.

Thanks for support

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2019, 3:36pm UTC](https://discuss.elastic.co/t/solved-forbidden-to-create-index-pattern-in-kibana-7-2/190947/10 "2019-08-25T15:36:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
