# Query on Source only snapshot

**URL:** https://discuss.elastic.co/t/query-on-source-only-snapshot/242919
**Category:** Elasticsearch
**Created:** [July 28, 2020, 2:08pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919 "2020-07-28T14:08:31Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)
#### Post date: [July 28, 2020, 2:08pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/1 "2020-07-28T14:08:31Z")

</div>

Hello Team,

I am currently testing snapshot and restore process in elasticsearch. After restoring a source only snapshot from s3 , it is not showing any doc counts and storage size. do we need to do any thing here to start searching this indices for data. Please help

 ![indices-so](https://us1.discourse-cdn.com/elastic/original/3X/6/1/61008fee478b6a7690cc7940443c7be3f07c9e80.jpeg)

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 28, 2020, 8:10pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/2 "2020-07-28T20:10:03Z")

</div>

As detailed [in the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.8/snapshots-register-repository.html#snapshots-source-only-repository) you will need to reindex the data after you have restored the snapshot.

---

<div class="post-metadata">

### Author: ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)
#### Post date: [July 30, 2020, 10:12am UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/3 "2020-07-30T10:12:11Z")

</div>

Thanks Christian, i tried to reindex one of the index but it not creating a new index after reindex .

POST \_reindex  
{  
"source": {  
"index": "auditbeat-7.6.2-2020.07.22-000036"  
},  
"dest": {  
"index": "auditbeat-7.6.2-2020.07.22-restored",  
"version\_type": "external"

}  
}

# Output

{  
"took" : 0,  
"timed\_out" : false,  
"total" : 0,  
"updated" : 0,  
"created" : 0,  
"deleted" : 0,  
"batches" : 0,  
"version\_conflicts" : 0,  
"noops" : 0,  
"retries" : {  
"bulk" : 0,  
"search" : 0  
},  
"throttled\_millis" : 0,  
"requests\_per\_second" : -1.0,  
"throttled\_until\_millis" : 0,  
"failures" :   
}  
Please help

---

<div class="post-metadata">

### Author: ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)
#### Post date: [July 30, 2020, 10:29am UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/4 "2020-07-30T10:29:47Z")

</div>

@Christian_Dahlqvist - What does this part of the doc mean, i.e. how would you get the right mappints, or will the reindex pick this up automatically?

" The mapping of the restored index is empty, but the original mapping is available from the types top level `meta` element."

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 30, 2020, 12:06pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/5 "2020-07-30T12:06:48Z")

</div>

Am not sure what is wrong. Will need to leave that for someone else.

---

<div class="post-metadata">

### Author: ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)
#### Post date: [July 30, 2020, 1:19pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/6 "2020-07-30T13:19:48Z")

</div>

@jijo.john- Any stats for "auditbeat-7.6.2-2020.07.22-000036" ? Or it's status maybe not green or recovered, etc?

From /auditbeat-7.6.2-2020.07.22-000036/\_stats  
Also /auditbeat-7.6.2-2020.07.22-000036/\_settings

Have you tried without the `version_type``external`? Seems not relevant if no existing docs in the index.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 30, 2020, 1:30pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/7 "2020-07-30T13:30:15Z")

</div>

What were the mappings of the original index?

---

<div class="post-metadata">

### Author: ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)
#### Post date: [July 30, 2020, 1:34pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/8 "2020-07-30T13:34:07Z")

</div>

> [@Steve\_Mushero](#):
>
> From /auditbeat-7.6.2-2020.07.22-000036/\_sta

Hi Steve,

The index status is red , i restored it with 0 replica.

Please see the output below

{  
"\_shards" : {  
"total" : 1,  
"successful" : 0,  
"failed" : 0  
},  
"\_all" : {  
"primaries" : { },  
"total" : { }  
},  
"indices" : { }  
}

# Settings Output - trimmed fields due to limit

{  
"index-7.6.2-2020.07.22-000036" : {  
"settings" : {  
"index" : {  
"mapping" : {  
"total\_fields" : {  
"limit" : "10000"  
}  
},  
"source\_only" : "true",  
"refresh\_interval" : "5s",  
"blocks" : {  
"write" : "true"  
},  
"provided\_name" : "\<auditbeat-7.6.2-{now/d}-000036\>",  
"query" : {  
"default\_field" : [  
"message",  
"tags",  
"agent.ephemeral\_id",  
"agent.id",  
"agent.name",  
"system.audit.user.password.type",  
"fields.\*"  
]  
},  
"frozen" : "true",  
"creation\_date" : "1595391714148",  
"number\_of\_replicas" : "0",  
"uuid" : "0HWx4QMaSs6U5HSBVupQ9g",  
"version" : {  
"created" : "7060299"  
},  
"lifecycle" : {  
"name" : "auditbeat",  
"rollover\_alias" : "auditbeat-7.6.2",  
"indexing\_complete" : "true"  
},  
"codec" : "best\_compression",  
"routing" : {  
"allocation" : {  
"require" : {  
"box\_type" : "warm"  
}  
}  
},  
"search" : {  
"throttled" : "true"  
},  
"number\_of\_shards" : "1"  
}  
}  
}  
}

 ![indices-so_new](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e3ead2cf63492184a3514439ae8c730b848884cd.jpeg)

---

<div class="post-metadata">

### Author: ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)
#### Post date: [July 30, 2020, 1:42pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/9 "2020-07-30T13:42:15Z")

</div>

Okay but red is likely why this not work - it has no primary (replica = 0 has no effect and should make it green, as won't be looking for replicas).

