# Start elasticsearch that used to be in a cluster as a single-node or in a different cluster

**URL:** <https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568>\
**Category:** Elasticsearch\
**Created:** [February 27, 2023, 10:55am UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568 "2023-02-27T10:55:54Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Post date:** [February 27, 2023, 10:55am UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/1 "2023-02-27T10:55:54Z")

</div>

Hey Everyone,

Due to some stuff that happened, I have an Elasticsearch node with a lot of data, that isn't up to date with the cluster.

What I need to do is somehow start this node as a separate cluster, without it needing the voting results of two other nodes, and without it joining the existing cluster.

How would I go about doing this?

Cheers,  
Luka

---

<div class="post-metadata">

**Author:** ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Post date:** [February 27, 2023, 11:29am UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/2 "2023-02-27T11:29:47Z")

</div>

One more thing, if it's not possible to transfer it as a single-node. Is it possible to create new voting-only masters and join them to the new cluster so it starts up?

Cheers,  
Luka

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 27, 2023, 11:39am UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/3 "2023-02-27T11:39:27Z")

</div>

Which version of Elasticsearch are you using?

Is the node master eligible?

How did you end up in this situation? Why can the node not rejoin the cluster?

---

<div class="post-metadata">

**Author:** ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Post date:** [February 27, 2023, 12:20pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/4 "2023-02-27T12:20:46Z")

</div>

> Which version of Elasticsearch are you using?

7.15.2

> Is the node master eligible?

yes

> How did you end up in this situation? Why can the node not rejoin the cluster?

The FS got corrupted so we spent a few days recovering it... A lot of stuff happened, but long story short - if he joins the cluster he will delete the indices because they are no longer present on the current cluster (they were deleted).

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 27, 2023, 12:30pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/5 "2023-02-27T12:30:19Z")

</div>

I suspect you will need to use the [elasticsearch-node tool](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/node-tool.html), but note that this comes with warnings and is unsafe. I will not be able to help with this as I have fortunately not had to use it, but maybe someone else can help if you have issues or questions around the docs.

---

<div class="post-metadata">

**Author:** ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Post date:** [February 27, 2023, 1:41pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/6 "2023-02-27T13:41:51Z")

</div>

Thanks @Christian_Dahlqvist, so far so good.  
The `unsafe-bootstrap` bootstrap option allowed me to start the node with a different cluster name and the data is safe, and in tact.

Now it's just about getting the data synced.

Cheers,  
Luka

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 27, 2023, 3:46pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/7 "2023-02-27T15:46:14Z")

</div>

Since that node is now it's own cluster. Could you use logstash to move the data between the two clusters? Might not be quick, but you'd have good visibility of it working as the process runs.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 27, 2023, 4:01pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/8 "2023-02-27T16:01:49Z")

</div>

I would recommend either moving the data through snapshot/restore or do a remote reindexing.

---

<div class="post-metadata">

**Author:** ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Post date:** [February 27, 2023, 4:22pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/9 "2023-02-27T16:22:24Z")

</div>

We did a lot of testing on a massive cluster we have and Logstash is only good for a small amount of data. Same goes for a remote reindex (since slicing is not supported).

No matter how much we tuned a single logstash couldn't go over 60k/s ingesting and a remote reindex capped at about 30-35k/s.

Another bad thing with Logstash is it has no state when using elasticsearch as input and output. If it restarts or crashes or smth and you have to restart it, it will re-read all the indexes (assuming you give it a wildcard). If going index by index you have to monitor it constantly which is also not ideal.

Best bet in case of smaller data, imo is remote reindex as it can be monitored via task API.

In big clusters, snapshot/restore is by FAR the best bet.

Cheers,  
Luka

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2023, 4:22pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568/10 "2023-03-27T16:22:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
