# Export data

**URL:** <https://discuss.elastic.co/t/export-data/219184>\
**Category:** Elasticsearch\
**Created:** [February 13, 2020, 10:23am UTC](https://discuss.elastic.co/t/export-data/219184 "2020-02-13T10:23:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jof300](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jof300](https://discuss.elastic.co/u/jof300)\
**Post date:** [February 13, 2020, 10:23am UTC](https://discuss.elastic.co/t/export-data/219184/1 "2020-02-13T10:23:51Z")

</div>

Hi,

We have a cluster of 7 nodes which is growing up fastly. We want to find a way to "archive" some logs that we must keep (legal inquiries) for several years.

I would like to know if there is a solution / command / way to export old data in a text format?  
I want to put those text files somewhere else.

Any other ideas / solution is also welcomed.

Regards

---

<div class="post-metadata">

**Author:** ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Post date:** [February 13, 2020, 10:29am UTC](https://discuss.elastic.co/t/export-data/219184/2 "2020-02-13T10:29:58Z")

</div>

Hi,

A frozen index has almost no overhead on the cluster (except for maintaining its metadata in memory) and is read-only. Read-only indices are blocked for write operations, such as docs-index\_ or force merges. That could be a solution

---

<div class="post-metadata">

**Author:** ![jof300](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jof300](https://discuss.elastic.co/u/jof300)\
**Post date:** [February 13, 2020, 10:40am UTC](https://discuss.elastic.co/t/export-data/219184/3 "2020-02-13T10:40:18Z")

</div>

Hi,

I can close / freeze indices but it will still take much space on data nodes.

I want to free up space but I have to keep some logs about 10 years.. With ILM, Idelete logs after X period of time ( 1 year for example)

Imo, export was one solution to gain space in data nodes.

Regards

---

<div class="post-metadata">

**Author:** ![jof300](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jof300](https://discuss.elastic.co/u/jof300)\
**Post date:** [February 17, 2020, 3:30pm UTC](https://discuss.elastic.co/t/export-data/219184/4 "2020-02-17T15:30:45Z")

</div>

any news ?

Regards

---

<div class="post-metadata">

**Author:** ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Post date:** [February 17, 2020, 4:08pm UTC](https://discuss.elastic.co/t/export-data/219184/5 "2020-02-17T16:08:53Z")

</div>

you can use logstash with elasticsearch as input with a your query and as output a file to which you can after archiving them wherever you want. (I imagine that these files can be reindexed).

```
input {
    elasticsearch {
        hosts => ["host:9200"]
        index => "index-we-are-reading-froml"
        query => '
        {"query": {
        .. 
        #Insert your Elasticsearch query here
                }
            }
            }
        }}'
    }

}
output {
    # see documentation
    file {
        path => ...
        codec => line { format => "custom format: %{message}"}
    }
}

```

I hope it will help you

---

<div class="post-metadata">

**Author:** ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Post date:** [February 17, 2020, 4:10pm UTC](https://discuss.elastic.co/t/export-data/219184/6 "2020-02-17T16:10:51Z")

</div>

see [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2020, 4:11pm UTC](https://discuss.elastic.co/t/export-data/219184/7 "2020-03-16T16:11:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
