# Data Path Change

**URL:** <https://discuss.elastic.co/t/data-path-change/317430>\
**Category:** Elasticsearch\
**Created:** [October 25, 2022, 5:18pm UTC](https://discuss.elastic.co/t/data-path-change/317430 "2022-10-25T17:18:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Safty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/safty/32/112921_2.png) [@Safty](https://discuss.elastic.co/u/Safty)\
**Post date:** [October 25, 2022, 5:18pm UTC](https://discuss.elastic.co/t/data-path-change/317430/1 "2022-10-25T17:18:27Z")

</div>

Hello,

I am interested in best practices for changing the default data and log path in the elasticsearch.yml file. I have found various references on the web about how this is done (a simple copy of the data as well as a snapshot restore to a new path) but it is unclear to me which is the recommended way from Elastic. Is there a definitive best practice on how to change the default data and log path?

Thank you.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2022, 12:20am UTC](https://discuss.elastic.co/t/data-path-change/317430/2 "2022-10-26T00:20:21Z")

</div>

Welcome to our community! 😃

There's not, no. As long as the node is shut down you can move it, then update the config and then restart.

---

<div class="post-metadata">

**Author:** ![Safty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/safty/32/112921_2.png) [@Safty](https://discuss.elastic.co/u/Safty)\
**Post date:** [October 26, 2022, 12:47am UTC](https://discuss.elastic.co/t/data-path-change/317430/3 "2022-10-26T00:47:14Z")

</div>

Hello,

Thank you for the response and the welcome!

So my plan of action will be the following based on my current understanding:

1. create new data storage location i.e. /foo/bar/log and /foo/bar/lib
2. chown elasticsearch:elasticsearch /foo/bar/log and /foo/bar/lib
3. shutdown the single node elasticsearch.service that I want to change the path on.
4. cp /var/lib/elasticsearch/ /foo/bar/
5. cp /var/logs/elasticsearch/ /foo/bar/
6. modify the elasticsearch.yml file and comment out the original path.logs and path.data items, create new path.logs and paths.log entries to the new locations listed above.
7. start the elasticsearch.service on the modified node.
8. validate cluster is 'green' and searching data is functioning as expected.
9. delete old data at old location at later time as needed/desired.

Is there anything else that I am missing from these order of operations or that I have missed completely?

Thank you.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2022, 1:02am UTC](https://discuss.elastic.co/t/data-path-change/317430/4 "2022-10-26T01:02:37Z")

</div>

Items 1 and 4+5 don't match and you're copying logs and data into `/foo/bar/`. Try `cp /var/lib/elasticsearch /foo/bar/data` and `cp /var/logs/elasticsearch /foor/bar/logs`, that way the names are clear.

I wouldn't be moving logs though to be honest, leave them in the system default location.

---

<div class="post-metadata">

**Author:** ![Safty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/safty/32/112921_2.png) [@Safty](https://discuss.elastic.co/u/Safty)\
**Post date:** [October 26, 2022, 4:19pm UTC](https://discuss.elastic.co/t/data-path-change/317430/5 "2022-10-26T16:19:13Z")

</div>

Understood. Thank you for the syntax error catch and recommendation.

In my case the data and logs are on an external NFS mounted storage device and that device is going away. So all data from the current nodes in the cluster needs to be 'migrated' to the new NFS storage system.

Beyond the cp example above, I am thinking that an array level migration of the data to the new storage system and then a modification of the underlying mount will be most efficient and clean. That will require a complete cluster shutdown upon cutover, but the paths and overall data structures will remain the same.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2022, 4:19pm UTC](https://discuss.elastic.co/t/data-path-change/317430/6 "2022-11-23T16:19:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
