In this blog, I am going to explain how we can take a snapshot of a single index or multiple indices to take the backup and how to restore the snapshot. We can not take the backup of Elasticsearch by just copying the data directories of all the nodes as Elasticsearch keeps on changing the contents of its data directories. So how to take the backup and how to restore it?
Elasticsearch provides a snapshot and restore API using which we can create the snapshot and can restore it. So to create the backup we need to do the following:
- We first need to identify the directory location where we want to store the snapshot files. Let's say I want to store it in "/var/tmp/backups" directory.
- We need to provide the directory access to Elasticsearch user so that Elasticsearch can write the snapshot files.
chown -R elasticsearch. /var/tmp/backups
- Now we need to tell Elasticsearch that this is our snapshot directory location. For that, we need to add the "repo.path" setting in elasticsearch.yml file.
- Here we are using the local file system directory for storing the snapshot but the same can be stored on the cloud as well. But in this blog, we will focus on file system based snapshot only.
- We first need to create the repository which would be used for taking a snapshot and to restore. We can create the repository using the following expression:
- After creating the repository we can take the snapshot of all indices using the following expression:
- If we want to take a snapshot of one or more index only then we can specify the index name in a comma-separated form, please refer to the below expression:
"indices": "index1, index2"
- If we want to see the snapshot details then we need to run the following expression:
Above expression provides us the snapshot details like version, list of indices, start time, end time, duration in milis etc.
- We can restore the snapshot by appending the _restore endpoint after the snapshot name.
We can test the restore process by first creating some indices, taking their snapshot, and then deleting those indices. After this, we can restore the snapshot to get the indices which we have deleted. I hope you can now create the snapshots and can restore them, in case of any query please leave your comment.
Other Blogs on Elastic Stack:
How to create Elasticsearch Cluster
Bucket Aggregation in Elasticsearch
Metrics Aggregation in Elasticsearch
Configure Logstash to push MySQL data into Elasticsearch
Wildcard and Boolean Search in Elasticsearch
Elasticsearch Rest API
Basics of Data Search in Elasticsearch
Elasticsearch Rest API
Log analysis with Elastic stack
Elasticsearch Installation and Configuration on Ubuntu 14.04
Introduction to Elasticsearch
If you found this article interesting, you can explore "Mastering Kibana 6.0", "Kibana 7 Quick Start Guide", and "Learning Kibana 7" to get more insight about Kibana and how we can configure ELK to create dashboards for key performance indicators
Author | Blogger | Tech Lead | Elastic Stack | Innovator |View Profile
Leave a comment
Oct 13, 2018, 8:49:59 PM | Anurag Srivastava
Feb 9, 2019, 12:06:18 PM | Anurag Srivastava
Mar 9, 2019, 8:20:38 AM | Anurag Srivastava
Apr 6, 2019, 8:41:41 PM | Anurag Srivastava
Apr 14, 2018, 1:18:05 PM | Anurag Srivastava
Jan 31, 2018, 6:11:29 AM | Anurag Srivastava
Feb 9, 2019, 6:34:22 PM | Anurag Srivastava
Jun 21, 2018, 4:58:11 AM | Anurag Srivastava
Jun 26, 2018, 4:50:18 PM | Anurag Srivastava
Jul 16, 2018, 5:00:02 PM | Anurag Srivastava
Jul 31, 2018, 6:16:42 PM | Anurag Srivastava
Jun 2, 2018, 10:49:54 AM | Anurag Srivastava
May 26, 2018, 6:42:02 PM | Anurag Srivastava
Aug 10, 2018, 7:14:40 PM | Anurag Srivastava