# \#slm-snapshot-lifecycle-management

**URL:** https://discuss.elastic.co/tag/slm-snapshot-lifecycle-management/47.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Clarification about frozen data on k8s](https://discuss.elastic.co/t/clarification-about-frozen-data-on-k8s/385397)

<div class="topic-metadata">

**Author:** [@Cario](https://discuss.elastic.co/u/Cario)\
**Replies:** 0\
**Last updated:** [March 10, 2026, 3:51pm UTC](https://discuss.elastic.co/t/clarification-about-frozen-data-on-k8s/385397 "2026-03-10T15:51:13Z")

</div>

Hello everyone, I am new to the forum and basically self-taught, so I apologize in advance if I lack some basic knowledge. Thank you for your understanding. The elastic cluster works on a k8s cluster as pods, but readi…

---

## [Kibana snapshot policy from 5 days and indexes from one year](https://discuss.elastic.co/t/kibana-snapshot-policy-from-5-days-and-indexes-from-one-year/381705)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 1\
**Last updated:** [September 7, 2025, 3:03am UTC](https://discuss.elastic.co/t/kibana-snapshot-policy-from-5-days-and-indexes-from-one-year/381705 "2025-09-07T03:03:55Z")

</div>

Hello, I defined snapshot policy (for test purposes) to create snapshots from 5 days but I would like to have also indexes from last 5 days. Instead of that I have indexes there from one year. How can I define snapshot…

---

## [Backup Of Elastic Cluster](https://discuss.elastic.co/t/backup-of-elastic-cluster/378474)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [May 26, 2025, 4:30pm UTC](https://discuss.elastic.co/t/backup-of-elastic-cluster/378474 "2025-05-26T16:30:45Z")

</div>

Hi Team, If we want to take backup of elastic cluster by using below command. Will it take backup everything in cluster like ILM Policy, SLM Policy and any settings related to cluster. PUT \_slm/policy/weekly-snapshots …

---

## [Exclude symbol "-" does not work to filter out indices](https://discuss.elastic.co/t/exclude-symbol-does-not-work-to-filter-out-indices/377787)

<div class="topic-metadata">

**Author:** [@ChatLee](https://discuss.elastic.co/u/ChatLee)\
**Replies:** 0\
**Last updated:** [May 5, 2025, 2:01am UTC](https://discuss.elastic.co/t/exclude-symbol-does-not-work-to-filter-out-indices/377787 "2025-05-05T02:01:19Z")

</div>

Hi teams, I want to setup some snapshot settings, and I want to only back up indices those name start with non-dot, I tried with pattern " -.\* " and " \*, -.\* ", but found these patterns does not work. I tried to setup …

---

## [Azure Blob Storage Keeps Disconnecting when verify it gives "502 Bad Gateway"](https://discuss.elastic.co/t/azure-blob-storage-keeps-disconnecting-when-verify-it-gives-502-bad-gateway/374987)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [February 25, 2025, 7:00am UTC](https://discuss.elastic.co/t/azure-blob-storage-keeps-disconnecting-when-verify-it-gives-502-bad-gateway/374987 "2025-02-25T07:00:14Z")

</div>

Basic Information: I'm experiencing an issue with my on-prem Elasticsearch cluster's (8.17) Azure Blob Storage repository. The repository is configured using a container and initially shows as connected when verified vi…

---

## [Snapshot Lifecycle Lifecyle and Managment Creating issue for rollover](https://discuss.elastic.co/t/snapshot-lifecycle-lifecyle-and-managment-creating-issue-for-rollover/373154)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 1\
**Last updated:** [January 14, 2025, 2:50pm UTC](https://discuss.elastic.co/t/snapshot-lifecycle-lifecyle-and-managment-creating-issue-for-rollover/373154 "2025-01-14T14:50:53Z")

</div>

Overview i have elasticsearch 8.11 with no replicas right now, only 5 hot nodes and 2 frozen that's it. Here is index lifecycle policy is this PUT \_ilm/policy/ConrainerLogs { "policy": { "phases": { …

