# Update\_mapping causes index.blocks.write to go to true

**URL:** <https://discuss.elastic.co/t/update-mapping-causes-index-blocks-write-to-go-to-true/182049>\
**Category:** Elasticsearch\
**Created:** [May 21, 2019, 3:26pm UTC](https://discuss.elastic.co/t/update-mapping-causes-index-blocks-write-to-go-to-true/182049 "2019-05-21T15:26:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![KevSex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevsex/32/29031_2.png) [@KevSex](https://discuss.elastic.co/u/KevSex)\
**Post date:** [May 21, 2019, 3:26pm UTC](https://discuss.elastic.co/t/update-mapping-causes-index-blocks-write-to-go-to-true/182049/1 "2019-05-21T15:26:00Z")

</div>

At random times, I am seeing the cluster fail to index new documents. From logstash I am seeing the following:

```auto
[2019-05-21T09:53:02,716][INFO][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/8/index write (api)];"})
[2019-05-21T09:53:02,716][INFO][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/8/index write (api)];"})
[2019-05-21T09:53:02,716][INFO][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/8/index write (api)];"})
[2019-05-21T09:53:02,717][INFO][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/8/index write (api)];"})

```

The only log entries I can see from the Elasticsearch cluster nodes is the following which occurs at the same time:

```auto
[2019-05-21T09:53:02,383][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,421][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,425][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,464][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,467][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,518][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,530][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,572][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,581][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,585][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,622][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]
[2019-05-21T09:53:02,638][INFO][o.e.c.m.MetaDataMappingService] [node-03] [winlogbeat-6.7.0-2019.05.21/zu5BnzyfSzil6Z8pE5Cydg] update_mapping [doc]

```

Although the `FORBIDDEN` error seen usually shows when the cluster is low on disk space or JVM memory, they are fine with plenty of resources available (over 450GB available on 900GB cluster)

This appears to happen at random times and no explanation as to why. Even though only some indices are set to `true`, the full cluster is unable to be written to by Logstash.

I end up having to resolve this by manually setting the `index.blocks.write` to `false` on the affected indices.

Cluster size:  
3 nodes  
1021 Shards  
182 indices

Anyone seen any similar behaviour or know why this would be happening?

Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2019, 3:40pm UTC](https://discuss.elastic.co/t/update-mapping-causes-index-blocks-write-to-go-to-true/182049/2 "2019-06-18T15:40:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
