# Unable to create index pattern from Kibana

**URL:** <https://discuss.elastic.co/t/unable-to-create-index-pattern-from-kibana/167184>\
**Category:** Kibana\
**Created:** [February 5, 2019, 7:18pm UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-from-kibana/167184 "2019-02-05T19:18:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmckeown](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jmckeown](https://discuss.elastic.co/u/jmckeown)\
**Post date:** [February 5, 2019, 7:18pm UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-from-kibana/167184/1 "2019-02-05T19:18:57Z")

</div>

I am experiencing a problem similar in nature to the one here:

> [@Kibana creating new index forever](https://discuss.elastic.co/t/kibana-creating-new-index-forever/152401):
>
> ~Hello, I have an issue creating new Index in Kibana 6.4.0; I successfully create logs with indexes on logstash - Kibana see's the inside of those logs in Dev Tolls - but for some reason when I go to Management-\>Index Patterns -\> Create new Index - and I pick the indexes I'm looking for the circle for 'creating' is spinning forever- I've left it for 7 hours without result - I even stopped logstash when logs had only few MB - still it was spinning constantly. […](https://imgur.com/a/7PkKxEG)

I have written a few (five) documents to an index, but when I attempt to make an index pattern through Kibana, the wheel just spins.

As per @jbudz's request, here are my kibana settings.

{".kibana":{"settings":{"index":{"number\_of\_shards":"1","auto\_expand\_replicas":"0-1","blocks":{"read\_only\_allow\_delete":"true"},"provided\_name":".kibana","creation\_date":"1541011008451","number\_of\_replicas":"0","uuid":"45i6FyJUQTad-fes0s72vg","version":{"created":"6040299"}}}}}

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [March 1, 2019, 7:25pm UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-from-kibana/167184/2 "2019-03-01T19:25:32Z")

</div>

> [@jmckeown](#):
>
> "read\_only\_allow\_delete":"true"

I think you are hitting high threshold and hence its becoming read only indices. Can you free up some space to see if this gets resolved ?

All indexes get locked when the disk threshold is reached

To unlock all indexes manually:

curl -XPUT -H "Content-Type: application/json" https://[YOUR\_ELASTICSEARCH\_ENDPOINT]:9200/\_all/\_settings -d '{"index.blocks.read\_only\_allow\_delete": null}'

Also try deleting .kibana index to get it back up and going.

Hope it helps  
Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![jmckeown](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jmckeown](https://discuss.elastic.co/u/jmckeown)\
**Post date:** [March 1, 2019, 7:46pm UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-from-kibana/167184/3 "2019-03-01T19:46:31Z")

</div>

I think that was the problem. high disk watermark [90%] exceeded on [fcqHgNaCRUWBvF5fvgxl\_A][fcqHgNa][/usr/local/var/lib/elasticsearch/nodes/0] free: 13.7gb[5.8%], shards will be relocated away from this node

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [March 1, 2019, 8:44pm UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-from-kibana/167184/4 "2019-03-01T20:44:09Z")

</div>

Am glad that the root cause is know.. Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 8:44pm UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-from-kibana/167184/5 "2019-03-29T20:44:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
