# When I refresh field list, it fails because of 【blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];: \[cluster\_block\_exception\] blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];】

**URL:** <https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158>\
**Category:** Kibana\
**Created:** [February 13, 2019, 7:10am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158 "2019-02-13T07:10:59Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Orli](https://avatars.discourse-cdn.com/v4/letter/o/b3f665/32.png) [@Orli](https://discuss.elastic.co/u/Orli)\
**Post date:** [February 13, 2019, 7:10am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/1 "2019-02-13T07:10:59Z")

</div>

Hi,  
When I refreshed field list in Management --\> Kibana --\> Index Patterns, it failed because of 【blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];】. The detailed error information is as follows.  
\</\>  
Error: blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];  
at [http://xxx](http://xxx):xxx/bundles/commons.bundle.js:3:428829  
at processQueue ([http://xxx:5601/bundles/vendors.bundle.js:133:134252](http://xxx:5601/bundles/vendors.bundle.js:133:134252))  
at [http://xxx](http://xxx):xxx/bundles/vendors.bundle.js:133:135201  
at Scope.$digest ([http://xxx](http://xxx):xxx/bundles/vendors.bundle.js:133:146077)  
at Scope.$apply ([http://xxx](http://xxx):xxx/bundles/vendors.bundle.js:133:148856)  
at done ([http://xxx](http://xxx):xxx/bundles/vendors.bundle.js:133:101124)  
at completeRequest ([http://xxx](http://xxx):xxx/bundles/vendors.bundle.js:133:106024)  
at XMLHttpRequest.xhr.onload ([http://xxx](http://xxx):xxx/bundles/vendors.bundle.js:133:106783).  
\</\>

For solving the aboved issue, I executed the following API via Dev Tools.  
PUT /zipkin\*/\_settings  
{  
"index.blocks.read\_only\_allow\_delete": null  
}  
But this issue has been still existed. How can I solve this issue?

I set up Elasticsearch into 3 servers respectively. And Kibana was set up into one of 3 servers. The following is the disk space information in the server which set up Elasticsearch and Kibana.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/4/f43d8b089517a9e598c67ed9a4322f3b89399a1d.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 13, 2019, 7:17am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/2 "2019-02-13T07:17:50Z")

</div>

This often means that you are running out of disk space and that the data path assigned to Elasticsearch is over 95% full, which means that the [flood stage watermark](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/disk-allocator.html) has triggered and made all indices read-only.

---

<div class="post-metadata">

**Author:** ![Orli](https://avatars.discourse-cdn.com/v4/letter/o/b3f665/32.png) [@Orli](https://discuss.elastic.co/u/Orli)\
**Post date:** [February 13, 2019, 8:48am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/3 "2019-02-13T08:48:26Z")

</div>

I set up Elasticsearch into 3 servers respectively. And Kibana was set up into one of 3 servers. The data path assigned to Elasticsearch is 【/xxx/data】.

The following is the disk space information of the server under the folder 【/xxx/data】 of this server, which set up Elasticsearch and Kibana.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1ce3a7c7f921ada60ee6150dd87bd15b3d7830f9.png)  
The aboved picture demostrates that these is no over 95% full about the disk space. So how to solve my issue..?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 13, 2019, 9:09am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/4 "2019-02-13T09:09:09Z")

</div>

Is this the case on all 3 servers?

---

<div class="post-metadata">

**Author:** ![Orli](https://avatars.discourse-cdn.com/v4/letter/o/b3f665/32.png) [@Orli](https://discuss.elastic.co/u/Orli)\
**Post date:** [February 13, 2019, 9:22am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/5 "2019-02-13T09:22:56Z")

</div>

The version of Elasticsearch in 3 servers is 6.3.0.  
The data path assigned to Elasticsearch in 3 servers is respectively 【/xxx/data】.

The below is the disk space information of the 2nd server under the folder 【/xxx/data】 of the 2nd server, which set up the 2nd Elastichsearch.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/e/bed658d6ae6b2531e9eac3f09341a798f4ec182d.png)

The below is the disk space information of the 3rd server under the folder 【/xxx/data】 of the 3rd server, which set up the 3rd Elastichsearch.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/32da446d3aa68b90e8fe054c0b70d0892f1ee1d3.png)

---

<div class="post-metadata">

**Author:** ![Orli](https://avatars.discourse-cdn.com/v4/letter/o/b3f665/32.png) [@Orli](https://discuss.elastic.co/u/Orli)\
**Post date:** [February 14, 2019, 1:36am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/6 "2019-02-14T01:36:29Z")

</div>

I replied to you about 16 hours ago. Sorry for my hurry. Look forward to your soon reply.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 14, 2019, 6:21am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/7 "2019-02-14T06:21:19Z")

</div>

Is there anything in the logs that indicates what happened?

