# Migrate one graylog to another graylog

**URL:** <https://community.graylog.org/t/migrate-one-graylog-to-another-graylog/20908>\
**Category:** Graylog Central (peer support)\
**Created:** [August 16, 2021, 8:28am UTC](https://community.graylog.org/t/migrate-one-graylog-to-another-graylog/20908 "2021-08-16T08:28:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![syntax](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@syntax](https://community.graylog.org/u/syntax)\
**Post date:** [August 16, 2021, 8:28am UTC](https://community.graylog.org/t/migrate-one-graylog-to-another-graylog/20908/1 "2021-08-16T08:28:47Z")

</div>

Hi,

Is it possible to migrate an elasticsearch index from one graylog to another graylog server?

I don’t need to migrate the entire graylog. Just a particular elasticsearch index.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [August 16, 2021, 9:34pm UTC](https://community.graylog.org/t/migrate-one-graylog-to-another-graylog/20908/2 "2021-08-16T21:34:21Z")

</div>

Hello @syntax

Yes this is posibible. I performed this on one of my CentOS 7 server and migrated to Ubuntu 20.0.4.

> **[Snapshot and restore | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/snapshot-restore.html)**

It was actually simple just like a MySQL Dump.  
One issue I did run into was when I started the restore proccess.  
If this error occurs check index your indice

> ERROR [IndexRotationThread] Couldn’t point deflector to a new index  
> java.lang.IllegalArgumentException: [alias] is unsupported for [REMOVE\_INDEX]

`curl -XGET 'http://localhost:9200/_cat/indices?pretty=true'`

I belive this was due from my restore index had the same name as my index on the new node. Since this was a new Graylog Server I just deleted the index on the new node and executed the restore process.  
Hope that helps

---

<div class="post-metadata">

**Author:** ![syntax](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@syntax](https://community.graylog.org/u/syntax)\
**Post date:** [August 17, 2021, 5:58am UTC](https://community.graylog.org/t/migrate-one-graylog-to-another-graylog/20908/3 "2021-08-17T05:58:38Z")

</div>

hi gsmith. thanks for the reply once again.

a few questions,

1. how does graylog detect the restored index?
2. does this process work for multi-node setup?

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [August 17, 2021, 9:36pm UTC](https://community.graylog.org/t/migrate-one-graylog-to-another-graylog/20908/4 "2021-08-17T21:36:42Z")

</div>

Hello,

> [@syntax](#):
>
> 1. how does graylog detect the restored index?

Only thing I did with Graylog is restart the service, so yes. Dont have indices with the same name when you do a restore and your good.  
Have a look here on that subject, @aaronsachs explains this procedure well.

> [@Elastic Restore Help Please](https://community.graylog.org/t/elastic-restore-help-please/19161/16):
>
> @mntbighker I’ve not forgotten about this–it’s just taken longer than I expect because my normal day-to-day duties have kept me pretty busy. I want to ensure I understand what you’re expecting to see. My read is that you’re expecting to see the renamed Graylog indices (both those prefixed w/ graylog- and gl\_) just show show up in Graylog–is accurate? If so, there’s additional steps that have to happen for an index to show up in Graylog, and those additional steps are what I was unaware of earlie…

As for

> [@syntax](#):
>
> 1. does this process work for multi-node setup?

To be honest, I have not done this on a multi node setup yet. I would image it can be done. If you have a cluster this could be dupicated on each ES node. All I used was `scp` command to migrate my indices to another node and performed a restore.

NOTE: Make sure the vsersion of Elasticsearch is the same before you do a restore or you might run into trouble.  
Hope that helps

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aaronsachs/32/7180_2.png) [@aaronsachs](https://community.graylog.org/u/aaronsachs)\
**Post date:** [August 17, 2021, 10:13pm UTC](https://community.graylog.org/t/migrate-one-graylog-to-another-graylog/20908/5 "2021-08-17T22:13:35Z")

</div>

For the multi-node question, a snapshot/restore works for a single-node or multi-node deployment since this is done through the API.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 31, 2021, 10:14pm UTC](https://community.graylog.org/t/migrate-one-graylog-to-another-graylog/20908/6 "2021-08-31T22:14:13Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
