# Elasticsearch 7.4.2 Snapshot and restore

**URL:** <https://discuss.elastic.co/t/elasticsearch-7-4-2-snapshot-and-restore/243928>\
**Category:** Elasticsearch\
**Created:** [August 5, 2020, 8:19pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-snapshot-and-restore/243928 "2020-08-05T20:19:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sanjay1](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@Sanjay1](https://discuss.elastic.co/u/Sanjay1)\
**Post date:** [August 5, 2020, 8:19pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-snapshot-and-restore/243928/1 "2020-08-05T20:19:42Z")

</div>

I am using Elasticsearch 7.4.2 and some clarification and help on snapshot and restore.  
There is nothing like full snapshot or partial snapshot. Each snapshot is a complete snapshot.

As I know each snapshot is incremental and it is point of time for index when snapshot taken.

**Regarding restore of an index (say kb-stest1):**

- Following is my snapshot history:

```auto
GET _cat/snapshots/es-ir?h=id,status,i,dur,i,`r

 snap-2020.07.02-7lhvlftarb2uq8jtc7uomw SUCCESS 23 36.2s
 snap-2020.07.02-dcqzttnrqles3btrgfs9sw SUCCESS 24 9.4s
 snap-2020.07.03-bnrozqossjiwtry6czg2qa SUCCESS 25 17s
 snap-2020.07.04-jin6qtmqtzgfsblzyhwqyg SUCCESS 28 18s
 snap-2020.07.05-yotsdhjwrdsb2mzswh4xeq SUCCESS 30 20s
 snap-2020.07.06-4sjkhullt72ft2fnvfaejg SUCCESS 32 15.6s
 snap-2020.07.07-ghnh9r3hsz-4tbml9rgxkw SUCCESS 34 25s
 snap-2020.07.08-5l1qrwfqskshosg8-a5efg SUCCESS 36 14s
 snap-2020.07.09-qsacncwbta6kuynhv_gtcw SUCCESS 34 13.8s
 snap-2020.07.10-cwxlit9xskmdoh3ljpcxng SUCCESS 35 10.6s
 full-snap-2020.07.10-5gd_xipgtd2lhctno_dfva SUCCESS 35 7.2s
 snap-2020.07.11-gplkmw7as3ev9gj9g2l7uw SUCCESS 34 6.4s
 full-snap-2020.07.11-m0h1rcs4r_szlpg4xi3fcw SUCCESS 34 5.8s
 snap-2020.07.12-sf8kzesqrkodzu_lxoldmw SUCCESS 34 9s
 full-snap-2020.07.12-roiwrk-lsys0gsz93wpreg SUCCESS 34 5.2s

```

- Index for the snapshot, say like to restore kb-stest1 index and in 3 snapshots mention below

```auto
 GET /_snapshot/es-ir/snap- 2020.07.02 -7lhvlftarb2uq8jtc7uomw
 contain index: kb-stest1-1591134776395
 GET /_snapshot/es-ir/snap-2020.07.14-mvnsbhfirbojhfo6lhdimq
 contain index: kb-stest1-1594676482430
 GET /_snapshot/es-ir/snap-2020.07.24-rak1t3dtty-tydputzuchg
 contain: kb-epsoneu-1594676482430

```

- Let us say need arise to restore **full** kb-stest1 index from snapshot created 2020-07-24 from the snapshot - snap-2020.07.24-rak1t3dtty-tydputzuchg, once we restore from the snapshot - snap-2020.07.24-rak1t3dtty-tydputzuchg is enough or we have to restore from the back snapshot (say snapshot of 2020-07-23, 22, 21....)as well.

---

<div class="post-metadata">

**Author:** ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)\
**Post date:** [August 10, 2020, 8:30am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-snapshot-and-restore/243928/2 "2020-08-10T08:30:58Z")

</div>

What is your question? Elasticsearch snaps are 'full' snapshots, data-wise, but actually are incremental on disk, because segments are immutable - but inside ES when you look at lists, they'll look full to you, and you can delete any you like and it'll still keep full snaps on disk. Very nice system.

Here is a recent blog I wrote on how it works:

> **[How Elasticsearch Snapshots Work](https://www.elkman.io/blog/how-elasticsearch-snapshots-work)**
>
> Elasticsearch is a powerful and dynamic distributed data system, and such things can be hard to backup, especially as they scale into the terabytes and beyond. Fortunately, the fol

---

<div class="post-metadata">

**Author:** ![Sanjay1](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@Sanjay1](https://discuss.elastic.co/u/Sanjay1)\
**Post date:** [August 11, 2020, 4:21pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-snapshot-and-restore/243928/3 "2020-08-11T16:21:52Z")

</div>

Thank you for reply Steve and link to blog.  
My question was as mention below my index kb-stest1-\<epoch\_time\> are in 3 snapshot.  
Like to restore **full** kb-stest1 index from snapshot created 2020-07-24 from the snapshot - snap-2020.07.24-rak1t3dtty-tydputzuchg, once we restore from the snapshot - snap-2020.07.24-rak1t3dtty-tydputzuchg is enough or worrey

```auto
GET /_snapshot/es-ir/snap- 2020.07.02 -7lhvlftarb2uq8jtc7uomw
 contain index: kb-stest1-1591134776395
 GET /_snapshot/es-ir/snap-2020.07.14-mvnsbhfirbojhfo6lhdimq
 contain index: kb-stest1-1594676482430
 GET /_snapshot/es-ir/snap-2020.07.24-rak1t3dtty-tydputzuchg
 contain: kb-epsoneu-1594676482430

```

---

<div class="post-metadata">

**Author:** ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)\
**Post date:** [August 12, 2020, 7:57am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-snapshot-and-restore/243928/4 "2020-08-12T07:57:44Z")

</div>

Not sure I understand but generally you restore from the latest snapshot - several may 'contain' the index, but at different points in time (assuming it's changing in that time; if not, then you don't care which).

---

<div class="post-metadata">

**Author:** ![Sanjay1](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@Sanjay1](https://discuss.elastic.co/u/Sanjay1)\
**Post date:** [August 13, 2020, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-snapshot-and-restore/243928/5 "2020-08-13T13:42:14Z")

</div>

Thank you, Steve.  
I understand clearly

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2020, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-snapshot-and-restore/243928/6 "2020-09-10T13:42:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
