# How can I restore logs from /usr/share/elasticsearch/data/nodes/0?

**URL:** <https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822>\
**Category:** Elasticsearch\
**Tags:** language-clients\
**Created:** [March 16, 2023, 8:16am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822 "2023-03-16T08:16:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![shawnmin](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Post date:** [March 16, 2023, 8:16am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822/1 "2023-03-16T08:16:08Z")

</div>

I am using Elasticsearch as a backend to save logs collected from Fluentd logging agent. Specifically, I've set up an EFK logging architecture in my Kubernetes cluster. (AWS EKS cluster to be specific)

I've mounted the container volume of Elasticsearch's /usr/share/elasticsearch/data into an EBS volume.

The question is: using this volume, is there a way to restore the logs? I've cd-ed into nodes/0/indices and saw bunch of folders and files in it -- but I couldn't figure out what they are. I've attached the capture of it.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78104233ac13ed41fef9e834384aa5f6d689f964.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 19, 2023, 9:25pm UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822/2 "2023-03-19T21:25:01Z")

</div>

Welcome to our community! 😃

Please don't post pictures of text, logs or code. They are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them.

> [@shawnmin](#):
>
> The question is: using this volume, is there a way to restore the logs?

I think it might be better to stop back and ask why you are doing this?

---

<div class="post-metadata">

**Author:** ![shawnmin](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Post date:** [March 20, 2023, 7:04am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822/3 "2023-03-20T07:04:06Z")

</div>

Okay I will not post pictures. Thanks for letting me know.

As mentioned above, I've set up an EFK logging architecture in my AWS EKS cluster for production usage.

For log retention strategy, I want old log data (say, 60-days old) to be automatically removed from the EBS volume (where Elasticsearch's container is mounted on).

But at the same time, as our client may request for log data that are older than our criterion (of 60-days), we are planning to take a snapshot of the EBS volume periodically, so that log data that are older than 60-days can also be restored from the snapshots taken before.

Given a snapshot of the EBS volume, then, I must be able to restore logs directly from it to meet my needs.

If there are other ways or better practices to restore logs, I am also willing to follow them.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 20, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822/4 "2023-03-20T07:27:16Z")

</div>

> [@shawnmin](#):
>
> planning to take a snapshot of the EBS volume periodically

Use the inbuilt Elasticsearch snapshot, no other approach is supported sorry.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 20, 2023, 7:37am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822/5 "2023-03-20T07:37:41Z")

</div>

> [@shawnmin](#):
>
> But at the same time, as our client may request for log data that are older than our criterion (of 60-days), we are planning to take a snapshot of the EBS volume periodically, so that log data that are older than 60-days can also be restored from the snapshots taken before.

That will as Mark said not work. Elasticsearch performs consistency checks on data on disk so in any way altering the data directory will make all the data invalid as consistency checks will fail.

The only way to snapshot data is through the [snapshot and restore APIs](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/snapshot-restore-apis.html), which allows you to back up data to S3 or a shared file system repository.

---

<div class="post-metadata">

**Author:** ![shawnmin](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Post date:** [March 20, 2023, 8:57am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822/6 "2023-03-20T08:57:07Z")

</div>

Thanks. I will take a look into the link you provided.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [March 20, 2023, 10:09am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822/7 "2023-03-20T10:09:19Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> That will as Mark said not work.

The [reference manual contains clear guidance on this topic](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/snapshot-restore.html#other-backup-methods):

> **Taking a snapshot is the only reliable and supported way to back up a cluster.** You cannot back up an Elasticsearch cluster by making copies of the data directories of its nodes. There are no supported methods to restore any data from a filesystem-level backup. If you try to restore a cluster from such a backup, it may fail with reports of corruption or missing files or other data inconsistencies, or it may appear to have succeeded having silently lost some of your data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2023, 10:10am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822/8 "2023-04-17T10:10:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
