What Is a Snapshot?

Also called: Storage snapshot, Point-in-time snapshot

Related problems: Needing a quick way to roll back a server after a bad update; Restoring from full backups takes too long for simple mistakes; Assuming our snapshots are a backup when they live on the same storage; Snapshot storage quietly eating up our disk or cloud bill

A snapshot is a point-in-time image of a storage volume, virtual machine, database or file system, captured almost instantly so you can roll back to that moment or copy data from it. Snapshots are fast to take and restore because most implementations don’t copy all the data at once: they record which data blocks have changed since the snapshot and preserve the originals. That speed makes them useful for quick recovery. Local snapshots that depend on the original storage aren’t a backup on their own; whether a snapshot counts as one depends on where it is kept, how long, how it is protected from deletion and whether restores are tested.

At a glance

  • A snapshot captures the state of data at one moment, typically within seconds, using change tracking rather than a full copy.
  • Snapshots are taken by storage arrays, hypervisors, cloud platforms and some file systems and databases.
  • They are well suited to short-term rollback, such as before patches or changes, and to frequent restore points.
  • Local snapshots share the source’s storage or admin access, so they share its failures; durable, provider-managed snapshots kept independently can count as backups if retention, deletion controls and tested restores support it.
  • Keeping many or old snapshots can consume storage and, on some platforms, affect performance.

What problem it solves

Full backups take time to create and longer to restore. For everyday mistakes, such as a failed software update, an accidentally deleted file or a bad configuration change, waiting hours for a restore is overkill. Snapshots offer a fast undo: take one before a change, and if the change goes wrong, roll back in minutes.

Snapshots also help backup itself. Backup software often takes a snapshot first, then copies data from the frozen snapshot to backup storage. That lets production keep running while the backup reads a consistent image, and it shortens the window in which backups affect performance.

How it works

Capture. When a snapshot is taken, the system records the state of the volume or virtual machine (VM) at that instant. Common methods either preserve original blocks before they are overwritten or write new data to new locations while keeping the old ones. Either way, extra space is used mainly for changed data.

Consistency. A crash-consistent snapshot captures what is on disk, like a sudden power loss. An application-consistent snapshot coordinates with the operating system or application, such as a database, so pending data is flushed first and the copy restores cleanly.

Restore. You can roll the whole volume back to the snapshot, mount it to pull out individual files, or use it as the source for a new copy or clone.

Schedules and limits. Snapshots can be taken on a schedule, such as hourly, and expired automatically. Platforms often limit how many can exist per volume, and long chains of snapshots can slow some systems.

Making them durable. To protect against storage failure or attack, snapshots are copied to separate storage, a backup service, another site through replication, or locked storage. Some storage systems and cloud services also offer snapshots that are locked against deletion for a set period, similar to immutable backup.

When it matters for buyers

  • When choosing storage or a cloud platform. Snapshot features, limits, locking options and costs differ widely across file systems and object storage and block storage offerings.
  • When reviewing backup design. Check whether “backups” are actually local snapshots on the same storage or account as the source.
  • When planning change windows. Snapshots before patches and upgrades make rollback quicker.
  • When cloud bills grow. Forgotten snapshots are a common source of steadily rising storage charges.

Questions to ask vendors

  • Are your snapshots crash-consistent or application-consistent for the systems we run?
  • Where are snapshots stored, and are they copied off the source storage automatically?
  • Can snapshots be locked against deletion, and can our administrators override the lock?
  • How many snapshots can we keep per volume or VM, and what is the performance impact?
  • How are snapshots billed, and how do we find and remove ones we no longer need?
  • How do snapshots fit into your backup service and its retention settings?

How it differs from backup

A backup is a separate, independent copy of data, stored apart from the original and kept for a defined retention period, so it survives the loss of the source system. A local snapshot is a dependent image on the same storage or under the same admin control as the source, which makes it fast but vulnerable to whatever affects that storage or account, including hardware failure, a deleted volume or an attacker with admin rights. Some providers keep durable, independent snapshots, and whether those count as backups depends on their failure domain, retention, immutability, deletion controls and tested restores. The two work together: snapshots for quick, frequent rollback, and backups, often taken from snapshots, for durable recovery following the 3-2-1 backup rule. Many backup as a service (BaaS) offerings manage both. Our backup as a service overview covers how providers handle snapshots and backup copies.

Frequently Asked Questions

Is a snapshot a backup?
It depends on the snapshot. A local snapshot that shares the source's storage or admin access is not a backup on its own, because a failure, deletion or attack that takes out that storage or account can take the snapshots too. Some providers keep snapshots as durable, independent copies, and those can serve as backups if they sit outside the source's failure domain, are retained long enough, are protected against deletion or locked, and have been restored successfully in tests.
How long should we keep snapshots?
Usually not long. Snapshots are best for short-term rollback, such as before an update or for frequent restore points over a few days. Keeping many or old snapshots can use a lot of storage and, on some platforms, slow down performance. Use backup retention for long-term history.
Do snapshots protect against ransomware?
They can help, depending on how they are protected. Snapshots that an attacker with admin access can delete offer limited protection. Some storage systems and cloud platforms offer locked or immutable snapshots that can't be deleted before a set time, which is much stronger.
Are snapshots application-consistent?
Not always. A basic snapshot is crash-consistent, like pulling the power: data on disk is captured but transactions in memory may not be. Application-consistent snapshots briefly pause or coordinate with the application, such as a database, so it restores cleanly. Ask which type your tool takes.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.