# ES Snapshot Delete

**URL:** <https://discuss.elastic.co/t/es-snapshot-delete/243902>\
**Category:** Elasticsearch\
**Created:** [August 5, 2020, 4:12pm UTC](https://discuss.elastic.co/t/es-snapshot-delete/243902 "2020-08-05T16:12:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bhuvaneshdct](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhuvaneshdct/32/70081_2.png) [@bhuvaneshdct](https://discuss.elastic.co/u/bhuvaneshdct)\
**Post date:** [August 5, 2020, 4:12pm UTC](https://discuss.elastic.co/t/es-snapshot-delete/243902/1 "2020-08-05T16:12:56Z")

</div>

Elasticsearch backups are always incremental. Let's say I have a daily backup job. After one week I have 7 snapshots.

On the 8th day if Im going to delete the day1's snapshot, then the rest of the snapshots will become useless? (since they are smaller in size.

Or before deleting the unchanged data will push it to the next incremental backup and make it a complete backup?

Another doubt is, if I want to restore the day 3's backup then will it only restore the day 3's backup(I mean that incremental data only) ? or apply snapshots from day 1 to day 3?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 5, 2020, 4:20pm UTC](https://discuss.elastic.co/t/es-snapshot-delete/243902/2 "2020-08-05T16:20:24Z")

</div>

Each snapshot is a full snapshot of the data at that time but segments that have not changed since previous snapshot are not copied again which is what is often referred to as incremental (it is not in the traditional sense). You can delete any snapshot without compromising others. Any segments referred to by multiple snapshots will be kept until no longer needed.

---

<div class="post-metadata">

**Author:** ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)\
**Post date:** [August 6, 2020, 6:22am UTC](https://discuss.elastic.co/t/es-snapshot-delete/243902/3 "2020-08-06T06:22:24Z")

</div>

I recently wrote a blog on this this works, as I had the same questions; it's a VERY nice system (though you should prune to keep total # under control as it has to read all the metadata and can get slow on big systems):

> **[How Elasticsearch Snapshots Work](https://www.elkman.io/blog/how-elasticsearch-snapshots-work)**
>
> Elasticsearch is a powerful and dynamic distributed data system, and such things can be hard to backup, especially as they scale into the terabytes and beyond. Fortunately, the fol

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 6, 2020, 7:33am UTC](https://discuss.elastic.co/t/es-snapshot-delete/243902/4 "2020-08-06T07:33:47Z")

</div>

[This old blog post](https://www.elastic.co/blog/found-elasticsearch-snapshot-and-restore) also contains a quite good description of how it works.

---

<div class="post-metadata">

**Author:** ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)\
**Post date:** [August 6, 2020, 9:53am UTC](https://discuss.elastic.co/t/es-snapshot-delete/243902/5 "2020-08-06T09:53:10Z")

</div>

Ah, that is nice, and I will link to it, as I thought I looked far & wide before writing one. It's more low-level than I was shooting for, as I tried to balance high-level operations with a bit of detail, but staying out of file contents. But nice map in there of snaps to segments 🙂

Note the first image has a mistake in its caption which says "Indexes and their segments" but is actually of indices and their shards, as it only shows a single shard of each index, number 0 (as also shown in the later file list which is correct).

---

<div class="post-metadata">

**Author:** ![bhuvaneshdct](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhuvaneshdct/32/70081_2.png) [@bhuvaneshdct](https://discuss.elastic.co/u/bhuvaneshdct)\
**Post date:** [August 10, 2020, 3:37am UTC](https://discuss.elastic.co/t/es-snapshot-delete/243902/6 "2020-08-10T03:37:23Z")

</div>

Hey Steve,

Its a very nice blog, thanks and its useful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2020, 3:37am UTC](https://discuss.elastic.co/t/es-snapshot-delete/243902/7 "2020-09-07T03:37:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
