# How to monitor Elasticsearch snapshots

**URL:** <https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 19, 2020, 8:48pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037 "2020-11-19T20:48:34Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![mwise29](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@mwise29](https://discuss.elastic.co/u/mwise29)\
**Post date:** [November 19, 2020, 8:48pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/1 "2020-11-19T20:48:34Z")

</div>

I'd like advice on how to monitor snapshots. Is there a way to do it via a monitor? We'd only want the status of the last snapshot taken (report either success or failed).

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [November 19, 2020, 11:37pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/2 "2020-11-19T23:37:38Z")

</div>

> [@mwise29](#):
>
> snapshot

You can use the 'Get Snapshot Status API'

> **[Get snapshot status API | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/get-snapshot-status-api.html)**

---

<div class="post-metadata">

**Author:** ![mwise29](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@mwise29](https://discuss.elastic.co/u/mwise29)\
**Post date:** [November 20, 2020, 12:30am UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/3 "2020-11-20T00:30:55Z")

</div>

I want this to alert me via a monitor if the last snapshot fails. I won't know the snapshot name because we use SLM which appends the unique identifier. Wouldn't I need to know the snapshot name to get the details of the last snapshot with this command?

---

<div class="post-metadata">

**Author:** ![mwise29](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@mwise29](https://discuss.elastic.co/u/mwise29)\
**Post date:** [November 20, 2020, 12:42am UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/4 "2020-11-20T00:42:13Z")

</div>

The goal is to create an automated check that would run every X minutes to check the status of the last snapshot. It would then email me the status (success or fail).

---

<div class="post-metadata">

**Author:** ![mwise29](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@mwise29](https://discuss.elastic.co/u/mwise29)\
**Post date:** [November 20, 2020, 4:57pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/5 "2020-11-20T16:57:41Z")

</div>

Here's how I could do it if I knew the name of the snapshot (snapshot name is v780nightlysnap-2020.11.20-mrage5htsvihwjav6mca5w). The problem is I don't know of a way to get the name of the last snapshot.

```auto
{
  "trigger": {
    "schedule": {
      "interval": "30m"
    }
  },
  "input" : {
    "http" : {
      "request" : {
        "host" : "localhost",
        "port" : 9200,
        "path" : "_snapshot/<repo>/v780nightlysnap-2020.11.20-mrage5htsvihwjav6mca5w"
      }
    }
  },
  "actions": {
    "email_action": {
      "email": {
        "to": "XXXXXXXX@XXXXX.com",
        "subject": "Snapshot status",
        "body": "Snapshot status is {{ctx.payload.snapshots.0.state}}"
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [November 22, 2020, 10:31pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/6 "2020-11-22T22:31:42Z")

</div>

You can get all snapshots, either from a specific repository or from all repositories. And then filter for the last one/top one.

---

<div class="post-metadata">

**Author:** ![mwise29](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@mwise29](https://discuss.elastic.co/u/mwise29)\
**Post date:** [November 22, 2020, 11:17pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/7 "2020-11-22T23:17:32Z")

</div>

I haven't been able to figure out how to filter for just the last one. Do you have sample code for how to do that?

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [November 23, 2020, 1:16am UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/8 "2020-11-23T01:16:43Z")

</div>

Search for top hits.  
There are multiple examples out there.  
By the way, why you are not using an elastic query?

---

<div class="post-metadata">

**Author:** ![mwise29](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@mwise29](https://discuss.elastic.co/u/mwise29)\
**Post date:** [November 27, 2020, 1:48pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/9 "2020-11-27T13:48:06Z")

</div>

Thanks for the information. I'll check on the top hits. Out of curiosity how would I be able to do a query against the snapshot repository? I tried using \_search, but it comes up with no handler found for uri [/\_cat/snapshots//\_search] and method [GET]. Unfortunately I'm new to elasticsearch. I'm a database administrator that has recently also become the ElasticSearch admin for storage related tasks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 27, 2020, 2:05pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/10 "2020-11-27T14:05:29Z")

</div>

You can't for now. You need to restore first.  
It will be supported in the future with the frozen tier.

---

<div class="post-metadata">

**Author:** ![mwise29](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@mwise29](https://discuss.elastic.co/u/mwise29)\
**Post date:** [November 27, 2020, 2:33pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/11 "2020-11-27T14:33:25Z")

</div>

Thanks for the info. I guess I'll have to continue logging in on the weekends to make sure the last snapshot was successful and current.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 27, 2020, 5:55pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/12 "2020-11-27T17:55:47Z")

</div>

Not sure I understood the last part.

If you snapshot your index and have at the end a success status, you'll be all good.

---

<div class="post-metadata">

**Author:** ![mwise29](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@mwise29](https://discuss.elastic.co/u/mwise29)\
**Post date:** [November 27, 2020, 6:13pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/13 "2020-11-27T18:13:38Z")

</div>

We currently do a snapshot daily via SLM. What I'm trying to do is have some sort of automated daily process that sends me an e-mail with the status of the last snapshot and if it was current so I don't have to check it manually. This would be especially handy on weekends and holidays. Right now I login daily to check it.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 28, 2020, 4:53am UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/14 "2020-11-28T04:53:47Z")

</div>

I'd like to complete my previous answer by linking to this new feature in 7.10.

> **[Searchable snapshots | Elasticsearch Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/searchable-snapshots.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2020, 4:54am UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/256037/15 "2020-12-26T04:54:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
