# How to export \`alerts\` as backup?

**URL:** <https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [January 21, 2021, 1:33am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715 "2021-01-21T01:33:06Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [January 21, 2021, 1:33am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/1 "2021-01-21T01:33:06Z")

</div>

Hi thanks for the lib! I am trying to monitor my server by using monitoring and alerting. When, for example, CPU is too high or memory is almost full, I want to send an email to myself. Thus I use Kibana Alerting (is it correct to use this?).

The problem is, how can I backup those alerts I created? I have tried to backup those "saved objects" but there seems no alerts.

Thanks!

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 21, 2021, 10:49am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/2 "2021-01-21T10:49:54Z")

</div>

Hi @fzyzcjy,

that functionality is still being worked on (see [https://github.com/elastic/kibana/issues/50266](https://github.com/elastic/kibana/issues/50266)). It's non-trivial because of the security implications of exporting the captured credentials.

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [January 25, 2021, 6:15am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/3 "2021-01-25T06:15:18Z")

</div>

Hmm thanks all the same!

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [January 30, 2021, 3:34am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/4 "2021-01-30T03:34:52Z")

</div>

Hi, how can I backup/restore those alerts currently? Thanks

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [February 3, 2021, 10:08am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/5 "2021-02-03T10:08:11Z")

</div>

Hi @fzyzcjy, I'm trying to find out if there is an option aside from backup up the `.kibana` system index directly.

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [February 6, 2021, 1:05am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/6 "2021-02-06T01:05:04Z")

</div>

Hi is there any updates? We know **backup** is very important, so I cannot let the elastic stack run without any backups!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 6, 2021, 2:06am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/7 "2021-02-06T02:06:15Z")

</div>

Hi @fzyzcjy just to be clear

With respect to Alerts

1. The Alerts **are backed up** as part of the normal snapshot and restore mechanism.

2. As @weltenwort said Import / Export of Alerts Saved Object is underway (working through security mechanism) . We do not have an ETA for that yet but it is a highly requested feature.

3. Also and API for directly Creating, Update, Deleting Retrieving alerts is also underway (nearly complete in Docs Stage). I do not have an exact ETA but that should be coming soon as well.

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [February 6, 2021, 2:31am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/8 "2021-02-06T02:31:26Z")

</div>

Sounds wonderful! However, I do not see the backuped alerts:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a3bbbd304a88b4d084401eafeff649c6e4ca45a1.png)

(the policy:)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c662c1c0eefbc1ac52b473c5d9cb1a665da649ef.png)

Am I missing something? Do I need to tune some configuration to backup? Or is it actually backuped (and just not shown?)

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 6, 2021, 2:51am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/9 "2021-02-06T02:51:39Z")

</div>

It appears that your current snapshot policies is only backing up 4 specific indices. Your snapshot policy is backing up a very limited set of indices and it does not appear it is backing up any of the system indices which may or may not be risky depending on your overall strategy. You will need to create a policy that backs up the kibana system indices at the very least, perhaps you should consider snapshot policy that covers all the system indices ... in general they tend to be small in comparison to data indices.

My snapshot policy is backing up everything 🙂

 ![Screen Shot 2021-02-05 at 6.44.31 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f611b6d12c49721af136d8a7e5dd93fbc1cd24d.png)

 ![Screen Shot 2021-02-05 at 6.47.36 PM](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1bf46fcdf8c2c0fd4c2dac2e1fee3155c710cecc.png)

Including the .kibana system indicies

 ![Screen Shot 2021-02-05 at 6.47.42 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/1/317f5142055aadde4c7b793bff16a0ae326adc1c.png)

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [February 6, 2021, 3:14am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/10 "2021-02-06T03:14:09Z")

</div>

Thanks very much! In my case, I should backup system index (though not done yet), and I want to backup those 4 indices shown above (post/user\_metadata/...), but I **do not** want to backup filebeat & metricbeat as they are too large. (By the way, is it a good or bad idea to backup filebeat/metricbeat data?)

Thus, should I select each and every one of those system indices **one by one** in this panel? Or is there any automatic way (like specifying an index pattern - which index pattern should I write down, maybe `.*` or something else?)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9cc986f15266aa26d951d344ce7882de34c5e3a.png)

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 6, 2021, 3:27am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/11 "2021-02-06T03:27:03Z")

</div>

See Here... so you should be able to use the `.*` syntax but I would run and test... 🙂

`indices`  
(Optional, string) A comma-separated list of data streams and indices to include in the snapshot. [Multi-index syntax](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/multi-index.html) is supported.

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [February 6, 2021, 3:49am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/12 "2021-02-06T03:49:22Z")

</div>

Thanks very much!

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [February 6, 2021, 3:58am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/13 "2021-02-06T03:58:02Z")

</div>

Hmm wait a bit... Some indices are quite huge!

Firstly, `.*` causes the following to be backup:

```auto
.apm-agent-configuration
.apm-custom-link
.async-search
.items-default-000001
.kibana-event-log-7.10.2-000001
.kibana-event-log-7.9.0-000001
.kibana-event-log-7.9.0-000002
.kibana-event-log-7.9.0-000003
.kibana_1
.kibana_2
.kibana_security_session_1
.kibana_task_manager_1
.kibana_task_manager_2
.lists-default-000001
.monitoring-beats-7-mb-2021.01.31
.monitoring-beats-7-mb-2021.02.01
.monitoring-beats-7-mb-2021.02.02
.monitoring-beats-7-mb-2021.02.03
.monitoring-beats-7-mb-2021.02.04
.monitoring-beats-7-mb-2021.02.05
.monitoring-beats-7-mb-2021.02.06
.monitoring-es-7-mb-2021.01.31
.monitoring-es-7-mb-2021.02.01
.monitoring-es-7-mb-2021.02.02
.monitoring-es-7-mb-2021.02.03
.monitoring-es-7-mb-2021.02.04
.monitoring-es-7-mb-2021.02.05
.monitoring-es-7-mb-2021.02.06
.monitoring-kibana-7-2021.01.31
.monitoring-kibana-7-2021.02.01
.monitoring-kibana-7-2021.02.02
.monitoring-kibana-7-2021.02.03
.monitoring-kibana-7-2021.02.04
.monitoring-kibana-7-2021.02.05
.monitoring-kibana-7-2021.02.06
.monitoring-kibana-7-mb-2021.01.31
.monitoring-kibana-7-mb-2021.02.01
.monitoring-kibana-7-mb-2021.02.02
.monitoring-kibana-7-mb-2021.02.03
.monitoring-kibana-7-mb-2021.02.04
.monitoring-kibana-7-mb-2021.02.05
.monitoring-kibana-7-mb-2021.02.06
.security-7
.siem-signals-default-000001
.slm-history-2-000001
.slm-history-3-000001
.transform-internal-005
.transform-notifications-000002

```

Secondly, some indices are huge:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f9934c711f286d3e9c4fe231127b7dcb2819bc84.png)

So I use this one instead:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73768f93f811870eeb309b1a49408fc09eafd050.png)

Result:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/d/9dba350a311a9c213e8109a916c14f4a006995a6.png)

Thanks for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2021, 3:58am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715/14 "2021-03-06T03:58:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
