# Snapshot & restore

**URL:** <https://discuss.elastic.co/t/snapshot-restore/106206>\
**Category:** Elasticsearch\
**Created:** [November 2, 2017, 1:58pm UTC](https://discuss.elastic.co/t/snapshot-restore/106206 "2017-11-02T13:58:56Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Damien](https://avatars.discourse-cdn.com/v4/letter/d/9de053/32.png) [@Damien](https://discuss.elastic.co/u/Damien)\
**Post date:** [November 2, 2017, 1:58pm UTC](https://discuss.elastic.co/t/snapshot-restore/106206/1 "2017-11-02T13:58:57Z")

</div>

Hi,

I use snapshot & restore module for Elasticsearch 2.3 to backup our server every day.  
We rotate every 7 backup.

The rotate works, i can verify with this command:  
curl -XGET 'localhost:9200/\_snapshot/my\_backup/\_all?pretty'

But old indices are not deleted and my backup size is important.

How can i do? use rm -r on very old indices?

Thanks for the help

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 2, 2017, 2:45pm UTC](https://discuss.elastic.co/t/snapshot-restore/106206/2 "2017-11-02T14:45:25Z")

</div>

Try using [Elasticsearch Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/4.3/installation.html). Version 4.3.1 will work with Elasticsearch v2.

---

<div class="post-metadata">

**Author:** ![Damien](https://avatars.discourse-cdn.com/v4/letter/d/9de053/32.png) [@Damien](https://discuss.elastic.co/u/Damien)\
**Post date:** [November 2, 2017, 3:55pm UTC](https://discuss.elastic.co/t/snapshot-restore/106206/3 "2017-11-02T15:55:28Z")

</div>

Hi, thank you for your response!

So, if i understand, i still use snapshot & restore module to backup my server, XDELETE to rotate, but i have to add Curator to reduce the backup in my ES repo?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 2, 2017, 4:01pm UTC](https://discuss.elastic.co/t/snapshot-restore/106206/4 "2017-11-02T16:01:51Z")

</div>

You can use Curator to do all of it. Create a Curator action file that

- performs your snapshot
- deletes indices older than _x_ days
- deletes snapshots older than _x_ days

each in sequence, all in the same configuration.

---

<div class="post-metadata">

**Author:** ![Damien](https://avatars.discourse-cdn.com/v4/letter/d/9de053/32.png) [@Damien](https://discuss.elastic.co/u/Damien)\
**Post date:** [November 2, 2017, 4:15pm UTC](https://discuss.elastic.co/t/snapshot-restore/106206/5 "2017-11-02T16:15:51Z")

</div>

Ok thank you, if i have no choice, i will use curator.

For now we use Elasticsearch with Graylog, and Graylog delete older indices than 50 days.  
So i backup only the last 50 indices.

To be sure:  
It is normal if my old indices (in my backup) are not deleted? although i use a curl -s XDELETE ?  
And if remove old indices (in my backup) with a rm -r, can i corrupt my backup?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 2, 2017, 4:19pm UTC](https://discuss.elastic.co/t/snapshot-restore/106206/6 "2017-11-02T16:19:05Z")

</div>

> [@Damien](#):
>
> It is normal if my old indices (in my backup) are not deleted? although i use a curl -s XDELETE ?

No. This is not normal. If indices persist, it could indicate the behavior characteristics of an overloaded cluster.

> [@Damien](#):
>
> And if remove old indices (in my backup) with a rm -r, can i corrupt my backup?

Absolutely. You should _never_ interact with the files in your data directory or your snapshot repository in any other way than via the designated API calls.

While I appreciate that you're using the API calls to handle what you're doing, Curator was expressly designed to be an index and snapshot selecting wrapper for those API calls, to enable you to do everything much more easily. I think if you give it a try you'll find it to your liking.

---

<div class="post-metadata">

**Author:** ![Damien](https://avatars.discourse-cdn.com/v4/letter/d/9de053/32.png) [@Damien](https://discuss.elastic.co/u/Damien)\
**Post date:** [November 6, 2017, 8:57am UTC](https://discuss.elastic.co/t/snapshot-restore/106206/7 "2017-11-06T08:57:07Z")

</div>

In fine this is ok  
Old indices folders are just empty

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2017, 8:57am UTC](https://discuss.elastic.co/t/snapshot-restore/106206/8 "2017-12-04T08:57:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
