# Salvage data from a single node that once belonged to a cluster

**URL:** <https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738>\
**Category:** Elasticsearch\
**Created:** [July 18, 2020, 8:58am UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738 "2020-07-18T08:58:49Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![yk928](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@yk928](https://discuss.elastic.co/u/yk928)\
**Post date:** [July 18, 2020, 8:58am UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/1 "2020-07-18T08:58:49Z")

</div>

I had an ES cluster of several nodes (let's say es1, es2, ...), and I have a disk snapshot from a certain point in the past, of the disk of a single ES node (i.e. es1).  
I'd like to dump all the data from this es1's backup.  
I can start a Linux instance (say, esX) from this backup, but the ES instance on esX won't start because it once belonged to a ES cluster.  
I don't have backups for es2, es3, ... so I can't start all nodes to build another cluster.  
How can I save data from this situation?

--

My guess is 1) maybe there's some way to force start the ES instance by skipping master discovery or election processes or the likes, or 2) maybe there's some way to dump data from /var/lib/elasticsearch directly, without starting an ES instance itself.  
But I can't find any way to do either of these.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 18, 2020, 9:02am UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/2 "2020-07-18T09:02:30Z")

</div>

Which version are you using?

---

<div class="post-metadata">

**Author:** ![yk928](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@yk928](https://discuss.elastic.co/u/yk928)\
**Post date:** [July 18, 2020, 9:06am UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/3 "2020-07-18T09:06:07Z")

</div>

```auto
{
    "number" : "7.7.0",
    "build_flavor" : "default",
    "build_type" : "deb",
    "build_hash" : "81a1e9eda8e6183f5237786246f6dced26a10eaf",
    "build_date" : "2020-05-12T02:01:37.602180Z",
    "build_snapshot" : false,
    "lucene_version" : "8.5.1",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  }

```

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 18, 2020, 10:00am UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/4 "2020-07-18T10:00:36Z")

</div>

What use will it be if you salvage the data from this single node? Elasticsearch doesn't store everything on every node, so whatever you salvage will be very incomplete and you likely won't even be able to tell what's missing.

---

<div class="post-metadata">

**Author:** ![yk928](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@yk928](https://discuss.elastic.co/u/yk928)\
**Post date:** [July 18, 2020, 10:31am UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/5 "2020-07-18T10:31:18Z")

</div>

That's fine. I just want to recover as much as possible.  
Plus, IIRC the number\_of\_replicas was set large enough so all shards were on es1.

Any help would be appreciated...

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 18, 2020, 11:44am UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/6 "2020-07-18T11:44:33Z")

</div>

The only reasonable way forward is to start again and replay your data from its original source into a new cluster. There's no value in filesystem-level backups of Elasticsearch nodes. Quoting [the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/snapshot-restore.html):

> You cannot back up an Elasticsearch cluster by simply copying the data directories of all of its nodes. [...] The only reliable way to back up a cluster is by using the snapshot and restore functionality.

Although you have a disk snapshot rather than a simple copy, this statement is still fundamentally true.

---

<div class="post-metadata">

**Author:** ![yk928](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@yk928](https://discuss.elastic.co/u/yk928)\
**Post date:** [July 18, 2020, 11:50am UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/7 "2020-07-18T11:50:11Z")

</div>

Thanks for your reply.  
Isn't there any way at all to get my data back even partially?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 18, 2020, 12:07pm UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/8 "2020-07-18T12:07:15Z")

</div>

I have no other recommendations, sorry. Logically the data was lost when the cluster failed without any proper snapshots.

---

<div class="post-metadata">

**Author:** ![yk928](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@yk928](https://discuss.elastic.co/u/yk928)\
**Post date:** [July 18, 2020, 12:22pm UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/9 "2020-07-18T12:22:46Z")

</div>

OK, I understand. Thanks. Will wait for some hack-ish advice hopefully.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 18, 2020, 1:19pm UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/10 "2020-07-18T13:19:35Z")

</div>

Resiliency has been improved in. 7.x, which means more checks and controls. This leaves less room for hacking solutions compared to earlier versions. If David can not suggest a solution I would bet such may not exist.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2020, 1:19pm UTC](https://discuss.elastic.co/t/salvage-data-from-a-single-node-that-once-belonged-to-a-cluster/241738/11 "2020-08-15T13:19:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
