# Does Snapshot/Restore to a different target cluster retain system indices?

**URL:** <https://discuss.elastic.co/t/does-snapshot-restore-to-a-different-target-cluster-retain-system-indices/115775>\
**Category:** Elasticsearch\
**Created:** [January 16, 2018, 6:58pm UTC](https://discuss.elastic.co/t/does-snapshot-restore-to-a-different-target-cluster-retain-system-indices/115775 "2018-01-16T18:58:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Senor](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@Senor](https://discuss.elastic.co/u/Senor)\
**Post date:** [January 16, 2018, 6:58pm UTC](https://discuss.elastic.co/t/does-snapshot-restore-to-a-different-target-cluster-retain-system-indices/115775/1 "2018-01-16T18:58:47Z")

</div>

As the title states, if I were to perform a snapshot on one cluster and restore it to another target cluster, will it retain the .\* system indices? In particular, `.security`, `.kibana`, `.monitoring`, `.watcher-history` and so forth.

If a full snapshot does do this, is there a way to exclude these without explicitly specifying all the other indices in our cluster? We have 3,000+ indices so it's not logical to necessarily specify each of them in order to exclude the rest.

---

<div class="post-metadata">

**Author:** ![Arvind\_Rao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arvind_rao/32/26758_2.png) [@Arvind\_Rao](https://discuss.elastic.co/u/Arvind_Rao)\
**Post date:** [January 18, 2018, 9:39am UTC](https://discuss.elastic.co/t/does-snapshot-restore-to-a-different-target-cluster-retain-system-indices/115775/2 "2018-01-18T09:39:39Z")

</div>

A snapshot by default includes all open and started indices so yes it would include the .\* indices unless you specify otherwise.

A useful way to exclude a small set of indices, rather than including a large set of indices, is to use the "-" operator ([multi index syntax](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-index.html)), as follows:

Everything except .security, .kibana, .monitoring and .watcher-history

```auto
PUT _snapshot/<repository_name>/<snapshot_name>
{
  "indices": "*,-.security,-.kibana,-.monitoring,-.watcher-history",
  "ignore_unavailable": true,
  "include_global_state": true
}

```

Or, everything except indices that start with "."

```auto
PUT _snapshot/<repository_name>/<snapshot_name>
{
  "indices": "*,-.*",
  "ignore_unavailable": true,
  "include_global_state": true
}

```

Same goes for the restore API.

---

<div class="post-metadata">

**Author:** ![Senor](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@Senor](https://discuss.elastic.co/u/Senor)\
**Post date:** [January 18, 2018, 7:46pm UTC](https://discuss.elastic.co/t/does-snapshot-restore-to-a-different-target-cluster-retain-system-indices/115775/3 "2018-01-18T19:46:30Z")

</div>

Perfect, that was precisely what I was looking for! I wasn't familiar with the exclude ("-") operator, so thank you kindly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2018, 7:46pm UTC](https://discuss.elastic.co/t/does-snapshot-restore-to-a-different-target-cluster-retain-system-indices/115775/4 "2018-02-15T19:46:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