---

## [Snapshot Repository is 8x larger than total clustered data!?!?!](https://discuss.elastic.co/t/snapshot-repository-is-8x-larger-than-total-clustered-data/371625)

<div class="topic-metadata">

**Author:** [@ivanlawrence](https://discuss.elastic.co/u/ivanlawrence)\
**Replies:** 1\
**Last updated:** [December 18, 2024, 8:08am UTC](https://discuss.elastic.co/t/snapshot-repository-is-8x-larger-than-total-clustered-data/371625 "2024-12-18T08:08:16Z")

</div>

My cluster has a total usage reported by kibana (kibana/app/monitoring#/overview) as 1TB (102 indices with one replica.) Snapshots go to backblaze (as the s3 default client) which is reporting 8TB stored. I was snappin…

---

## [What are ilm-history and slm-history indices used for?](https://discuss.elastic.co/t/what-are-ilm-history-and-slm-history-indices-used-for/305711)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [November 30, 2024, 9:49pm UTC](https://discuss.elastic.co/t/what-are-ilm-history-and-slm-history-indices-used-for/305711 "2024-11-30T21:49:10Z")

</div>

I'm doing some cleanup on my cluster and saw that there are a couple of small system indices that I'm not sure for what they are used. Those indices are mostly ilm-history-\* , .ds-ilm-history-\* , .slm-history-\* and .ds-…

---

## [Restoring 7.x snapshot to fresh 8.14.3 ECK: System data streams missing after migration](https://discuss.elastic.co/t/restoring-7-x-snapshot-to-fresh-8-14-3-eck-system-data-streams-missing-after-migration/368674)

<div class="topic-metadata">

**Author:** [@Hadj\_Hassine\_Younes](https://discuss.elastic.co/u/Hadj_Hassine_Younes)\
**Replies:** 0\
**Last updated:** [October 11, 2024, 9:00am UTC](https://discuss.elastic.co/t/restoring-7-x-snapshot-to-fresh-8-14-3-eck-system-data-streams-missing-after-migration/368674 "2024-10-11T09:00:13Z")

</div>

I created the snapshot of my old version 7.x elk stack , and I now I am trying to restore the old snapshot on the new eck-elasticsearch version 8.14.3. Context: Upgraded from Elasticsearch v7.17.22 to v8.14.3 using ECK…

---

## [Changing timezone of instance for ilm and slm](https://discuss.elastic.co/t/changing-timezone-of-instance-for-ilm-and-slm/364026)

<div class="topic-metadata">

**Author:** [@kirik](https://discuss.elastic.co/u/kirik)\
**Replies:** 0\
**Last updated:** [July 30, 2024, 6:57am UTC](https://discuss.elastic.co/t/changing-timezone-of-instance-for-ilm-and-slm/364026 "2024-07-30T06:57:17Z")

</div>

Hi, I have elasticsearch running on one instance, logstash and kibana together on another separate instance with UTC timezone, so ilm and slm policy is running according to the UTC timezone. If I change the both server …

---

## [Closed indices are included in snapshot policy](https://discuss.elastic.co/t/closed-indices-are-included-in-snapshot-policy/357697)

<div class="topic-metadata">

**Author:** [@vishalk663](https://discuss.elastic.co/u/vishalk663)\
**Replies:** 1\
**Last updated:** [April 18, 2024, 11:34am UTC](https://discuss.elastic.co/t/closed-indices-are-included-in-snapshot-policy/357697 "2024-04-18T11:34:51Z")

</div>

We are using the elasticsearch 7.13.3 version using eck operator in our openshift cluster. When we are using below snapshot policy it did not include the closed indices in a snapshot. PUT \_slm/policy/elastic-snapshot {…

