Hello,
Someone in our team created new indexes in elasticsearch and we started to see an error in the logstash and since that day we no longer see alerts in kibana.
Will they have any idea of the problem?
Eliminating the indices could be solved?
Or do you have some record of a similar problem reported?
The error in logstash is as follows
[2018-11-22T17:13:52,271][INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})
[2018-11-22T17:13:52,271][INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})
[2018-11-22T17:13:52,271][INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})
[2018-11-22T17:13:52,271][INFO ][logstash.outputs.elasticsearch] Retrying individual bulk actions that failed or were rejected by the previous bulk request. {:count=>125}
New indices in elasticsearch