# Kibana snapshot policy from 5 days and indexes from one year

**URL:** <https://discuss.elastic.co/t/kibana-snapshot-policy-from-5-days-and-indexes-from-one-year/381705>\
**Category:** Kibana\
**Tags:** slm-snapshot-lifecycle-management\
**Created:** [September 6, 2025, 8:19pm UTC](https://discuss.elastic.co/t/kibana-snapshot-policy-from-5-days-and-indexes-from-one-year/381705 "2025-09-06T20:19:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dominbdg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dominbdg/32/102457_2.png) [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Post date:** [September 6, 2025, 8:19pm UTC](https://discuss.elastic.co/t/kibana-snapshot-policy-from-5-days-and-indexes-from-one-year/381705/1 "2025-09-06T20:19:25Z")

</div>

Hello,

I defined snapshot policy (for test purposes) to create snapshots from 5 days but I would like to have also indexes from last 5 days. Instead of that I have indexes there from one year.

How can I define snapshot policy for indexes from last 5 days ?

Here is my script:

> PUT \_slm/policy/daily-snapshots  
> {  
> "schedule": "0 5 9 \* \* ?",  
> "name": "\<daily-snap-{now/d}\>",  
> "repository": "my\_repository",  
> "config":  
> {  
> "indices": "index-\*",  
> "include\_global\_state": true  
> },  
> "retention":  
> {  
> "expire\_after": "5d",  
> "min\_count": 1,  
> "max\_count": 5  
> }  
> }

by the way - I have a problem with understand min\_count and max\_count values.

Can someone explain it to me ?

Basically I need to have SLM for last 5 days and indexes from last 5 days also not all.

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [September 7, 2025, 3:03am UTC](https://discuss.elastic.co/t/kibana-snapshot-policy-from-5-days-and-indexes-from-one-year/381705/2 "2025-09-07T03:03:55Z")

</div>

Hello @dominbdg

As part of SLM i do not think we can only create a snapshot for last 5 days of indices.

In your cluster you are keeping 1 year of indices of type index-\* , so SLM will take backup of all index patterns.

Please find below documentation :

> **[Get policy information
 | Elasticsearch API documentation](https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-slm-get-lifecycle)**
>
> All methods and paths for this operation:
> GET
> /\_slm/policy
> 
> 
> GET
> /\_slm/policy/{policy\_id}
> Get snapshot li...

min\_count number :  
Minimum number of snapshots to retain, even if the snapshots have expired.

max\_count number :  
Maximum number of snapshots to retain, even if the snapshots have not yet expired. If the number of snapshots in the repository exceeds this limit, the policy retains the most recent snapshots and deletes older snapshots.

You might have to use an external script to extract indices of last 5 days & than pass that as part of indices parameter via API to take backup via SLM.

Thanks!!
