# Backup/Restore Security and Audit Indices

**URL:** <https://forum.opensearch.org/t/backup-restore-security-and-audit-indices/7645>\
**Category:** Security\
**Created:** [November 16, 2021, 12:29pm UTC](https://forum.opensearch.org/t/backup-restore-security-and-audit-indices/7645 "2021-11-16T12:29:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![asfoorial](https://avatars.discourse-cdn.com/v4/letter/a/3da27b/32.png) [@asfoorial](https://forum.opensearch.org/u/asfoorial)\
**Post date:** [November 16, 2021, 12:29pm UTC](https://forum.opensearch.org/t/backup-restore-security-and-audit-indices/7645/1 "2021-11-16T12:29:23Z")

</div>

Good day all,

What is the best practice to backup/restore the .opendistro\_security (or its opensearch equivalent) and the security-auditlog indices?

I am currently running ODFE 1.9.

Thanks

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [November 16, 2021, 12:44pm UTC](https://forum.opensearch.org/t/backup-restore-security-and-audit-indices/7645/2 "2021-11-16T12:44:28Z")

</div>

Hello @asfoorial

Check snapshot function in [ODFE](https://opendistro.github.io/for-elasticsearch-docs/docs/elasticsearch/snapshot-restore/#take-and-restore-snapshots) and [Opensearch](https://opensearch.org/docs/latest/opensearch/snapshot-restore/).

---

<div class="post-metadata">

**Author:** ![asfoorial](https://avatars.discourse-cdn.com/v4/letter/a/3da27b/32.png) [@asfoorial](https://forum.opensearch.org/u/asfoorial)\
**Post date:** [November 16, 2021, 1:06pm UTC](https://forum.opensearch.org/t/backup-restore-security-and-audit-indices/7645/3 "2021-11-16T13:06:00Z")

</div>

I tried it against .opensearch\_security index and got permission error when calling the restore API.

So is there a specific process for it?

I was doing this using the admin user.

Regards

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [November 16, 2021, 1:15pm UTC](https://forum.opensearch.org/t/backup-restore-security-and-audit-indices/7645/4 "2021-11-16T13:15:03Z")

</div>

The last section in this document explains how to restore .opendistro\_security index.  
Since this index contains sensitive data, restore must be executed with an admin certificate.  
Admin certificate is not the same as admin user.

> **[Take and Restore Snapshots](https://opendistro.github.io/for-elasticsearch-docs/docs/elasticsearch/snapshot-restore/#security-plugin-considerations)**
>
> Documentation for Open Distro, the community-driven, 100% open source distribution of Elasticsearch OSS with advanced security, alerting, deep performance analysis, and more.
