Elasticsearch Error: Cluster_Block_Exception [Forbidden/12/Index Read-Only / Allow Delete (Api)], Flood Stage Disk Watermark Exceeded
When Trying to Post Documents to Elasticsearch as Normal I'm Getting This Error: Cluster_Block_Exception [Forbidden/12/Index Read-Only / Allow Delete (Api)]; I...
When trying to post documents to Elasticsearch as normal I'm getting this error:
cluster_block_exception [FORBIDDEN/12/index read-only / allow delete (api)];
I also see this message on the Elasticsearch logs:
flood stage disk watermark [95%] exceeded ... all indices on this node will marked read-only
7 Answers
This happens when Elasticsearch thinks the disk is running low on space so it puts itself into read-only mode.
By default Elasticsearch's decision is based on the percentage of disk space that's free, so on big disks this can happen even if you have many gigabytes of free space.
The flood stage watermark is 95% by default, so on a 1TB drive you need at least 50GB of free space or Elasticsearch will put itself into read-only mode.
For docs about the flood stage watermark see .
The right solution depends on the context - for example a production environment vs a development environment.
Must Read
Solution 1: free up disk space
Freeing up enough disk space so that more than 5% of the disk is free will solve this problem. Elasticsearch won't automatically take itself out of read-only mode once enough disk is free though, you'll have to do something like this to unlock the indices:
$ curl -XPUT -H "Content-Type: application/json" -d '{"index.blocks.read_only_allow_delete": null}'