I am currently in the process of trying to setup a backup strategy for our Elasticsearch cluster.
I understand there is backup/restore snapshot functionality available in Elasticsearch that can be used, however this would require pointing to a file share (AWS, Azure, local, etc) and I am trying to avoid using more storage if possible as this is only logging for a single platform.
My question therefore is would VM backups of the Elastic search cluster be able to be used for restore purposes in your opinion?
In other words if we keep VM backups and we need to look at logs for 4 months ago. Could we restore a single cluster node VM from that time period, re-IP it then connect Kibana to this cluster to view the logs?
I am trying to avoid using more storage if possible as the VMs themselves are backed up daily so we technically already have backups of the indices.