---

## [Elasticsearch 8.5.2 SLM Exclude index and datastream does not work](https://discuss.elastic.co/t/elasticsearch-8-5-2-slm-exclude-index-and-datastream-does-not-work/357029)

<div class="topic-metadata">

**Author:** [@Gautier\_Franchini](https://discuss.elastic.co/u/Gautier_Franchini)\
**Replies:** 3\
**Last updated:** [April 9, 2024, 8:09am UTC](https://discuss.elastic.co/t/elasticsearch-8-5-2-slm-exclude-index-and-datastream-does-not-work/357029 "2024-04-09T08:09:01Z")

</div>

Dear community members, using SLM policy I would like to exclue some indices and datastream from y daily backup; using the policy below doesn't gives me any ERROR ; but it's NOT applied as expected; Because doing a 'GET …

---

## [Adding an additional PVC without resetting the entire cluster](https://discuss.elastic.co/t/adding-an-additional-pvc-without-resetting-the-entire-cluster/355900)

<div class="topic-metadata">

**Author:** [@PustyB](https://discuss.elastic.co/u/PustyB)\
**Replies:** 0\
**Last updated:** [March 21, 2024, 12:57pm UTC](https://discuss.elastic.co/t/adding-an-additional-pvc-without-resetting-the-entire-cluster/355900 "2024-03-21T12:57:33Z")

</div>

Hi. I have Elastic Stack on self-hosted kubernetes. It is managed by the Elastic operator. I have 3 replicas. I would like to add an additional VolumeClaimTemplate to them, which will be responsible for holding snapshot…

---

## [S3 compatible with repository\_verification\_exception](https://discuss.elastic.co/t/s3-compatible-with-repository-verification-exception/353360)

<div class="topic-metadata">

**Author:** [@Omizollo](https://discuss.elastic.co/u/Omizollo)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 10:31am UTC](https://discuss.elastic.co/t/s3-compatible-with-repository-verification-exception/353360 "2024-02-15T10:31:32Z")

</div>

I have a custom s3 storage which I can communicate with using AWS sdk. I have configured the repository with Elasticsearch v7.17 and it is working fine, but after upgrade to the version v8.11 the verification to the repo…

---

## [Difference in Shard & Index count during Snapshot & Restore](https://discuss.elastic.co/t/difference-in-shard-index-count-during-snapshot-restore/352154)

<div class="topic-metadata">

**Author:** [@Vadiraj\_Prahalad](https://discuss.elastic.co/u/Vadiraj_Prahalad)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 6:46am UTC](https://discuss.elastic.co/t/difference-in-shard-index-count-during-snapshot-restore/352154 "2024-01-31T06:46:18Z")

</div>

Hello All, We are performing Elastic Upgrade by building parallel cluster for the existing cluster ( due to organization issues ) I have created Snapshot Policy in Source Cluster to run the snapshot at 5:30 PM PST ever…

---

## [Optimizing Storage Costs for Historical Data in Elasticsearch on Azure: Seeking Community Advice](https://discuss.elastic.co/t/optimizing-storage-costs-for-historical-data-in-elasticsearch-on-azure-seeking-community-advice/348440)

<div class="topic-metadata">

**Author:** [@identifysun](https://discuss.elastic.co/u/identifysun)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:41pm UTC](https://discuss.elastic.co/t/optimizing-storage-costs-for-historical-data-in-elasticsearch-on-azure-seeking-community-advice/348440 "2023-12-01T15:41:26Z")

</div>

I have an Elasticsearch cluster deployed on Azure. I need to retain historical data in Elasticsearch and currently use snapshot policies to store snapshots in Azure Blob storage. However, over time, I noticed that the st…

---

## [Restore from S3 Snapshot](https://discuss.elastic.co/t/restore-from-s3-snapshot/347210)

<div class="topic-metadata">

**Author:** [@Vadiraj\_Prahalad](https://discuss.elastic.co/u/Vadiraj_Prahalad)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 9:52am UTC](https://discuss.elastic.co/t/restore-from-s3-snapshot/347210 "2023-11-15T09:52:21Z")

