# What is the best approach for ELK stack clsuter migration to different location?

**URL:** <https://discuss.elastic.co/t/what-is-the-best-approach-for-elk-stack-clsuter-migration-to-different-location/187933>\
**Category:** Elasticsearch\
**Created:** [June 27, 2019, 9:16pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-for-elk-stack-clsuter-migration-to-different-location/187933 "2019-06-27T21:16:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [June 27, 2019, 9:16pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-for-elk-stack-clsuter-migration-to-different-location/187933/1 "2019-06-27T21:16:23Z")

</div>

Hi Experts,

My current ELK stack(6.3.2) setup is at abc location and now data center is migrating to another xyz location . I have 3 node cluster for ES and one kibana and 1 logstash . Now I have to rebuild the entire setup at the new location . So i will be having brand new servers , separate network etc etc.  
My concern here is what will be the best approach? I can think of 2

1. Snapshot (But because my data is live and indices are per day basis on the old cluster so how I am going to achieve this) I mean without downtime how this is possible ?
2. Re-index API approach which I think is not possible in my case because i do not have the same network ?

Please suggest what would be the best approach . Waiting for your valuable responses .

Regards  
VG

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 28, 2019, 5:23am UTC](https://discuss.elastic.co/t/what-is-the-best-approach-for-elk-stack-clsuter-migration-to-different-location/187933/2 "2019-06-28T05:23:13Z")

</div>

If you have time-based indices where new indices are created at a specific time each day you can try the following approach:

- Update Logstash to write to both clusters in parallel.
- Then wait until the indices that were being written to at the time of the change are no longer written to.
- Take a full snapshot of the old cluster. This will now contain all old data, including the index that was only partially written to the new cluster.
- Go into the new cluster and delete the partially written indices.
- Restore all indices that do not exist in the destimation cluster from the snapshot.
- Check that the new cluster is working and has all data.
- Change Logstash to only write to the new cluster and remove the old cluster.

If you have time-based indices with longer time periods, e.g. weekly or monthly, or are using the rollover API the process would need to be altered.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [June 28, 2019, 6:31pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-for-elk-stack-clsuter-migration-to-different-location/187933/3 "2019-06-28T18:31:43Z")

</div>

This sounds really good approach as i have daily Indices thank you very much @Christian_Dahlqvist . I just need to check if I can dual feed from one LS to 2 clusters as both are on different networks. Also on the old LS server I have syslog which write data to a file then LS read it and index that data , so I need to take care of that as well. Any further suggestion on this please .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2019, 6:40pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-for-elk-stack-clsuter-migration-to-different-location/187933/4 "2019-07-26T18:40:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
