# Advice on snapshot and restore setup for elasticsearch DR scenario

**URL:** <https://discuss.elastic.co/t/advice-on-snapshot-and-restore-setup-for-elasticsearch-dr-scenario/385873>\
**Category:** Elasticsearch\
**Tags:** snapshot-and-restore\
**Created:** [April 13, 2026, 3:13pm UTC](https://discuss.elastic.co/t/advice-on-snapshot-and-restore-setup-for-elasticsearch-dr-scenario/385873 "2026-04-13T15:13:32Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![fffasttFGHb3t](https://avatars.discourse-cdn.com/v4/letter/f/71c47a/32.png) [@fffasttFGHb3t](https://discuss.elastic.co/u/fffasttFGHb3t)\
**Post date:** [April 13, 2026, 3:13pm UTC](https://discuss.elastic.co/t/advice-on-snapshot-and-restore-setup-for-elasticsearch-dr-scenario/385873/1 "2026-04-13T15:13:32Z")

</div>

We currently have an elasticsearch cluster deployed on-prem kubernetes with the elastic operator.

Our main goals are exactly as described in the [documentation](https://www.elastic.co/docs/deploy-manage/tools/snapshot-and-restore):

- Regularly back up a cluster with no downtime
- Recover data after deletion or a hardware failure

I have a few questions I am struggling to find the answers to and wonder if the community can help me out:

1. What control do I have over what is included in the snapshot - how granular does it get? - ex. I have 1 week index retention/lifecycle in my cluster, can I take daily snapshots which only include shards for yesterday/last 24hr OR every snapshot includes all indexes and all shards?
2. Similarly to 1), what control do I have over what can be restored - for example if I have lost/deleted a single shard/index - can I only restore that shard/index or do I have to perform a whole cluster restore?
3. After a hardware failure where all elasticsearch nodes and data has been lost - how does the recovery process look like - redeploy the cluster to kubernetes again, and restore the latest snapshot on top of it?
4. If 1) is achievable and we do take snapshots of a days’ shards - how do I restore a whole cluster after hardware failure - can I only use the latest snapshot or can multiple snapshots be restored (ex. last 5 days’ worth of snaps)?

Any other ideas around preparing for DR / better approaches are welcome as well - thanks !

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [April 13, 2026, 6:55pm UTC](https://discuss.elastic.co/t/advice-on-snapshot-and-restore-setup-for-elasticsearch-dr-scenario/385873/2 "2026-04-13T18:55:09Z")

</div>

> [@fffasttFGHb3t](#):
>
> how granular does it get?

You can specify which indices should be included. But generally that’s a bad idea. Snapshots are deduplicated so it’s usually best to include everything - things that haven’t changed won’t cost you any extra storage.

> [@fffasttFGHb3t](#):
>
> what control do I have over what can be restored

Likewise, you can specify the indices to restore. Restoring one shard out of a multi-shard index doesn’t really make sense and is not supported.

> [@fffasttFGHb3t](#):
>
> how does the recovery process look like - redeploy the cluster to kubernetes again, and restore the latest snapshot on top of it?

Sounds about right.

> [@fffasttFGHb3t](#):
>
> can I only use the latest snapshot or can multiple snapshots be restored (ex. last 5 days’ worth of snaps)?

You can restore multiple snapshots. But that’s just making life hard for yourself. Take full snapshots and rely on deduplication for the storage savings instead.