</div>

Hello Everyone, We are trying to Restore the snapshot from S3 bucket. The snapshot is taken from a different cluster (7.12) & getting restored in different cluster (7.17 ). Below is the error during the restore activit…

---

## [Snapshot, Hot/Warm Architecture and Upgrade](https://discuss.elastic.co/t/snapshot-hot-warm-architecture-and-upgrade/344887)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 11\
**Last updated:** [October 13, 2023, 11:25am UTC](https://discuss.elastic.co/t/snapshot-hot-warm-architecture-and-upgrade/344887 "2023-10-13T11:25:36Z")

</div>

Hi there, I have a few questions here: First, if I have an index of 4.5 TB, what is the best way to back up that much data? Second, my existing cluster has 25 data nodes in total, if I want to apply hot/warm architect…

---

## [Will the snapshot repository able to capture the changes in mappings?](https://discuss.elastic.co/t/will-the-snapshot-repository-able-to-capture-the-changes-in-mappings/339244)

<div class="topic-metadata">

**Author:** [@ian.chan](https://discuss.elastic.co/u/ian.chan)\
**Replies:** 6\
**Last updated:** [July 27, 2023, 5:19am UTC](https://discuss.elastic.co/t/will-the-snapshot-repository-able-to-capture-the-changes-in-mappings/339244 "2023-07-27T05:19:09Z")

</div>

Hi. Let's say I have registered a snapshot repository for an index A, with slm policy taking snapshot every hour. Then I add a new field in the mapping of the index A, and add some new documents with values in this new…

---

## [Elasticsearch backup](https://discuss.elastic.co/t/elasticsearch-backup/335848)

<div class="topic-metadata">

**Author:** [@Akshay\_Patidar](https://discuss.elastic.co/u/Akshay_Patidar)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/elasticsearch-backup/335848 "2023-06-20T04:30:10Z")

</div>

As specific date interval for slm policy in not possible so what is the alternative way for taking backup of Elasticsearch for specific date interval Example : like I wanted to take backup daily from 15/06 to 30/06

---

## [Elasticsearch snapshots fail everyday](https://discuss.elastic.co/t/elasticsearch-snapshots-fail-everyday/335747)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 11:23am UTC](https://discuss.elastic.co/t/elasticsearch-snapshots-fail-everyday/335747 "2023-06-14T11:23:01Z")

</div>

Hi, I am using elasticsearch 8.7 in out production cluster on Azure kubernetes platform which has 8 data and master nodes and almost 4TB per node disks being used to store our observability data. we have 699 indexes as …

---

## [Can Snapshots save index in a limited time](https://discuss.elastic.co/t/can-snapshots-save-index-in-a-limited-time/333553)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 12:04pm UTC](https://discuss.elastic.co/t/can-snapshots-save-index-in-a-limited-time/333553 "2023-05-16T12:04:17Z")

</div>

Hello everyone, I would like to know if it is possible to set up a snapshot policy that retrieves for example indexes only from the last 7 days. For example, I save my logs from my active directory with this format: in…

---

## [Removing one of the s3 snapshot repository causing connection pool shutdown](https://discuss.elastic.co/t/removing-one-of-the-s3-snapshot-repository-causing-connection-pool-shutdown/329857)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 2:31am UTC](https://discuss.elastic.co/t/removing-one-of-the-s3-snapshot-repository-causing-connection-pool-shutdown/329857 "2023-04-13T02:31:02Z")

</div>

Hello - When we configure single S3 bucket for backup, snapshot functionality is working as expected. But when we create a additional repository and remove it afterwards, elasticsearch snapshot functionality is failing t…

