Make use of Snapshot Backup Restore & Purging of Old Indices

278 views
Skip to first unread message

Khul Sat

unread,
Sep 6, 2024, 12:11:12 AM9/6/24
to Wazuh | Mailing List
Greetings!

I am looking for a solution which would help me achieve following -
  • Local log retention - 90days

  • Older than 90 days but newer than 365 days - S3 bucket

  • Older than 365 days -  Glacier

I checked following two blogs -

It seems to be the blogs are not updated for a latest version. I am currently on Wazuh 4.7.
Please someone guide me in accomplishing this goal.


Thanks,KS

Md. Nazmur Sakib

unread,
Sep 6, 2024, 8:58:19 AM9/6/24
to Wazuh | Mailing List

Khul Sat

unread,
Sep 7, 2024, 2:48:51 AM9/7/24
to Wazuh | Mailing List

Hi Md. Nazmur Sakib,

Thanks for your reply. Few questions I have though -

  1. For ILM, isn’t there a need to make changes in filebeat configuration for policy to get applied to all future indices? I think this part is missing in the document?!?
  2. For Snapshots, if I want to use s3 bucket, what would be the steps? I got some idea from the blog mentioned earlier, but one challenge I suspect w.r.t. short term credentials. Is there anything which can be done?

Regds,KS

Khul Sat

unread,
Sep 11, 2024, 6:59:56 AM9/11/24
to Wazuh | Mailing List
Any comments/suggestions? Please?
Message has been deleted
Message has been deleted

Md. Nazmur Sakib

unread,
Sep 18, 2024, 1:28:45 AM9/18/24
to Wazuh | Mailing List
To use an Amazon S3 bucket as a snapshot repository, install the repository-s3 plugin in your indexer node. We do not have any official document on this but you can follow this document from the Opensearch.

https://opensearch.org/docs/latest/tuning-your-cluster/availability-and-recovery/snapshots/snapshot-restore/#amazon-s3

Let me know if this works for you.
Reply all
Reply to author
Forward
0 new messages