# Restoring snapshot (filesystem) - empty

**URL:** <https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987>\
**Category:** Elasticsearch\
**Tags:** snapshot-and-restore\
**Created:** [January 9, 2025, 10:44am UTC](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987 "2025-01-09T10:44:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![e-lastic](https://avatars.discourse-cdn.com/v4/letter/e/cab0a1/32.png) [@e-lastic](https://discuss.elastic.co/u/e-lastic)\
**Post date:** [January 9, 2025, 10:44am UTC](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987/1 "2025-01-09T10:44:48Z")

</div>

Hi,  
TL;DR;  
Tried to restore a snapshot I did before re-installing the machine but ended up with elasticsearch complaining the snapshot is "empty"

What happened:  
I had to set up a machine from scratch (single instance ELK installation, no cluster running under Ubuntu). So I created a snapshot, tar-ed the resulting directory and put it in a safe place on another machine. After setting up the machine (OS, ELK 8.17.0) I wanted to restore the snapshot only to find out that elasticsearch.

I "tar xpf"-ed the snapshot tar (~31GB) I created on the "old" installation (also Ubuntu), made sure it's owned by the elasticsearch-user:

```auto
drwxr-xr-x 3 elasticsearch elasticsearch 4096 Nov 14 12:23 Zappy-snapshot-Repo

```

Next I added the path the directory is in to `/etc/elasticsearch/elasticsearch.yml`, i.e.

```auto
path.repo: /tmp/Zappy-snapshot-Repo

```

Next I went to kibana and added the Repo. No errors here, but I got a message that the Repo has no snapshots:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a04b656805c1680126bde478a428d2870708757c.png)

Same in the developer console

```auto
GET _snapshot/ 

```

gives

```auto
{
  "My-Test-Repo": {
    "type": "fs",
    "settings": {
      "location": "/tmp/Zappy-snapshot-Repo"
    }
  }
}

```

but

```auto
GET _snapshot/_status

```

gives

```auto
{
  "snapshots": []
}

```

i.e. "empty" 🤔

No error messages whatsoever in /var/log/elasticsearch/elasticsearch.log

Also tried with debuging, i.e.

```auto
PUT _cluster/settings
{
  "transient": {
    "logger.org.elasticsearch.snapshots": "DEBUG"
  }
} 

```

Still no useful information in elasticsearch.log.

Any ideas what could be wrong, i.e. why I can't re-import the snapshot?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 9, 2025, 12:55pm UTC](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987/2 "2025-01-09T12:55:57Z")

</div>

What do you have inside of `/tmp/Zappy-snapshot-Repo`?

Please run a `ls` on that path and share the results.

---

<div class="post-metadata">

**Author:** ![e-lastic](https://avatars.discourse-cdn.com/v4/letter/e/cab0a1/32.png) [@e-lastic](https://discuss.elastic.co/u/e-lastic)\
**Post date:** [January 9, 2025, 3:41pm UTC](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987/3 "2025-01-09T15:41:36Z")

</div>

Here we go:

```auto
/tmp/Zappy-snapshot-Repo# ls -la
total 204
drwxr-xr-x 3 elasticsearch elasticsearch 4096 Nov 14 12:23 .
drwxrwxrwt 17 root root 4096 Jan 9 15:30 ..
-rw-r--r-- 1 elasticsearch elasticsearch 40680 Nov 14 12:23 index-0
-rw-r--r-- 1 elasticsearch elasticsearch 8 Nov 14 12:23 index.latest
drwxr-xr-x 149 elasticsearch elasticsearch 12288 Nov 14 12:14 indices
-rw-r--r-- 1 elasticsearch elasticsearch 135746 Nov 14 12:23 meta-6bs6VgeaQ7-StvlUpmov1g.dat
-rw-r--r-- 1 elasticsearch elasticsearch 3224 Nov 14 12:23 snap-6bs6VgeaQ7-StvlUpmov1g.dat
/tmp/Zappy-snapshot-Repo#

```

so it's owned by "elasticsearch:elasticsearch" with the exact same permissions as the original (tar-ed via "tar cf" and extracted with "tar xpf")

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 9, 2025, 3:58pm UTC](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987/4 "2025-01-09T15:58:00Z")

</div>

What happens when you click in _Verify Repository_ ?

From the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/snapshots-register-repository.html#snapshots-repository-backup), it suggests that you need to Verify the repository before starting to use it.

---

<div class="post-metadata">

**Author:** ![e-lastic](https://avatars.discourse-cdn.com/v4/letter/e/cab0a1/32.png) [@e-lastic](https://discuss.elastic.co/u/e-lastic)\
**Post date:** [January 11, 2025, 7:27pm UTC](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987/5 "2025-01-11T19:27:00Z")

</div>

> [@leandrojmp](#):
>
> What happens when you click in _Verify Repository_ ?

No complaints, just the message that the repo has no snapshots.

In the meantime though thanks to a tip from one of my colleagues I could fix the problem: I originally put the directory containing the snapshot files to /tmp where elasticsearch didn't find them. As soon as I moved the files making up the repo away from /tmp to some other place in the filesystem elasticsearch was able to access them. Seems to have something to do with the way systemd treats /tmp.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [January 12, 2025, 9:25am UTC](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987/6 "2025-01-12T09:25:44Z")

</div>

> [@e-lastic](#):
>
> Seems to have something to do with the way systemd treats /tmp.

Yes, Elasticsearch sets the `PrivateTmp` option by default. You can adjust this if you really need to, but the simplest solution is to avoid putting non-temporary (or at least non-process-private) stuff like snapshots in `/tmp`.