---

<div class="post-metadata">

**Author:** ![Orli](https://avatars.discourse-cdn.com/v4/letter/o/b3f665/32.png) [@Orli](https://discuss.elastic.co/u/Orli)\
**Post date:** [February 14, 2019, 6:38am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/8 "2019-02-14T06:38:12Z")

</div>

Where are the logs, which you pointed? Are they located in some folder which is pointed by 【path.logs】 in the elasticsearch.yml config file?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/4/14805061ca8cd26d1fd5a54e13c580a26dbb100d.png)

What are the log files names, which I should provide?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/25112802a599dd4d855b22122a5daedf70d5a7d7.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 14, 2019, 6:55am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/9 "2019-02-14T06:55:28Z")

</div>

I would recommend unblocking the indices as outlines in the documentation I linked to earlier. If they then go back to read-only status you should probably see something in the `my-elasticsearch.log` file on one of the hosts.

---

<div class="post-metadata">

**Author:** ![Orli](https://avatars.discourse-cdn.com/v4/letter/o/b3f665/32.png) [@Orli](https://discuss.elastic.co/u/Orli)\
**Post date:** [February 14, 2019, 7:34am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/10 "2019-02-14T07:34:06Z")

</div>

1. 

This is the log content in the my-elasticsearch.log in the 1st Elasticsearch server:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c5f79ef4313941ef64edb3dca693356cfa7ab391.png)

This is the log content in the my-elasticsearch.log in the 2nd Elasticsearch server:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1e81105b8ce2430f266ea8ab36153794208c592.png)

This is the log content in the my-elasticsearch.log in the 3rd Elasticsearch server:  
[2019-02-14T01:00:00,001][INFO][o.e.x.m.e.l.LocalExporter] cleaning up [2] old indices  
[2019-02-14T01:00:00,031][INFO][o.e.c.m.MetaDataDeleteIndexService] [node-3] [.monitoring-kibana-6-2019.02.06/4xwQZb8fTU69ZTrrIy4q1w] deleting index  
[2019-02-14T01:00:00,031][INFO][o.e.c.m.MetaDataDeleteIndexService] [node-3] [.monitoring-es-6-2019.02.06/Hfv2tQDZQWakhdQ1k5HQiQ] deleting index  
[2019-02-14T01:23:00,001][INFO][o.e.x.m.MlDailyMaintenanceService] triggering scheduled [ML] maintenance tasks  
[2019-02-14T01:23:00,002][INFO][o.e.x.m.a.TransportDeleteExpiredDataAction] [node-3] Deleting expired data  
[2019-02-14T01:23:00,009][INFO][o.e.x.m.a.TransportDeleteExpiredDataAction] [node-3] Completed deletion of expired data  
[2019-02-14T01:23:00,009][INFO][o.e.x.m.MlDailyMaintenanceService] Successfully completed [ML] maintenance tasks  
[2019-02-14T08:00:01,094][INFO][o.e.c.m.MetaDataCreateIndexService] [node-3] [.monitoring-es-6-2019.02.14] creating index, cause [auto(bulk api)], templates [.monitoring-es], shards [1]/[0], mappings [doc]  
[2019-02-14T08:00:01,144][INFO][o.e.c.m.MetaDataUpdateSettingsService] [node-3] updating number\_of\_replicas to [1] for indices [.monitoring-es-6-2019.02.14]  
[2019-02-14T08:00:01,152][INFO][o.e.c.m.MetaDataUpdateSettingsService] [node-3] [.monitoring-es-6-2019.02.14/28TgxEaoSwqJ7wLZ1he\_Bw] auto expanded replicas to [1]  
[2019-02-14T08:00:01,258][INFO][o.e.c.m.MetaDataCreateIndexService] [node-3] [idt7-sit-mcs-2019.02.14] creating index, cause [auto(bulk api)], templates , shards [5]/[1], mappings   
[2019-02-14T08:00:01,589][INFO][o.e.c.m.MetaDataMappingService] [node-3] [idt7-sit-mcs-2019.02.14/3a1otDYlSW-Ab81aHNe-mQ] create\_mapping [doc]  
[2019-02-14T08:00:01,659][INFO][o.e.c.m.MetaDataCreateIndexService] [node-3] [log-idt7-sit-msc-2019.02.14] creating index, cause [auto(bulk api)], templates [idt\_logs], shards [5]/[1], mappings [_default_]  
[2019-02-14T08:00:02,096][INFO][o.e.c.m.MetaDataMappingService] [node-3] [log-idt7-sit-msc-2019.02.14/57N99nsfR86sikjDNAvZTg] create\_mapping [doc]  
[2019-02-14T08:00:02,273][INFO][o.e.c.m.MetaDataCreateIndexService] [node-3] [idt7-mcs-2019.02.14] creating index, cause [auto(bulk api)], templates , shards [5]/[1], mappings   
[2019-02-14T08:00:02,540][INFO][o.e.c.m.MetaDataMappingService] [node-3] [idt7-mcs-2019.02.14/1QbKGdo8Sgm9h8pyYFScmQ] create\_mapping [doc]  
[2019-02-14T08:00:02,611][INFO][o.e.c.m.MetaDataCreateIndexService] [node-3] [log-idt7-msc-2019.02.14] creating index, cause [auto(bulk api)], templates [idt\_logs], shards [5]/[1], mappings [_default_]  
[2019-02-14T08:00:03,069][INFO][o.e.c.m.MetaDataMappingService] [node-3] [log-idt7-msc-2019.02.14/ljbejLbfQFqgY6pYHv6gOQ] create\_mapping [doc]  
[2019-02-14T08:00:03,620][INFO][o.e.c.r.a.AllocationService] [node-3] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[idt7-mcs-2019.02.14][2]] ...]).  
[2019-02-14T08:00:05,446][INFO][o.e.c.m.MetaDataCreateIndexService] [node-3] [.monitoring-kibana-6-2019.02.14] creating index, cause [auto(bulk api)], templates [.monitoring-kibana], shards [1]/[0], mappings [doc]  
[2019-02-14T08:00:05,510][INFO][o.e.c.m.MetaDataUpdateSettingsService] [node-3] updating number\_of\_replicas to [1] for indices [.monitoring-kibana-6-2019.02.14]  
[2019-02-14T08:00:05,523][INFO][o.e.c.m.MetaDataUpdateSettingsService] [node-3] [.monitoring-kibana-6-2019.02.14/HxpVMtmPR9e8BluU1K7b4A] auto expanded replicas to [1]  
[2019-02-14T08:00:06,244][INFO][o.e.c.r.a.AllocationService] [node-3] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[.monitoring-kibana-6-2019.02.14][0]] ...]).  
[2019-02-14T09:10:21,315][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T09:13:51,349][INFO][o.e.c.m.MetaDataCreateIndexService] [node-3] [zipkin:span-2019-02-14] creating index, cause [auto(bulk api)], templates [zipkin:span\_template], shards [5]/[1], mappings [_default_, span]  
[2019-02-14T09:13:51,623][INFO][o.e.c.m.MetaDataMappingService] [node-3] [zipkin:span-2019-02-14/YFEQZka\_QJOK7\_qdKTxBnA] update\_mapping [span]  
[2019-02-14T09:13:52,179][INFO][o.e.c.r.a.AllocationService] [node-3] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[zipkin:span-2019-02-14][4]] ...]).  
[2019-02-14T09:17:09,728][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T09:18:23,530][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T09:26:15,334][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T10:35:41,289][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T10:39:39,658][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T10:52:13,570][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T10:52:37,376][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T13:48:53,053][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]  
[2019-02-14T14:13:00,946][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-3] adding template [kibana\_index\_template:.kibana] for index patterns [.kibana]