You have allocation routing, too - for box warm - is that able to be satisfied here? Or else maybe you have no shards as they can't find a node that's warm.

Suggest get shard list/status for this index and an allocation explain on that shard to understand issue; might be obvious, but you have to fix this before it has any data to reindex, I think.

GET /\_cat/shards?v&h=n,index,shard,prirep,state,sto,sc,unassigned.reason,unassigned.details&s=sto,index

GET /\_cluster/allocation/explain  
{"index": "auditbeat-7.6.2-2020.07.22-000036", "shard": 0,  
"primary": true}

Why is this index frozen ? Is that part of source restore?

From what I read, the restored index is functional in that you can query the source data, etc. so I'd think should not be red, just read-only limited query; those aren't the same thing so something seems wrong but maybe someone who knows more about restores has info.

---

<div class="post-metadata">

### Author: ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)
#### Post date: [July 30, 2020, 1:57pm UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/10 "2020-07-30T13:57:04Z")

</div>

Please see the Output below

n index shard prirep state sto sc unassigned.reason unassigned.details  
index-7.6.2-2020.07.22-000036 0 p UNASSIGNED INDEX\_REOPENED  
index-7.6.2-2020.07.22-000036 0 r UNASSIGNED INDEX\_REOPENED  
index-7.6.2-2020.07.23-000037 0 p UNASSIGNED INDEX\_REOPENED  
index-7.6.2-2020.07.23-000037 0 r UNASSIGNED INDEX\_REOPENED  
index-7.6.2-2020.07.27-000039 0 p UNASSIGNED INDEX\_REOPENED  
index-7.6.2-2020.07.27-000039 0 r UNASSIGNED INDEX\_REOPENED

# Output for Cluster

{  
"index" : "index-7.6.2-2020.07.23-000037",  
"shard" : 0,  
"primary" : true,  
"current\_state" : "unassigned",  
"unassigned\_info" : {  
"reason" : "INDEX\_REOPENED",  
"at" : "2020-07-30T13:42:14.606Z",  
"last\_allocation\_status" : "no\_valid\_shard\_copy"  
},  
"can\_allocate" : "no\_valid\_shard\_copy",  
"allocate\_explanation" : "cannot allocate because a previous copy of the primary shard existed but can no longer be found on the nodes in the cluster",  
"node\_allocation\_decisions" : [  
{  
"node\_id" : "6Kc\_4PJcTyKUPeAzvKRUCQ",  
"node\_name" : "ibs-dc-siem-1",  
"transport\_address" : "10.186.10.176:9300",  
"node\_attributes" : {  
"ml.machine\_memory" : "33170718720",  
"xpack.installed" : "true",  
"ml.max\_open\_jobs" : "20"  
},  
"node\_decision" : "no",  
"store" : {  
"found" : false  
}  
},  
{  
"node\_id" : "O25dSwZSRaec8-cQh5Mfpg",  
"node\_name" : "ibs-dc-siem-backup",  
"transport\_address" : "10.186.10.12:9300",  
"node\_attributes" : {  
"xpack.installed" : "true",  
"box\_type" : "warm"  
},  
"node\_decision" : "no",  
"store" : {  
"found" : false  
}  
}  
]  
}

Index Freezing we enabled it as a part of roll over

---

<div class="post-metadata">

### Author: ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)
#### Post date: [July 31, 2020, 1:59am UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/11 "2020-07-31T01:59:22Z")

</div>

Well, this all seems weird - this index was restored, but has no shards? And any shard it had was lost, how is that possible? And it's frozen for rollover, even though it's a restored index you are working ?

All strange - I guess I'd try to restore it again and immediately see its status, shards, etc. Long time since I restored, so I'm not sure what to expect, but docs talk about how it's queryable for \_source and read-only, so I'd expect it to be green, just in limited duty until you reindex it.

---

<div class="post-metadata">

### Author: ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)
#### Post date: [August 11, 2020, 10:10am UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/12 "2020-08-11T10:10:33Z")

</div>

Thanks Steve for your support , i was away for few days , Let me delete all the backups and take a fresh backup for testing

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 8, 2020, 10:10am UTC](https://discuss.elastic.co/t/query-on-source-only-snapshot/242919/13 "2020-09-08T10:10:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
