# Snapshot policy to include closed indices

**URL:** <https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851>\
**Category:** Elasticsearch\
**Tags:** slm-snapshot-lifecycle-management\
**Created:** [December 16, 2020, 11:10am UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851 "2020-12-16T11:10:24Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomhe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomhe/32/120065_2.png) [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Post date:** [December 16, 2020, 11:10am UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/1 "2020-12-16T11:10:24Z")

</div>

The [create snapshot API](https://www.elastic.co/guide/en/elasticsearch/reference/current/create-snapshot-api.html) states that the default for `expand_wildcards` is `all`, but our snapshots created through a snapshot policy does not include our closed indices.

We have tried with wildcards:

```auto
PUT _slm/policy/daily-snapshots
{
    "name": "<snapshot-{now/d}>",
    "schedule": "0 30 21 * * ?",
    "repository": "snapshots-001",
    "config": {
        "indices": ["*", ".*"]
    }
}

```

as well as without:

```auto
PUT _slm/policy/daily-snapshots
{
    "name": "<snapshot-{now/d}>",
    "schedule": "0 30 21 * * ?",
    "repository": "snapshots-001",
    "config": {}
}

```

In both cases our closed indices are not included.

How can we create a policy that creates snapshots that include closed indices?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 16, 2020, 12:05pm UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/2 "2020-12-16T12:05:46Z")

</div>

Where do those docs say anything about `expand_wildcards`?

They do say this (emphasis mine)

> By default, a snapshot includes all data streams and **open** indices in the cluster, as well as the cluster state.

I don't think we include closed indices in snapshots.

---

<div class="post-metadata">

**Author:** ![tomhe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomhe/32/120065_2.png) [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Post date:** [December 16, 2020, 3:26pm UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/3 "2020-12-16T15:26:10Z")

</div>

Sorry, for some reason I pasted the wrong url. This is the documentation that I meant to link:

> **[Create a snapshot | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/snapshots-take-snapshot.html#create-snapshot-options)**

This is the text:

> The `expand_wildcards` option can be used to control whether hidden and closed indices will be included in the snapshot, and defaults to `all` .

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 16, 2020, 4:06pm UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/4 "2020-12-16T16:06:34Z")

</div>

Which version of Elasticsearch are you using? Looking at the documentation it looks like that description appeared for version Elasticsearch 7.7.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 16, 2020, 4:16pm UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/5 "2020-12-16T16:16:21Z")

</div>

Apologies, yes, you're quite right, it's rather well-hidden in the code too but I see it now. I haven't had time to investigate further yet.

---

<div class="post-metadata">

**Author:** ![tomhe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomhe/32/120065_2.png) [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Post date:** [December 16, 2020, 4:22pm UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/6 "2020-12-16T16:22:45Z")

</div>

We're on 7.10.0.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 16, 2020, 6:20pm UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/7 "2020-12-16T18:20:20Z")

</div>

As far as I can tell the newer docs are right and what I said before was wrong, we default `"expand_wildcards":["open","closed","hidden"]` which means `all` and definitely includes closed indices, and snapshots do include closed indices by default. I don't see anything in the SLM code that would change that. All very strange.

---

<div class="post-metadata">

**Author:** ![tomhe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomhe/32/120065_2.png) [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Post date:** [December 17, 2020, 4:02pm UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/8 "2020-12-17T16:02:20Z")

</div>

To check this in a more controlled manner I fired up a local Docker cluster from scratch with one Elasticsearch node and one Kibana instance running 7.10.1.

1. I registered a repository and created a policy with default values.

```auto
PUT _slm/policy/daily-snapshots
{
  "name": "<snapshot-{now/d}>",
  "schedule": "0 0 0 1 1 ?",
  "repository": "snapshots",
  "config": {
    "include_global_state": true
  }
}

```

1. I created an index
2. I ran the policy =\> 8 indices in snapshot
3. I closed the index that I created in step 2
4. I ran the policy =\> 7 indices in snapshot

 ![Screenshot 2020-12-17 at 16.55.13](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b6b615a2a2dbe8db4d9d09dfd287430fcf22e2d.png)

Any ideas on what to try with in order to get the closed indices included in the snapshots?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 17, 2020, 6:03pm UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/9 "2020-12-17T18:03:24Z")

</div>

Thanks for reproducing it in a controlled fashion, that's very helpful. I suggest opening an issue on Github with this information, it sounds like a bug to me.

---

<div class="post-metadata">

**Author:** ![tomhe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomhe/32/120065_2.png) [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Post date:** [December 18, 2020, 10:23am UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/10 "2020-12-18T10:23:47Z")

</div>

OK, here's what I know:

This command does not include closed:

```auto
POST /_snapshot/repo/snapshot

```

This command includes closed:

```auto
POST /_snapshot/repo/snapshot
{
  "expand_wildcards": "all"
}

```

I will create an issue on Github.

---

<div class="post-metadata">

**Author:** ![tomhe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomhe/32/120065_2.png) [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Post date:** [December 18, 2020, 11:00am UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/11 "2020-12-18T11:00:43Z")

</div>

> <https://github.com/elastic/elasticsearch/issues/66585>
>
> Elasticsearch version (bin/elasticsearch --version):
> Version: 7.10.1, Build: default/docker/1c34507e66d7db1211f66f3513706fdf548736aa/2020-12-05T01:00:33.671820Z, JVM: 15.0.1
> Plugins installed: \[\]
> JVM version (java -version):
> OS version (uname -a if on a Unix-like...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2021, 11:00am UTC](https://discuss.elastic.co/t/snapshot-policy-to-include-closed-indices/258851/12 "2021-01-15T11:00:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