After reading the above logs, how to do in the next step?

1. 

I set index.blocks.read\_only\_allow\_delete to false according to the "[https://www.elastic.co/guide/en/elasticsearch/reference/6.6/disk-allocator.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/disk-allocator.html)", which you recommended. However, it has no effect.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 14, 2019, 7:39am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/11 "2019-02-14T07:39:59Z")

</div>

Then I am not sure what is going on. You might need to wait for someone else to help out.

---

<div class="post-metadata">

**Author:** ![Orli](https://avatars.discourse-cdn.com/v4/letter/o/b3f665/32.png) [@Orli](https://discuss.elastic.co/u/Orli)\
**Post date:** [February 14, 2019, 7:48am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/12 "2019-02-14T07:48:16Z")

</div>

I am not sure whether someone else would appear or not. So may you continue thinking how to solve this issue?

---

<div class="post-metadata">

**Author:** ![Orli](https://avatars.discourse-cdn.com/v4/letter/o/b3f665/32.png) [@Orli](https://discuss.elastic.co/u/Orli)\
**Post date:** [February 14, 2019, 8:16am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/13 "2019-02-14T08:16:53Z")

</div>

I executed the following command, and then the issue was solved.  
PUT /\_all/\_settings  
{  
"index.blocks.read\_only\_allow\_delete": null  
}  
But I do not understand why the issue appears with the enough disk space.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2019, 8:16am UTC](https://discuss.elastic.co/t/when-i-refresh-field-list-it-fails-because-of-blocked-by-forbidden-12-index-read-only-allow-delete-api-cluster-block-exception-blocked-by-forbidden-12-index-read-only-allow-delete-api/168158/14 "2019-03-14T08:16:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
