# AWS ElasticSearch - Manual Snapshot Archival

**URL:** <https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960>\
**Category:** Elasticsearch\
**Created:** [May 29, 2020, 5:25pm UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960 "2020-05-29T17:25:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![mehak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak/32/77348_2.png) [@mehak](https://discuss.elastic.co/u/mehak)\
**Post date:** [May 29, 2020, 5:25pm UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/1 "2020-05-29T17:25:18Z")

</div>

Hi Everyone,

I have a query regarding archival of ElasticSearch data. We are taking Manual snapshots of our ElasticSearch data after every 6 hours and it is getting stored in storage like S3. In our ElasticSearch, say we have 3 indexes and each index has a different retention policy, like 7 days, 14 days and 30 days respectively.

Now, we want to query the data as old as 6 months at some point of time, but since we have the retention policies in place, so how would we be able to query the old data if we are storing indexes only for few days.

Any inputs would be appreciated!

Thanks,  
Mehak

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 30, 2020, 3:05am UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/2 "2020-05-30T03:05:14Z")

</div>

I think you'd need to restore the snapshots.

In the future, searching in snapshots will be hopefully available. I'm not sure it will be possible to have that with the service you're using though.

BTW did you look at [https://www.elastic.co/cloud](https://www.elastic.co/cloud) and [https://aws.amazon.com/marketplace/pp/B01N6YCISK](https://aws.amazon.com/marketplace/pp/B01N6YCISK) ?

Cloud by elastic is one way to have access to all features, all managed by us. Think about what is there yet like Security, Monitoring, Reporting, SQL, Canvas, APM, Logs UI, Infra UI, SIEM, Maps UI, AppSearch and what is coming next 🙂 ...

---

<div class="post-metadata">

**Author:** ![mehak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak/32/77348_2.png) [@mehak](https://discuss.elastic.co/u/mehak)\
**Post date:** [May 31, 2020, 8:44pm UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/3 "2020-05-31T20:44:03Z")

</div>

@dadoonet, thanks for your inputs.

Since the snapshots are incremental, so for the index having retention policy of 7 days, the 8th day snapshot wouldn't contain the old data of 7 days but only the ones created on 8th day (if I'm not wrong). I am not sure how to handle the historical data of all the indexes then.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 1, 2020, 9:46am UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/4 "2020-06-01T09:46:04Z")

</div>

Don't consider snapshots as incremental backups. They are actually full backups even though only changes between the last run are actually backed up.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 1, 2020, 9:52am UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/5 "2020-06-01T09:52:35Z")

</div>

If you want to keep snapshots with indices you have deleted you may need to create time-based repositories instead of using a single cluster wide one.

---

<div class="post-metadata">

**Author:** ![mehak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak/32/77348_2.png) [@mehak](https://discuss.elastic.co/u/mehak)\
**Post date:** [June 1, 2020, 2:09pm UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/6 "2020-06-01T14:09:57Z")

</div>

Yes, right. Thank you.

---

<div class="post-metadata">

**Author:** ![mehak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak/32/77348_2.png) [@mehak](https://discuss.elastic.co/u/mehak)\
**Post date:** [June 1, 2020, 2:11pm UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/7 "2020-06-01T14:11:47Z")

</div>

@Christian_Dahlqvist , Alright, I will have a look at this approach. Thank you for your inputs.

---

<div class="post-metadata">

**Author:** ![mehak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak/32/77348_2.png) [@mehak](https://discuss.elastic.co/u/mehak)\
**Post date:** [June 3, 2020, 8:07pm UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/8 "2020-06-03T20:07:54Z")

</div>

So, we are preferring to query the data as per the retention policy of each index only for now. If in case we plan to change this scenario, we will be sending the snapshots stored in S3 to S3 Glacier (and later restore it) as per Lifecycle management policy to prevent storage cost and keep the historical data for as long as we might want.

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2020, 8:08pm UTC](https://discuss.elastic.co/t/aws-elasticsearch-manual-snapshot-archival/234960/9 "2020-07-01T20:08:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
