# Question on the backup snapshot

**URL:** <https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876>\
**Category:** Elasticsearch\
**Created:** [July 27, 2018, 5:58am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876 "2018-07-27T05:58:32Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ahrtr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahrtr/32/29551_2.png) [@ahrtr](https://discuss.elastic.co/u/ahrtr)\
**Post date:** [July 27, 2018, 5:58am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/1 "2018-07-27T05:58:32Z")

</div>

Based on the following guide, only the first snapshot is a complete copy of data, and all subsequent snapshots will save the delta between the existing snapshots and the new data.  
[https://www.elastic.co/guide/en/elasticsearch/guide/current/backing-up-your-cluster.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/backing-up-your-cluster.html)

I have a couple of questions as below,

1. If I create a snapshot daily, and there will be 365 snapshots a year later. Does it mean that only the first one is a complete one, and all other 364 are just incremental snapshots, and each is based on previous one? In that case, We can't purge any old snapshot.

2. Is it possible to forcely create a snapshot with a complete copy of data?

3. I used /\_snapshot/my\_backup/\_all to get all snapshots. I couldn't tell which one is a snapshot with a complete copy of data from the response. How can I know which one is a complete one? Thanks.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 27, 2018, 7:11am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/2 "2018-07-27T07:11:41Z")

</div>

> [@ahrtr](#):
>
> If I create a snapshot daily, and there will be 365 snapshots a year later. Does it mean that only the first one is a complete one, and all other 364 are just incremental snapshots, and each is based on previous one?

It's not quite that simple, but at a high level that's true.

> [@](#):
>
> In that case, We can't purge any old snapshot.

Per the guide you linked to, you can delete snapshots through the Elasticsearch API. You cannot delete them directly on the storage layer.

- [https://www.elastic.co/guide/en/elasticsearch/guide/6.3/backing-up-your-cluster.html#\_deleting\_snapshots](https://www.elastic.co/guide/en/elasticsearch/guide/6.3/backing-up-your-cluster.html#_deleting_snapshots)

> [@](#):
>
> Is it possible to forcely create a snapshot with a complete copy of data?

Each repository is independent, so if you create a brand new _repository_ then the first snapshot you save there will be a complete copy.

> [@ahrtr](#):
>
> I used /\_snapshot/my\_backup/\_all to get all snapshots. I couldn't tell which one is a snapshot with a complete copy of data from the response

Why do you care? If it's just for deletion purposes, then you just need to use the API to manage that.

---

<div class="post-metadata">

**Author:** ![ahrtr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahrtr/32/29551_2.png) [@ahrtr](https://discuss.elastic.co/u/ahrtr)\
**Post date:** [July 27, 2018, 7:55am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/3 "2018-07-27T07:55:28Z")

</div>

@TimV Thanks a lot for the quick response, which makes sense to me.

But I am still interested in how the snapshot deletion API works, because I need work out a plan to delete the old data. Can you please provide more detailed info (work flow or algorithm?) on the deletion API?

Another thing is that I have to use the storage service provided by our own cloud infrastructure, so I have to implement a new elasticsearch plugin to support our own storage service. Are there any online documents/guides?

Thanks!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 27, 2018, 8:02am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/4 "2018-07-27T08:02:02Z")

</div>

> [@ahrtr](#):
>
> But I am still interested in how the snapshot deletion API works, because I need work out a plan to delete the old data.

I don't understand. The delete API will delete the old data for you - you just need to decide when you aren't interested in keeping that snapshot any longer.  
If you delete a snapshot that is still sharing data with another (presumably newer) snapshot, then the shared data will not be deleted.

> [@ahrtr](#):
>
> I have to implement a new elasticsearch plugin to support our own storage service

I don't believe so, your best path will be to review & learn from the [official repository plugins](https://github.com/elastic/elasticsearch/tree/v6.3.2/plugins/) and then ask questions if you need more info.

---

<div class="post-metadata">

**Author:** ![ahrtr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahrtr/32/29551_2.png) [@ahrtr](https://discuss.elastic.co/u/ahrtr)\
**Post date:** [July 27, 2018, 8:33am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/5 "2018-07-27T08:33:24Z")

</div>

> [@TimV](#):
>
> I don't understand. The delete API will delete the old data for you - you just need to decide when you aren't interested in keeping that snapshot any longer.  
> If you delete a snapshot that is still sharing data with another (presumably newer) snapshot, then the shared data will not be deleted.

Let me ask this question another way. I just created a snapshot named "snapshot\_1", afterwards fed more data into elasticsearch cluster. Then I generated another snapshot named "snapshot\_2". It's for sure that the first snapshot "snapshot\_1" had a complete copy of data because it's the very first one. Regarding "snapshot\_2", it's most likely an incremental one based on snapshot\_1. At last, I deleted "snapshot\_1", and successfully. So I am a little confused why "snapshot\_1" could be deleted successfully, when it's (most likely) depended on by snapshot\_2? Does it mean that the snapshot\_1 was actually not deleted, even I got a successful resposne on deletion?

> [@TimV](#):
>
> I don't believe so, your best path will be to review & learn from the [official repository plugins](https://github.com/elastic/elasticsearch/tree/v6.3.2/plugins/) and then ask questions if you need more info.

It seems that elasticsearch only supports the following four repository types. But I need to use our own cloud storage service. So I ask for guides on how to implement a new elasticsearch plugin. Did I miss anything? Thanks!

> Shared filesystem, such as a NAS  
> Amazon S3  
> HDFS (Hadoop Distributed File System)  
> Azure Cloud

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 27, 2018, 8:36am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/6 "2018-07-27T08:36:26Z")

</div>

[This blog post](https://www.elastic.co/blog/found-elasticsearch-snapshot-and-restore) is old, but still explains the principles behind snapshot and restore quite well.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 27, 2018, 8:56am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/7 "2018-07-27T08:56:17Z")

</div>

> [@ahrtr](#):
>
> Does it mean that the snapshot\_1 was actually not deleted, even I got a successful resposne on deletion?

The snapshot was deleted. You cannot restore from that snapshot anymore. It may not have deleted all the files in use by that snapshot, but it doesn't claim to do so.

Note, snapshots are not incremental in the simplest sense of just writing deltas from the previous backup, they follow the underlying lucene segments, which means merge events on the underlying indices will be reflected in the snapshots.

> [@ahrtr](#):
>
> So I ask for guides on how to implement a new elasticsearch plugin.

And my answer was that we don't have docs for that, and your best option is to look at the code for the existing plugins, and use that to guide you.

---

<div class="post-metadata">

**Author:** ![ahrtr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahrtr/32/29551_2.png) [@ahrtr](https://discuss.elastic.co/u/ahrtr)\
**Post date:** [July 27, 2018, 9:07am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/8 "2018-07-27T09:07:58Z")

</div>

@Christian_Dahlqvist @TimV Thanks both of you for the helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2018, 9:08am UTC](https://discuss.elastic.co/t/question-on-the-backup-snapshot/141876/9 "2018-08-24T09:08:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
