# Watcher to create snapshot and restore snapshot

**URL:** <https://discuss.elastic.co/t/watcher-to-create-snapshot-and-restore-snapshot/219236>\
**Category:** Elasticsearch\
**Created:** [February 13, 2020, 3:27pm UTC](https://discuss.elastic.co/t/watcher-to-create-snapshot-and-restore-snapshot/219236 "2020-02-13T15:27:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jlim0930](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@jlim0930](https://discuss.elastic.co/u/jlim0930)\
**Post date:** [February 13, 2020, 3:27pm UTC](https://discuss.elastic.co/t/watcher-to-create-snapshot-and-restore-snapshot/219236/1 "2020-02-13T15:27:05Z")

</div>

I am trying to create a watcher to create a snapshot and another watcher to restore the same snapshot then delete it.

to take the snapshot I have

```
POST _watcher/watch/test
{
  "trigger": {
    "schedule": {
      "interval": "30m"
    }
  },
  "actions": {
    "take_snapshot_kibana": {
      "webhook": {
        "method": "PUT",
        "port": 9200,
        "scheme": "https",
        "host": "localhost"
        "path": "/_snapshot/s3/snapshot_kibana",
        "body": ""
      }
    }
  }
}

```

and in the body I want to set it so that it only takes the .kibana like  
{  
"indices": ".kibana",  
"ignore\_unavailable": true,  
}

so how would you format the body portion ?

ultimately I am wanting to replicate all of .kibana and .logstash from one cluster to another.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 13, 2020, 4:54pm UTC](https://discuss.elastic.co/t/watcher-to-create-snapshot-and-restore-snapshot/219236/2 "2020-02-13T16:54:10Z")

</div>

Take a look at the [Snapshot Lifecycle Management](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/snapshot-lifecycle-management-api.html) - also there is a nice UI for this if you do not want to fiddle with the API endpoints. See the kibana docs at [https://www.elastic.co/guide/en/kibana/7.6/snapshot-repositories.html#snapshot-repositories](https://www.elastic.co/guide/en/kibana/7.6/snapshot-repositories.html#snapshot-repositories)

There is no need for watcher here, Elasticsearch offers this out of the box.

---

<div class="post-metadata">

**Author:** ![jlim0930](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@jlim0930](https://discuss.elastic.co/u/jlim0930)\
**Post date:** [February 13, 2020, 5:07pm UTC](https://discuss.elastic.co/t/watcher-to-create-snapshot-and-restore-snapshot/219236/3 "2020-02-13T17:07:23Z")

</div>

I am trying to setup a automated backup/restore of .kibana(for saved objects) and .logstash(for pipelines) indexes onto another cluster for near live DR setup. in the SLM i know that you can setup policies for backups on schedule but not for restores on the remote cluster.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2020, 5:07pm UTC](https://discuss.elastic.co/t/watcher-to-create-snapshot-and-restore-snapshot/219236/4 "2020-03-12T17:07:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
