It's urgent, though i doubt about recovery but if you can help it will be great.
My ES cluster datanodes are under autoscaling group and while updating the stack we did a mistake. The result is, we had 8 data nodes out of which 4 got terminated. New nodes came up but now ES is RED because shards (450) are unassigned.
To start ELK i closed all indexes for which shards were unassigned but need to reproduce the data. Snapshot i tested but not yet implemented, so backup looks like not an option.
Here is some conf details:
ES Cluster: 1-master, 1-client,8-data node
Conf: 4-shards and 2-replicas
Size: 150GB (before incident)
Please let me know if you need more information.
Thanks & Regards,