# Where eleasticsearch is store the data

**URL:** <https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975>\
**Category:** Elasticsearch\
**Created:** [June 22, 2018, 6:25am UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975 "2018-06-22T06:25:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![antonopo](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Post date:** [June 22, 2018, 6:25am UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975/1 "2018-06-22T06:25:41Z")

</div>

Hi 🙂  
Where eleasticsearch is store the data??

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 22, 2018, 6:31am UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975/2 "2018-06-22T06:31:59Z")

</div>

Each node stores it in the path(s) specified through the [path.data](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/path-settings.html) setting in the `elasticsearch.yml` file. The default location depends on the operating system and how you installed Elasticsearch.

---

<div class="post-metadata">

**Author:** ![antonopo](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Post date:** [June 22, 2018, 6:49am UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975/3 "2018-06-22T06:49:30Z")

</div>

i see on my elasticsearch.yml --\> path.data: /var/lib/elasticsearch

[root@atdevxhv03 elasticsearch]# ls  
elasticsearch java\_pid10887.hprof java\_pid1235.hprof java\_pid14871.hprof java\_pid9070.hprof java\_pid993.hprof nodes

i see this structure

[root@atdevxhv03 indices]# ls  
1z1lyK32RV-Jp8kklkpUjg A54xsLVDRwCAQF8v76OJRg KuL\_\_xJOR12Hb36B6E\_Fuw NXkYdUJJRwC1c3nd8m5ljQ \_q60dpyHS5mUvlu6Gxwk4w rykKc0rVSaaSJRzfa-k40w XewkX5E6QKCJRm0UHHMxxg ZLp8E5aBT1GIOW4REI8rKQ  
1ZS3zxCPRg2AVRtUPLXSgg bct20jbGTTCwDJ2SK6tv\_Q kYm6Tz6ZRde8S\_u9B9q3OQ OduaKFIuQ\_6jK2VBDCihzA QdtShFGsQ1i823-RT3H0Jg -Tg08EFyRJeMjXYnovxB6A XvedsiJARmyTvGtGMImnUQ zMkwFcwDRhy1gzQuixhQDA  
24XCvfm0TIasQiw5C0uL-Q IDx6DHShSaeJcVePu8UQbg MkxEuMvkRFqjHQVmwJw6KA puhINUGwQx6tctY2WkALVA qtO5PE\_OTIWN20Z6IT1B1g \_TQnvOpnR0Sq\_aCrWLGdkA ye-mQ7blRWCtcfguWLnzzQ  
7xBuTcTgQySPR2wIPtAiUA jQWu\_bv2TdGY8ZsPpWTssw ntPZQMPuRt6wTYMVFqAnhA pZ5j6QD6QcmSQHjcwfHUiQ rHtkw24-Tpe-0SSqkb-WCQ wkMW4PbST6muOER3VNg0yQ ytcOOL2mT8arC6YA123GDQ  
[root@atdevxhv03 indices]# pwd  
/var/lib/elasticsearch/nodes/0/indices

The data can only read from Kibana?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 22, 2018, 7:08am UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975/4 "2018-06-22T07:08:07Z")

</div>

No, you can access it directly through the Elasticsearch APIs as well, and there are language clients for most popular programming languages that make this easier.

What is it you are looking to do?

---

<div class="post-metadata">

**Author:** ![antonopo](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Post date:** [June 22, 2018, 7:40am UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975/5 "2018-06-22T07:40:22Z")

</div>

How i can access it through ElasticSearch APIs or from language clients?

I have configured my ELK server on a Centos 7 server and i have 5-6 clients with centos that i am sending their logs to ELK Server using the filebeats deamon which is installed in each centos client.  
If i understand well the Logstash service that is running on the ELK server parses these logs from the clients and then it send them on the elasticsearch service who store them somewhere.

From my Kibana interface i am able to see them using indexes patterns . In my case the index pattern is filebeat\*

For example from my json files that i get i see this "\_index": "filebeat-2018.06.22"

So all the logs today are stored on "\_index": "filebeat-2018.06.22" ?

Where i can see the logs that i got yestarday? for example the "\_index": "filebeat-2018.06.21". Where all these indexes are stored?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 22, 2018, 7:48am UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975/6 "2018-06-22T07:48:45Z")

</div>

Create a `filebeat-*` index pattern in Kibana. I would also recommend going through the [getting started guide](https://www.elastic.co/guide/en/kibana/current/getting-started.html) if you have not already. [This webinar](https://www.elastic.co/webinars/introduction-elk-stack) might also be useful.

---

<div class="post-metadata">

**Author:** ![antonopo](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Post date:** [June 22, 2018, 12:12pm UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975/7 "2018-06-22T12:12:39Z")

</div>

ok thanks a lot!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2018, 12:12pm UTC](https://discuss.elastic.co/t/where-eleasticsearch-is-store-the-data/136975/8 "2018-07-20T12:12:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
