# Need guide for data retension/archiving

**URL:** <https://discuss.elastic.co/t/need-guide-for-data-retension-archiving/64806>\
**Category:** Elasticsearch\
**Created:** [November 3, 2016, 6:58am UTC](https://discuss.elastic.co/t/need-guide-for-data-retension-archiving/64806 "2016-11-03T06:58:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eugene\_Gwon](https://avatars.discourse-cdn.com/v4/letter/e/6a8cbe/32.png) [@Eugene\_Gwon](https://discuss.elastic.co/u/Eugene_Gwon)\
**Post date:** [November 3, 2016, 6:58am UTC](https://discuss.elastic.co/t/need-guide-for-data-retension-archiving/64806/1 "2016-11-03T06:58:58Z")

</div>

Hello all,  
I'm using ES 1.7.4 with Graylog. this system stores almost 200GB of data per month.  
After several months of test and live-use, I realize that I don't need more than 2 or 3 months of data on ES. so I decided to delete old data.  
but who knows? there's always unexpected situation.

After some searches, I found that I can simply 'close' indices. and It seems more safe than delete, but It uses disk spaces... ☹

Is there any guide for data retension or archiving?

Thanks for any help.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 3, 2016, 7:08am UTC](https://discuss.elastic.co/t/need-guide-for-data-retension-archiving/64806/2 "2016-11-03T07:08:26Z")

</div>

I would recommend using the [snapshot and restore functionality in Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/1.7/modules-snapshots.html#_monitoring_snapshot_restore_progress) to backup older indices to some form of shared storage. This frees up space on the node and allows you to restore the data back if necessary.

---

<div class="post-metadata">

**Author:** ![Eugene\_Gwon](https://avatars.discourse-cdn.com/v4/letter/e/6a8cbe/32.png) [@Eugene\_Gwon](https://discuss.elastic.co/u/Eugene_Gwon)\
**Post date:** [November 3, 2016, 9:43am UTC](https://discuss.elastic.co/t/need-guide-for-data-retension-archiving/64806/3 "2016-11-03T09:43:17Z")

</div>

Thanks for response. I'll try it 🙂

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [November 3, 2016, 1:45pm UTC](https://discuss.elastic.co/t/need-guide-for-data-retension-archiving/64806/4 "2016-11-03T13:45:46Z")

</div>

So snapshot/restore isn't really a great archiving solution because Elasticsearch can only restore snapshots from the last major version. We don't have a better archiving solution built in though.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:06pm UTC](https://discuss.elastic.co/t/need-guide-for-data-retension-archiving/64806/5 "2017-07-05T22:06:55Z")

</div>


