Are there any preferences to take snapshots of individual indices or to take snapshots of the whole cluster in Elasticsearch?

Viewed 47

I am trying to understand if in Elasticsearch, there are any advantages to take snapshots of individual indices in comparison to taking snapshots of the whole cluster in terms of performance, hardware usage (CPU/RAM/Disk/Network) and comfortable restoring process of the snapshot in the future. Can anyone describe it to me?

1 Answers

Maybe this answer does not evaluate the two cases from all points of view. But I want to share one point: since it is mentioned in the Elasticsearch documentation that snapshots are taken from segments and snapshots are incrementally taken (only new segments are taken in new snapshots) [1], so it senses that taking a snapshot from n indices should not generally differ from taking n snapshots from each index (I'm not sure about exceptions such as metadata and feature states).

But there might be a limitation in taking a lot of snapshots from individual indices: if number of snapshots increases, memory of the master node and the cluster performance might be affected. It is mentioned in the Elasticsearch documentation where setting a retention for snapshots in configuring SLM is suggested [2].

[1] https://www.elastic.co/guide/en/elasticsearch/reference/current/snapshot-restore.html

[2] https://www.elastic.co/guide/en/elasticsearch/reference/current/snapshots-take-snapshot.html

Related