# Elastic Restore Help Please

**URL:** <https://community.graylog.org/t/elastic-restore-help-please/19161>\
**Category:** Graylog Central (peer support)\
**Created:** [March 18, 2021, 1:41am UTC](https://community.graylog.org/t/elastic-restore-help-please/19161 "2021-03-18T01:41:25Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 18, 2021, 1:41am UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/1 "2021-03-18T01:41:25Z")

</div>

I’m migrating from Graylog 3.2.x to 4.x and I have made an elastic backup from 3.x.

> **[HOW TO CREATE SNAPSHOT And RESTORE OF ELASTICSEARCH CLUSTER DATA](https://linuxaws.wordpress.com/2018/09/21/how-to-create-snapshots-of-elasticsearch-cluster-data-and-restore/)**
>
> It is a very simple  method if you want to migrate your current elasticsearch cluster to a new version or  To backup and restoration due to any failure, without loss of any data (Indices). This  ar…

I have added the elastic repo on the new running and logging server. It has been collecting logs for about a week. I’m about ready to pull the trigger on restoring the old data. But I need a sanity check before I blow away a week worth of logs. I’m not exactly sure what happens now. Will I see a new index appear in Graylog after the restore? Will I accidentally erase the new stuff restoring the old? Will Graylog even be able to search the restored indices, or is something required to see them? Should graylog-server be stopped while the restore runs?

Help???

#\> curl -XGET ‘[http://localhost:9200/\_snapshot/\_all?pretty](http://localhost:9200/_snapshot/_all?pretty)’  
{  
“esrestore” : {  
“type” : “fs”,  
“settings” : {  
“compress” : “true”,  
“location” : “/mnt/elastic/es-backup”  
}  
}  
}

The restore command?  
curl -XPOST “[http://localhost:9200/\_snapshot/esrestore/linuxpoint\_snapshot/\_restore?wait\_for\_completion=true](http://localhost:9200/_snapshot/esrestore/linuxpoint_snapshot/_restore?wait_for_completion=true)”

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 23, 2021, 5:43pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/2 "2021-03-23T17:43:06Z")

</div>

Bump, I’m still hoping for validation I’m not about to destroy my existing logs.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [March 24, 2021, 1:00am UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/3 "2021-03-24T01:00:10Z")

</div>

Hello,  
Just to touch base with you. I personally have not migrating from Graylog 3.2.x to 4.x. I’ve always upgraded my server/s.

Since our server/s are virtual machine’s we can create a checkpoint incase things go wrong.  
I am in the process of migrating my graylog server to a different OS but not yet. I’m actually waiting to see what happens with your environment 🙂

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 25, 2021, 8:26pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/4 "2021-03-25T20:26:24Z")

</div>

Not exactly what I was hoping to hear 🙄

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aaronsachs/32/7180_2.png) [@aaronsachs](https://community.graylog.org/u/aaronsachs)\
**Post date:** [March 25, 2021, 8:34pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/5 "2021-03-25T20:34:06Z")

</div>

Hmmmm…I’ve not done a restore from a snapshot before, but I think you may be able to avoid overwriting existing data by renaming the indices on restore (see [Restore a snapshot | Elasticsearch Reference [7.10] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/snapshots-restore-snapshot.html)). They’d be under a different index, but should still be present and available search if I’m reading their docs correctly.

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 25, 2021, 9:27pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/6 "2021-03-25T21:27:02Z")

</div>

My thinking was renaming would not be required because of the GUID. But since the default index seems to have a prefix of “graylog” I may be wrong. I guess renaming is the best option since I don’t know. I suppose I’ll do something like a “7” suffix (RHEL7).

“rename\_pattern”: “graylog\_(.+)”,  
“rename\_replacement”: “graylog7\_$1”,

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 25, 2021, 9:28pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/7 "2021-03-25T21:28:32Z")

</div>

There is also a “Restored Archives” index on the new one that says “read only” and it’s empty??

