Elasticsearch快照工作原理及两类场景下的恢复与数据处理疑问
Elasticsearch Snapshot & Recovery Questions: Two Scenarios Explained
Let’s break down your two scenarios clearly, based on how Elasticsearch’s snapshot and recovery system actually works:
Scenario 1: Daily Snapshots + 1-Month Retention, Deleted Document Recovery
Yes, you will not be able to recover the barcelona document once the last snapshot containing it is deleted. Here’s why:
- Elasticsearch snapshots capture the state of your index’s segments at the time the snapshot is taken. When you delete the
barcelonadocument, it’s not immediately removed from the index—instead, it’s marked as deleted and only purged during a segment merge. - Any snapshot taken after you delete the document will not include a recoverable version of
barcelona(since the deleted marker is part of the segment state). The only snapshots that have the document are those taken before the deletion. - Once the last of those pre-deletion snapshots hits the 1-month retention limit and gets deleted, there’s no remaining backup source that contains the
barcelonadocument. You won’t have any way to restore it after that point.
Scenario 2: 3-Month Retention, Cluster Recovery from Old Snapshot
Let’s split this into two parts:
Can you restore the cluster to its 3-month-old state?
Absolutely—if your 3-month-old snapshot includes all the indices that existed in the cluster at that time.
- If only some indices changed: You can restore just the specific indices from the snapshot to revert them to their 3-month-old state. Any unmodified indices (or new indices created after the snapshot) will remain as-is unless you explicitly overwrite them.
- If all indices were deleted: Restoring the entire snapshot will recreate all the indices that existed 3 months ago, with exactly the data they had at that time. The cluster will match the state captured in the snapshot.
Does the recovery process rewrite all data?
No, it doesn’t. Elasticsearch snapshots are segment-based, which makes recovery efficient:
- Instead of reindexing every document, the recovery process directly copies the segment files from the snapshot repository to the cluster’s nodes. These are the same immutable files that Elasticsearch uses to store data.
- The only time you’ll see any "rewriting" is if there’s a need to merge small segments (a regular Elasticsearch operation) or update metadata, but this is minimal and not a full rewrite of all data.
内容的提问来源于stack exchange,提问作者nfdklg
相关产品推荐
相关产品推荐