---

## [Are there any guidelines to estimate how many snapshots can be handled by elasticsearch with specific amount of memory/cpu](https://discuss.elastic.co/t/are-there-any-guidelines-to-estimate-how-many-snapshots-can-be-handled-by-elasticsearch-with-specific-amount-of-memory-cpu/329811)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/are-there-any-guidelines-to-estimate-how-many-snapshots-can-be-handled-by-elasticsearch-with-specific-amount-of-memory-cpu/329811 "2023-04-12T08:29:34Z")

</div>

HI - I am looking for any data or estimates if we can derive about retaining the snapshots based on size of the cluster. E.g. If we have a smaller elastic cluster with 2G of memory allocation, and SLM with each 15 min s…

---

## [S3 API Costs are extraordinary expensive for snapshots](https://discuss.elastic.co/t/s3-api-costs-are-extraordinary-expensive-for-snapshots/329071)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 7:04pm UTC](https://discuss.elastic.co/t/s3-api-costs-are-extraordinary-expensive-for-snapshots/329071 "2023-03-31T19:04:45Z")

</div>

To store 5TB of data, we are paying about $1,200 in storage fees per month and $10,000 in API calls Is there a way to fix this? During a snapshot we are seeing upwards of 120k s3 api calls/minute SLM: PUT \_slm/policy/…

---

## [SLM should be happening only for Delete Phase indices](https://discuss.elastic.co/t/slm-should-be-happening-only-for-delete-phase-indices/327546)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 5:28pm UTC](https://discuss.elastic.co/t/slm-should-be-happening-only-for-delete-phase-indices/327546 "2023-03-13T17:28:59Z")

</div>

Hi All, I am using ELK version 8.0.0, where we are using SLM policy but wanted to know it there any option to make sure when the SLM happens it should be only happening for indices which are in delete phase. Currently i…

---

## [SLM cron expression](https://discuss.elastic.co/t/slm-cron-expression/327357)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 12:55pm UTC](https://discuss.elastic.co/t/slm-cron-expression/327357 "2023-03-10T12:55:36Z")

</div>

Hi Team, I am using a slm policy and wanted to add the cron expression such that it run on every 26th day. e.g for 1st month jan it run on 26/01/2023 and then run on +26 days that is 21/02/2023 and so on. Can someone pl…

---

## [Elasticsearch snapshot retention behavior](https://discuss.elastic.co/t/elasticsearch-snapshot-retention-behavior/326262)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 3\
**Last updated:** [February 23, 2023, 7:08am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-retention-behavior/326262 "2023-02-23T07:08:14Z")

</div>

Lets say we create daily indices with ILM policy that delete data after 1 year. And lets say we have SLM that have retention period of 30 days. So, eventually what will be the content of snapshot after 1 year. Is it one…

---

## [Automatically closing indices older than x days using ILP](https://discuss.elastic.co/t/automatically-closing-indices-older-than-x-days-using-ilp/325765)

<div class="topic-metadata">

**Author:** [@Monica\_majua](https://discuss.elastic.co/u/Monica_majua)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 8:21pm UTC](https://discuss.elastic.co/t/automatically-closing-indices-older-than-x-days-using-ilp/325765 "2023-02-16T20:21:17Z")

</div>

I was wondering if it is possible to configure a lifecycle policy so that nodes older than 300 days are automatically closing? I would like to know if I am on the right way or am I really trying something that I will nev…

---

## [Snapshot error](https://discuss.elastic.co/t/snapshot-error/323104)

<div class="topic-metadata">

**Author:** [@Sam\_LE](https://discuss.elastic.co/u/Sam_LE)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 11:28pm UTC](https://discuss.elastic.co/t/snapshot-error/323104 "2023-01-18T23:28:33Z")

</div>

Hello, We have an ES cluster v7.8.1 and we try to create a first snapshot. We used kibana and created a policy. However we got errors on several index. Errors are : """ElasticsearchException\[failed to create blob conta…

[Next page](https://discuss.elastic.co/tag/slm-snapshot-lifecycle-management/47.md?match_all_tags=true&page=1&tags%5B%5D=slm-snapshot-lifecycle-management)