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 26, 2021, 8:32pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/8 "2021-03-26T20:32:58Z")

</div>

My first attempt at a restore was an unmitigated disaster. Had to restore to a 10 hour old backup. It could be I simply had a missing comma in the JSON. The rename commands were totally ignored, and everything went to hell in a Fed-Ex truck very quickly.

curl -XPOST “[http://localhost:9200/](http://localhost:9200/)_snapshot/esrestore/linuxpoint\_snapshot/restore?wait\_for\_completion=false" '{  
“indices”: “graylog\_16,graylog\_17,graylog\_18,graylog\_19,graylog\_20,graylog\_21,graylog\_22,graylog\_23,graylog\_24,graylog\_25”  
“ignore\_unavailable”: true,  
“include\_global\_state”: false,  
“rename\_pattern”: "graylog(.+)",  
“rename\_replacement”: "old\_graylog_$1”  
}’

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 30, 2021, 5:45pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/9 "2021-03-30T17:45:08Z")

</div>

I’ll be making another attempt today. Not only was a comma missing, but more importantly I was missing the -d switch in curl. #eyeroll

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 30, 2021, 9:10pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/10 "2021-03-30T21:10:50Z")

</div>

I have managed a successful data restore into Elastic on the new server. And finally managed to get the indices to be renamed. So at this point the restored indices “old\_graylog\_x” do NOT appear in Graylog at all. The question is how do I go about adding them in Graylog? It has a wizard to create a new index set. But these indices already exist. How do you add them if they are already there? And can they be added read-only?

```
# Restore indices
#!/bin/bash

curl -X POST "http://localhost:9200/_snapshot/esrestore/linuxpoint_snapshot/_restore?wait_for_completion=true&pretty" -H 'Content-Type: application/json' -d'
{
	 "indices": "graylog_16,graylog_17,graylog_18,graylog_19,graylog_20,graylog_21,graylog_22,graylog_23,graylog_24,graylog_25",
	 "ignore_unavailable": "true",
	 "include_global_state": "false",
	 "rename_pattern": "graylog_(.+)",
	 "rename_replacement": "old_graylog_$1",
	 "include_aliases": false
}
'
```

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [March 30, 2021, 9:34pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/11 "2021-03-30T21:34:39Z")

</div>

BTW, in Googling getting at other indices in Elastic (without the graylog\_ prefix), other Graylog staff have said this is impossible. So now I’m really intrigued what the hell I do. @aaronsachs said they should be available under a different index. But I found other staff members saying you can only have the one prefix. So having old\_graylog as a prefix makes them unreachable. Or is this a capability that has been added since they said that?

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aaronsachs/32/7180_2.png) [@aaronsachs](https://community.graylog.org/u/aaronsachs)\
**Post date:** [April 1, 2021, 6:37pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/12 "2021-04-01T18:37:05Z")

</div>

Hi @mntbighker. Thanks for your patience here–I’ve been out since one of my kiddos had surgery and haven’t been able to reply. Let me test in the lab, and I’ll check back in. AFAIK, this should be doable, but maybe someone like @konrad or @mpfz0r might have a better idea in the intervening time.

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [April 1, 2021, 6:58pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/13 "2021-04-01T18:58:51Z")

</div>

Thanks, the graylog\_xx indices are restored, but I have my concerns that the gl-\* indices that were not restored contain essential metadata for the logs to be added in Graylog. It’s beginning to look like the only supported restore method is supposed to entirely replace the fresh installed indices with identically named ones. Complete with all related indices. It seems like (at least in the past) there was simply no way to add the indices from another Graylog instance to an existing one. Or if it’s possible, you don’t have a method documented anywhere.

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [April 5, 2021, 4:40pm UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/14 "2021-04-05T16:40:46Z")

</div>

Any ideas yet @aaronsachs , @konrad or @mpfz0r ?? What we are talking about here is really the ability to combine multiple Graylog instances. This seems to me like a use case that should be documented somewhere. Recovering from a disaster is a process that, to me anyway, looks markedly different from building a fresh instance to migrate your data to. One is planned, and the other is not.

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [April 9, 2021, 5:08am UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/15 "2021-04-09T05:08:45Z")

</div>

As you can see, we have another thread started on this same topic.

