How to export your data from Elasticsearch
Elasticsearch data can be exported as CSV via Kibana's reporting feature for small/medium result sets, or pulled in bulk as JSON documents using the Scroll, Point-in-time, or Reindex APIs; for a full cluster backup (data + settings + Kibana objects) use the snapshot and restore feature.
✓ Verified against Elasticsearch's official documentation, September 2026
Step by step
- 1For a quick CSV of query/dashboard results: in Kibana go to Discover or a saved search, open the panel menu and choose 'Generate CSV report', then download it from Stack Management > Reporting once it finishes processing
- 2For bulk/full-size export via API: use the Scroll API (GET /<index>/_search?scroll=1m) or the Point-in-time API (POST /<index>/_pit) with search_after to page through all documents as JSON without timing out
- 3To copy documents into another index or cluster: call the Reindex API (POST _reindex) with a source (index, or a remote cluster with source.remote.host) and a destination index
- 4For a full backup (data plus cluster state, ILM policies, templates, pipelines, and Kibana saved objects): register a snapshot repository (Stack Management > Snapshot and Restore, or the Snapshot Repository API), then take a snapshot
- 5Restore or migrate that snapshot into a new cluster with the Restore API/UI, or use Snapshot Lifecycle Management (SLM) to automate recurring snapshots
- 6If you only need specific indices, limit both scroll/PIT queries and snapshots to those index names to avoid pulling the whole cluster
What the export includes
- ✓Document source (_source) fields for the indices/queries you target, as CSV rows or JSON hits
- ✓For snapshots: full index data, cluster state, index templates, legacy templates, ingest pipelines, ILM policies, stored scripts, and (for snapshots since 7.12) feature states such as Kibana saved objects, Fleet, and security config
What it doesn't include
- ✗Transient cluster settings, registered snapshot repository definitions, node configuration files, and security configuration files are not included in snapshots
- ✗Closed indices are not included in snapshots
- ✗CSV export is capped in practice around 250MB and is not intended as a backup or bulk-export method
- ✗Mappings, settings, shard counts, and replicas are not copied by the Reindex API — the destination must be created and configured beforehand
Before you start
- ⚠Elastic explicitly warns that CSV export is for moderate data volumes only, not bulk export or backup, and risks timeouts/incomplete data above ~250MB, on slow storage tiers, or with unavailable shards
- ⚠Kibana's CSV export uses the Point-in-time API by default; permissions granted only on an alias (not the underlying indices/data streams) will cause it to fail
- ⚠If you switch CSV export to use the Scroll API instead of Point-in-time, search is limited to 500 shards maximum
- ⚠Token expiration errors are common on large CSV reports with SAML/token auth; split into smaller time-ranged reports or use Basic auth
- ⚠Reindexing from a remote cluster requires the remote host to be explicitly allowlisted in reindex.remote.whitelist in elasticsearch.yml
- ⚠Snapshots must be stored in an off-cluster snapshot repository (e.g. S3, GCS, Azure, shared filesystem) that has to be registered before any snapshot or restore can happen
- ⚠On Elastic Cloud Hosted, the default found-snapshots repository and cloud-snapshot-policy SLM policy should not be modified or deleted; cross-cluster snapshot restore is limited to the same region
Where to take your data
Free and cheaper tools that can take a Elasticsearch export. See all Elasticsearch alternatives →
OpenSearch
OpenSearch is a fork of Elasticsearch that supports the same snapshot/restore repository format and a compatible Reindex/Bulk API, so JSON documents pulled via Scroll/PIT or a registered snapshot repository can be bulk-indexed or restored directly into an OpenSearch cluster.
Meilisearch
Convert the exported JSON documents into an array of objects and push them with Meilisearch's add-documents API/bulk import; field mappings and settings (ranking rules, searchable attributes) need to be reconfigured manually since Meilisearch does not read Elasticsearch mappings.
Typesense
Feed the JSON documents from your export into Typesense's /collections/<name>/documents/import bulk endpoint after defining an equivalent collection schema, since Typesense requires an explicit schema rather than Elasticsearch's dynamic mapping.
Exporting from Elasticsearch: common questions
Can I export my Elasticsearch data as CSV?+
Yes, using Kibana's 'Generate CSV report' feature on a saved search or Discover session, but Elastic recommends it only for moderate data volumes (well under 250MB) — for larger exports use the Scroll or Point-in-time API directly.
How do I export ALL documents from a large index without timing out?+
Use the Scroll API or Point-in-time API with search_after to page through results in batches, or use the Reindex API to copy documents into another index/cluster; these bypass the size and timeout limits of Kibana's CSV reporting.
Does an Elasticsearch snapshot include my Kibana dashboards and index settings?+
Yes — snapshots taken after version 7.12 include feature states covering Kibana saved objects, plus cluster state such as index templates, ILM policies, ingest pipelines, and stored scripts, in addition to the raw index data.
What's NOT included in a snapshot?+
Transient cluster settings, the registered snapshot repository definitions themselves, node configuration files, and security configuration files are excluded, as are closed indices.
Do I need a paid Elastic license to export data?+
No — the Scroll, Point-in-time, Reindex, and Snapshot/Restore APIs are core Elasticsearch functionality available on any plan; Kibana's CSV reporting depends on your Kibana/Elastic Stack license having Reporting enabled.
Can I migrate data directly between two Elasticsearch clusters without exporting to a file?+
Yes — the Reindex API supports a remote source (source.remote.host) to copy documents cluster-to-cluster, and snapshot repositories can be shared and restored across clusters (within the same region on Elastic Cloud Hosted).
Sources
This guide was written from Elasticsearch's own documentation and checked against it in September 2026. If a step has changed, the official page wins.
Elasticsearch head-to-head
More Dev Tools tools people are leaving
All Dev Tools alternatives →What would you save without Elasticsearch?
Pick your team size and see the yearly number.