# How to prooceed with a data node with corrupt disk file system

**URL:** <https://discuss.elastic.co/t/how-to-prooceed-with-a-data-node-with-corrupt-disk-file-system/303503>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [April 28, 2022, 10:51am UTC](https://discuss.elastic.co/t/how-to-prooceed-with-a-data-node-with-corrupt-disk-file-system/303503 "2022-04-28T10:51:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elaskibuser](https://avatars.discourse-cdn.com/v4/letter/e/e19b73/32.png) [@elaskibuser](https://discuss.elastic.co/u/elaskibuser)\
**Post date:** [April 28, 2022, 10:51am UTC](https://discuss.elastic.co/t/how-to-prooceed-with-a-data-node-with-corrupt-disk-file-system/303503/1 "2022-04-28T10:51:06Z")

</div>

I would really appreciate help on the correct course of action. The setup is 3 ELK nodes which have all roles.  
No shard replication is done. Node 2 experienced a failure on the disk which contains the data folder. An old copy (about a month) of that folder exists, and I know it would not be sufficient to copy the data in.

My question is, what is the correct course of action at this point which would return the stack to normal operation mode:

1. install a new disk and just launch the node? By a strike of luck, that was our least important data.
2. install the new disk and copy the old data and see if it can recover that data?

Also, would doing option 1, while launching an experimental node on which the data folder is mounted and restore whichever recoverable data and re-index them remotely to the original cluster?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 29, 2022, 12:58am UTC](https://discuss.elastic.co/t/how-to-prooceed-with-a-data-node-with-corrupt-disk-file-system/303503/2 "2022-04-29T00:58:29Z")

</div>

Option 2 will work, but you will lose the data. You can try 1, I've seen it work, but it's not guaranteed.

> [@elaskibuser](#):
>
> An old copy (about a month) of that folder exists

You are best off using snapshot and restore here.

---

<div class="post-metadata">

**Author:** ![elaskibuser](https://avatars.discourse-cdn.com/v4/letter/e/e19b73/32.png) [@elaskibuser](https://discuss.elastic.co/u/elaskibuser)\
**Post date:** [May 3, 2022, 9:57am UTC](https://discuss.elastic.co/t/how-to-prooceed-with-a-data-node-with-corrupt-disk-file-system/303503/3 "2022-05-03T09:57:32Z")

</div>

Thank you for the reply warkolm!

Just to make sure I understood that correctly because I suspect you might flipped the numbers.

You have a birthday cake next to your name! happy birthday!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 3, 2022, 10:32am UTC](https://discuss.elastic.co/t/how-to-prooceed-with-a-data-node-with-corrupt-disk-file-system/303503/4 "2022-05-03T10:32:50Z")

</div>

Yes, they are the wrong way around sorry.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2022, 10:33am UTC](https://discuss.elastic.co/t/how-to-prooceed-with-a-data-node-with-corrupt-disk-file-system/303503/5 "2022-05-31T10:33:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