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aaronsachs/32/7180_2.png) [@aaronsachs](https://community.graylog.org/u/aaronsachs)\
**Post date:** [April 10, 2021, 1:30am UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/16 "2021-04-10T01:30:05Z")

</div>

@mntbighker I’ve not forgotten about this–it’s just taken longer than I expect because my normal day-to-day duties have kept me pretty busy. I want to ensure I understand what you’re expecting to see. My read is that you’re expecting to see the renamed Graylog indices (both those prefixed w/ `graylog-` and `gl_`) just show show up in Graylog–is accurate? If so, there’s additional steps that have to happen for an index to show up in Graylog, and those additional steps are what I was unaware of earlier in the post.

I’ll start this this: while an index can be snapshotted and restored to Graylog, Graylog on its own has no concept that the index exists, effectively resulting in it not being visible in the UI. That’s because an _index set_ is required to inform Graylog that the index exists and should be read by Graylog. Graylog’s a bit dumb in this respect.

So let me walk through the test that I set up. I started by doing a pretty standard snapshot:

```auto
curl -X PUT "localhost:9200/_snapshot/my_backup/snapshot_1?wait_for_completion=true&pretty" -H 'Content-Type: application/json' -d '
{
    "indices": "graylog_1",
    "ignore_unavailable": true,
    "include_global_state": false,
    "metadata": {
        "taken_by": "aaron",
        "taken_because": "testing for community issue",
        "date": "2021-04-09"
    }
}
'

```

No issue there.

I then restored the snapshot to another Graylog deployment:

```auto
curl -X POST "192.168.156.181:9200/_snapshot/my_backup/snapshot_1/_restore?pretty" -H 'Content-Type: application/json' -d'
{
  "indices": "graylog_1",
  "ignore_unavailable": true,
  "include_global_state": "false",
  "rename_pattern": "graylog_(.+)",
  "rename_replacement": "test_graylog_$1",
  "include_aliases": false
}
'

```

Again, no issue. I double checked to see that the indices existed in the cluster:

```auto
curl "localhost:9200/_cat/indices?pretty"                                                                                                                                      
green open restored_graylog_1 _5KCzSLnSG6HWVq1KOz8IA 4 0 20000601 0 7gb 7gb
green open test_graylog_1 VKDk6ZQ3Qq6R0Ytnp0G0Ew 4 0 20000601 0 7gb 7gb

```

Excellent–the indices exist, but they’re not showing up in Graylog:

 ![CleanShot 2021-04-09 at 21.00.53@2x](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/7/7e9848088a97af3cf8b51a84c63a7e44e069cf6f.png)

So I created a new index set:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/051d02d5f772a9f4389286a8d6542d6f5ea38359.png)

I’ll note that after saving, I could see the index set, but it didn’t seem to indicate that there was anything there until I clicked on it:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/eb2cbae47e59d3982f1b318710210a05fb5e9740.png)

So the missing piece is indeed the Index Set–did you happen to try adding one for the `graylog_` prefixed indices that you restored to see if that enabled the indices to show up?

---

<div class="post-metadata">

**Author:** ![mntbighker](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mntbighker/32/1441_2.png) [@mntbighker](https://community.graylog.org/u/mntbighker)\
**Post date:** [April 10, 2021, 4:01am UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/17 "2021-04-10T04:01:44Z")

</div>

Ok @aaronsachs, I ceated a new index as you showed, with my restore prefix. For the record I did NOT restore any of the “gl\_” indices. I then looked at Overview with no sign of trouble. Then back to Indices, and bingo, it showed the 10 indices with millions of events. The data was entirely useless, but it kindly informs you to recalculate index ranges. That happened shockingly quickly, and after that all looks good to go. I was able to search from last May to August and up popped the results. I’m still not sure I have a 100% healthy Graylog. There are a few niggling issues remaining as a result of doing the mongo restore presumably. But I would say it’s 98% operational, and collecting logs. And the old data is available to search. In general I think Graylog needs a well documented process for combining Elastic data, which is effectively the same thing as a disaster recovery. That being said, I appreciate the help. I can finally move on to bigger fish waiting to be fried 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [April 24, 2021, 4:01am UTC](https://community.graylog.org/t/elastic-restore-help-please/19161/18 "2021-04-24T04:01:58Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
