# Save Index in specific Directory

**URL:** <https://discuss.elastic.co/t/save-index-in-specific-directory/375384>\
**Category:** Elasticsearch\
**Tags:** docker, ingest-pipeline\
**Created:** [March 4, 2025, 4:10pm UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384 "2025-03-04T16:10:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![NikoCosmico01](https://avatars.discourse-cdn.com/v4/letter/n/90db22/32.png) [@NikoCosmico01](https://discuss.elastic.co/u/NikoCosmico01)\
**Post date:** [March 4, 2025, 4:10pm UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384/1 "2025-03-04T16:10:53Z")

</div>

Hi,  
I've the ELK stack installed via docker having in particular 3 ES nodes and 1 LogStash node.  
My question is if there is a way to have the data ingested from a specific LogStash pipeline saved in a specific directory inside my host machine avoiding _/usr/share/elasticsearch/data/indices_ which is binded to host machine folder.  
In other words I want all the data inside a specific index to be saved onto a specific NAS.

I've tried using symbolic links but without success. I moved the index folder (named with the index uid) inside _/nas/node01/_ and then I performed

> ln -s /nas/node01/"index-uid" /hostPath/data/indices/"index-uid"

this for each data node. Please note that _/hostPath_ is binded onto _/usr/share/elasticsearch_ and _/nas_ is binded onto _/nas_.  
The moment I restart the docker-compose from Kibana the index has a grey status bullet point.

Many thanks in advance.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 4, 2025, 4:13pm UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384/2 "2025-03-04T16:13:21Z")

</div>

That's not possible.

All indices will be saved in the specified data path of elasticsearch.

---

<div class="post-metadata">

**Author:** ![NikoCosmico01](https://avatars.discourse-cdn.com/v4/letter/n/90db22/32.png) [@NikoCosmico01](https://discuss.elastic.co/u/NikoCosmico01)\
**Post date:** [March 4, 2025, 4:51pm UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384/3 "2025-03-04T16:51:53Z")

</div>

Is there a way to achieve what I mentioned using workarounds?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 4, 2025, 5:20pm UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384/4 "2025-03-04T17:20:37Z")

</div>

> [@NikoCosmico01](#):
>
> Is there a way to achieve what I mentioned using workarounds?

No, there are no workarounds.

When you configure Elasticsearch you configure a data path, this is the place where all data will be saved, you can configure it to be in your NAS if you want, but you cannot save specific data in different places, everything will be saved on the same data path.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 4, 2025, 6:43pm UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384/5 "2025-03-04T18:43:28Z")

</div>

If @NikoCosmico01 considers saving **all** indices to the NAS as an acceptable compromise, that is indeed possible. But, even that has risks, as the NAS would need to be a very snappy NAS for this to be sensible and performant, each node needs its own directory on the NAS, and the NAS (and network path to/from) is then effectively a single point of failure.

I often ask the "why" question back - it sometimes leads to a better idea, or even uncovers some misunderstanding of how stuff works.

So, _why_ do you want that specific index on the NAS, but the rest not on the NAS?

---

<div class="post-metadata">

**Author:** ![NikoCosmico01](https://avatars.discourse-cdn.com/v4/letter/n/90db22/32.png) [@NikoCosmico01](https://discuss.elastic.co/u/NikoCosmico01)\
**Post date:** [March 4, 2025, 8:16pm UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384/6 "2025-03-04T20:16:57Z")

</div>

Thank you both for these precise clarifications.

My actual data path leads to SSD disks with a limited capacity and the data on these needs to be highly available both for fast data retrieval and data retention. At the same time I have reading access to another SIEM in my org, not manageable by me due to bureoucracy, from whose I get a ton of data that I want to use for ML training jobs. I do not want the latter logs to end up on my main SSDs also because I do not need these to be higly available. I want to precise it is a non prod environment.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 6, 2025, 4:49pm UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384/7 "2025-03-06T16:49:54Z")

</div>

> [@RainTown](#):
>
> I often ask the "why" question back - it sometimes leads to a better idea, or even uncovers some misunderstanding of how stuff works.

So your logic makes sense and I dont see a simple alternative approach jumping out to me. You can add new clusters, even just add a single node cluster whose data directory is on your NAS (all caveats around using remote storage apply), where you can dump your data for later use / ML training.

But with your existing cluster and 2 such different requirements there's no sensible way to achieve both simultaneously that I can see.

---

<div class="post-metadata">

**Author:** ![NikoCosmico01](https://avatars.discourse-cdn.com/v4/letter/n/90db22/32.png) [@NikoCosmico01](https://discuss.elastic.co/u/NikoCosmico01)\
**Post date:** [March 11, 2025, 8:50am UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384/8 "2025-03-11T08:50:17Z")

</div>

At the end I have been able to achieve what I wanted by adding another node, binding it to the NAS directory and assigning this node the only role of _data\_warm_. Then I have created a Lifecycle Policy that moves immediately all the data to Warm phase after 0 minutes and assigned that policy to my desired index.  
I am aware that I can no longer use the warm phase for other indexes but at the moment I am only using hot and cold ones.
