# Daily Snapshot script question

**URL:** <https://discuss.elastic.co/t/daily-snapshot-script-question/108762>\
**Category:** Elasticsearch\
**Created:** [November 22, 2017, 4:51pm UTC](https://discuss.elastic.co/t/daily-snapshot-script-question/108762 "2017-11-22T16:51:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nsur1](https://avatars.discourse-cdn.com/v4/letter/n/2acd7d/32.png) [@nsur1](https://discuss.elastic.co/u/nsur1)\
**Post date:** [November 22, 2017, 4:51pm UTC](https://discuss.elastic.co/t/daily-snapshot-script-question/108762/1 "2017-11-22T16:51:54Z")

</div>

I have a snapshot repository in which I would like to have backups of my daily indices. I wanted to automate this process by creating a snapshot of the previous day's index daily.

My script thus far is:

```
yesterday="$(date -d "yesterday 13:00" '+%Y.%m.%d')"
curl -XPUT "http://localhost:9200/_snapshot/test_backup/$yesterday" -d '{
   "indices": "sflow-$yesterday",
   "ignore_unavailable": true,
   "include_global_state": false
}'

```

I guess this is more of a syntax question but when I run this, it creates a snapshot of no indices.

when I run this: curl -XGET "[http://localhost:9200/\_snapshot/test\_backup/$yesterday?pretty](http://localhost:9200/_snapshot/test_backup/%24yesterday?pretty)",  
I get this output:

```
{
"snapshots" : [
{
  "snapshot" : "2017.11.21",
  "uuid" : "am11Fd1hSauT5xzcnk215A",
  "version_id" : 5050199,
  "version" : "5.5.1",
  "indices" : [],
  "state" : "SUCCESS",
  "start_time" : "2017-11-22T16:43:44.353Z",
  "start_time_in_millis" : 1511369024353,
  "end_time" : "2017-11-22T16:43:44.357Z",
  "end_time_in_millis" : 1511369024357,
  "duration_in_millis" : 4,
  "failures" : [],
  "shards" : {
    "total" : 0,
    "failed" : 0,
    "successful" : 0
  }
}
]
}

```

You'll see that indices is []. When instead of using "indices": "sflow-$yesterday", I use "indices": "sflow-{actual date}", it works and starts the snapshot.

Why is that?

---

<div class="post-metadata">

**Author:** ![nsur1](https://avatars.discourse-cdn.com/v4/letter/n/2acd7d/32.png) [@nsur1](https://discuss.elastic.co/u/nsur1)\
**Post date:** [November 22, 2017, 5:13pm UTC](https://discuss.elastic.co/t/daily-snapshot-script-question/108762/2 "2017-11-22T17:13:30Z")

</div>

I ended up using the python elasticsearch client to accomplish this instead of using bash.

---

<div class="post-metadata">

**Author:** ![Maekee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maekee/32/21708_2.png) [@Maekee](https://discuss.elastic.co/u/Maekee)\
**Post date:** [November 22, 2017, 7:44pm UTC](https://discuss.elastic.co/t/daily-snapshot-script-question/108762/3 "2017-11-22T19:44:07Z")

</div>

When you take a full snapshot, doesnt elasticsearch take a snapshot and automatically know what indicies you have backed in the same repo, and therefore only backes up the changed/new data?

I have created a powershell function that i use, you can steal the api call from that:

> <https://github.com/maekee/Powershell/blob/master/ElasticSearch/Create-ESSnapshot.ps1>

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 22, 2017, 9:01pm UTC](https://discuss.elastic.co/t/daily-snapshot-script-question/108762/4 "2017-11-22T21:01:29Z")

</div>

Why not [Elasticsearch Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2017, 9:01pm UTC](https://discuss.elastic.co/t/daily-snapshot-script-question/108762/5 "2017-12-20T21:01:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
