# Failed to restore an incremental snapshot

**URL:** <https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657>\
**Category:** Elasticsearch\
**Tags:** snapshot-and-restore\
**Created:** [February 20, 2024, 8:38am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657 "2024-02-20T08:38:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![praval\_singhal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praval_singhal/32/131505_2.png) [@praval\_singhal](https://discuss.elastic.co/u/praval_singhal)\
**Post date:** [February 20, 2024, 8:38am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657/1 "2024-02-20T08:38:54Z")

</div>

I have been trying to restore an incremental snapshot for my ES cluster stored in azure storage account.

I am getting this error

{"error":{"root\_cause":[{"type":"snapshot\_restore\_exception","reason":"[elasticsearch\_snapshot:snapshot\_2-19-2024] snapshot does not  
exist"}],"type":"snapshot\_restore\_exception","reason":"[elasticsearch\_snapshot:snapshot\_2-19-2024] snapshot does not exist"},"status":500}

Both the source and destination ES cluster have the same storage account name and key properly configured. Also, Both clusters are running the same ES version 7.17.5.

We have verified all the indexes are in closed state and there are no failed indexes.

We have been successfully able to restore an initial snapshot {snapshot} and also an incremental snapshot {snapshot\_1-31-2024} but when we are again trying to restore another incremental snapshot {snapshot\_2-19-2024}, we are seeing issues.

I can see my snapshot in the response for list API on the source cluster

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a577276c0d449346c51a4f253a79170e6fd5303.png)

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 20, 2024, 8:55am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657/2 "2024-02-20T08:55:09Z")

</div>

I suspect you've not followed [these docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/snapshots-register-repository.html#snapshot-repo-considerations):

> Clusters should only register a particular snapshot repository bucket once. If you register the same snapshot repository with multiple clusters, only one cluster should have write access to the repository. **On other clusters, register the repository as read-only.**

---

<div class="post-metadata">

**Author:** ![praval\_singhal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praval_singhal/32/131505_2.png) [@praval\_singhal](https://discuss.elastic.co/u/praval_singhal)\
**Post date:** [February 20, 2024, 9:04am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657/3 "2024-02-20T09:04:29Z")

</div>

@DavidTurner We are doing write operations only from one cluster. Other cluster is just reading the snapshots.

Also, can we update this at this point of time when it is already registered and the cluster is running?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 20, 2024, 10:05am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657/4 "2024-02-20T10:05:10Z")

</div>

> [@praval\_singhal](#):
>
> We are doing write operations only from one cluster. Other cluster is just reading the snapshots.

That's good, but you must follow the docs and register the repository as read-only too.

> [@praval\_singhal](#):
>
> Also, can we update this at this point of time when it is already registered and the cluster is running?

Yes, if it's registered as read-only.

---

<div class="post-metadata">

**Author:** ![praval\_singhal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praval_singhal/32/131505_2.png) [@praval\_singhal](https://discuss.elastic.co/u/praval_singhal)\
**Post date:** [February 20, 2024, 10:11am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657/5 "2024-02-20T10:11:42Z")

</div>

@DavidTurner Currently for both the cluster, the repository setting is this

{  
"elasticsearch\_snapshot" : {  
"type" : "azure",  
"uuid" : "some string",  
"settings" : { }  
}  
}

Can I re-register with read-only setting as true on the restoring cluster?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 20, 2024, 10:31am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657/6 "2024-02-20T10:31:22Z")

</div>

Yes, remove that repository and add it back with `readonly: true` in the settings.

---

<div class="post-metadata">

**Author:** ![praval\_singhal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praval_singhal/32/131505_2.png) [@praval\_singhal](https://discuss.elastic.co/u/praval_singhal)\
**Post date:** [February 20, 2024, 11:42am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657/7 "2024-02-20T11:42:38Z")

</div>

Thanks. This worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2024, 11:43am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657/8 "2024-03-19T11:43:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
