Backup and restore planning
There are two main reasons for backing up your Neo4j databases and storing them in a safe, off-site location:
-
to be able to quickly recover your data in case of failure, for example related to hardware, human error, or natural disaster.
-
to be able to perform routine administrative operations, such as moving a database from one instance to another, upgrading, or reclaiming space.
Backup and restore strategy
Depending on your particular deployment and environment, it is important to design an appropriate backup and restore strategy.
There are various factors to consider when deciding on your strategy, such as:
-
Type of environment – development, test, or production.
-
Data volumes.
-
Number of databases.
-
Available system resources.
-
Downtime tolerance during backup and restore.
-
Demands on Neo4j performance during backup and restore. This factor might lead your decision towards performing these operations during an off-peak period.
-
Tolerance for data loss in case of failure.
-
Tolerance for downtime in case of failure. If you have zero tolerance for downtime and data loss, you might want to consider performing an online or even a scheduled backup.
Starting with Neo4j 2026.02, full and differential backups can be scheduled on independent cadences. Use the differential schedule to drive your recovery point objective (RPO), and the full schedule to drive your recovery time objective (RTO). See Scheduling for RPO and RTO for details.
-
Frequency of updates to the database.
-
Type of backup and restore method (online or offline), which may depend on whether you want to:
-
perform full backups (online or offline).
-
perform differential backups (online only).
-
use SSL/TLS for the backup network communication (online only).
-
keep your databases as archive files (online or offline).
-
-
How many backups you want to keep.
-
Where the backups will be stored — drive or remote server, cloud storage, different data center, different location, etc.
Verify the target directory permissions before running backup or dump command. The backup directory must never be world-readable or world-executable. Even if individual backup files inside are restricted, a world-executable directory can still expose sensitive information.
For details and intructions, refer to Security considerations.
It is recommended to store your database backups on a separate off-site server (drive or remote) from the database files. This ensures that if for some reason your Neo4j DBMS crashes, you will be able to access the backups and perform a restore.
-
How you will test recovery routines, and how often.
Backup and restore options
Neo4j supports backing up and restoring both online and offline databases.
It uses Neo4j Admin tool commands that can be executed on a Neo4j DBMS, whether it is running or offline.
All neo4j-admin commands must be invoked as the neo4j user to ensure the appropriate file permissions.
-
neo4j-admin database backup/restoreEnterprise Edition – used for performing online backup (full and differential) and restore operations.-
The database to be backed up must be in online mode.
-
The command produces an immutable artifact, which has an inspectable API to aid management and operability.
-
This command is suitable for production environments, where you cannot afford downtime.
-
The command can also be invoked over the network if access is enabled using
server.backup.listen_address.Make sure to limit access to the backup server port to fully trusted, specific devices. Firewall policies should be considered. For more information, refer to the Server configurations section.
When using
neo4j-admin database backupin a cluster, it is recommended to back up from an external instance as opposed to reuse instances that form part of the cluster.
-
-
neo4j-admin database dump/load–- used for performing offline dump and load operations.-
The database to be dumped must be in offline mode.
-
The dump command can only be invoked from the server command line and is suitable for environments where downtime is not a factor.
-
The command produces an archive file that follows the format <databasename><timestamp>.dump.
-
-
neo4j-admin database copy–- used for copying an offline database or backup. This command can be used for cleaning up database inconsistencies and reclaiming unused space.
|
File system copy-and-paste of databases is not supported and may result in unwanted behavior, such as corrupt stores. |
The following table summarizes the commands' capabilities and usage.
| Capability/ Usage | backup/restore |
dump/load |
copy |
|---|---|---|---|
Neo4j Edition |
Enterprise |
all |
Enterprise |
Run from an online Neo4j DBMS |
Enterprise Only |
||
Run from an offline Neo4j DBMS |
|||
Run against a user database |
|||
Run against the |
|||
Run against a composite database |
|||
Perform full backups |
n/a |
||
Perform differential backups |
n/a |
||
Applied to an online database |
|||
Applied to an offline database |
only |
||
Can be run remotely |
only |
||
Command input |
database/archive (.backup) |
database/archive (.dump) |
database |
Command output |
archive (.backup)/database |
archive (.dump)/database |
database; no schema store |
Clean up database inconsistencies |
|||
Compact data store |
|
The Neo4j Admin commands |
Considerations for backing up and restoring databases in a cluster
Backing up a database in a clustered environment is not essentially different from a standalone backup, apart from the fact that you must know which server in a cluster to connect to.
Use SHOW DATABASE <database> to learn which servers are hosting the database you want to back up.
See Listing a single database for more information.
Starting from 2025.09, you can use the --remote-address-resolution option to let the DBMS select which servers to use as backup sources.
See Back up an online database → Cluster configurations for more details.
Restoring from the command line involves putting a copy of the database on disk on each server that will need it. That can be awkward to achieve. The recommended way to restore a database in a cluster is to seed from URI.
|
By default, when backing up a database using the When restoring, you have the flexibility to define the target topology (how many primaries and secondaries are desired for the database), which may differ from the topology at backup time. The database will then be allocated across the available servers according to that topology. |
Databases to back up
A Neo4j DBMS can host multiple databases.
Both Neo4j Community and Enterprise Editions have a default user database named neo4j and a system database.
The system database contains configurations, e.g., operational states of databases, security configuration, schema definitions, login credentials, and roles.
In the Enterprise Edition, you can also create multiple user databases. Each of these databases is backed up independently of one another.
It is very important to store a recent backup of your databases, including the system database, in a safe location.
Additional files to back up
The following files must be backed up separately from the databases:
-
The neo4j.conf file. If you have a cluster deployment, you should back up the configuration file for each cluster member.
-
All the files used for encryption, i.e., private key, public certificate, and the contents of the trusted and revoked directories. The locations of these are described in SSL framework. If you have a cluster, you should back up these files for each cluster member.
-
If using custom plugins, make sure that you have the plugins in a safe location.
-
If using Bloom or GDS Enterprise, back up license key files for these products as well.
Storage considerations
For any backup, it is important that you store your data separately from the production system, where there are no common dependencies, and preferably off-site. If you are running Neo4j in the cloud, you may use a different availability zone or even a separate cloud provider. Since backups are kept for a long time, the longevity of archival storage should be considered as part of backup planning.
Glossary
- allocator
-
A component in the cluster that allocates databases to servers according to the topology constraints specified and an allocation strategy.
- asynchronous replication
-
Asynchronous replication is used by secondary copies to poll for new transactions, which means they cannot be guaranteed to have received the most recent transactions. This enables efficient scale-out of read-performance.
- Aura instance
-
A fully-managed DBMS represented by a single instance ID, that is running in the Neo4j Aura cloud.
- auto-commit transaction
-
An automatically committed transaction that contains a single query.
- Bolt protocol
-
Bolt is a protocol used for interaction between Neo4j instances and drivers.
- bookmark
-
A marker the client can request from the cluster to ensure that it is able to read its own writes so that the application’s state is consistent and only databases that have a copy of the bookmark are permitted to respond.
- category (Bloom)
-
A category is based on a node label and is defined in a Perspective as a way of visually distinguishing nodes with the same label(s).
- causal consistency
-
All servers in a cluster agree on the order in which transactions take place. The position of a server on the causal chain can be guaranteed using a bookmark.
- cluster
-
A Neo4j DBMS that spans multiple servers working together to increase fault tolerance and/or read scalability. Databases on a cluster may be configured to replicate across servers in the cluster thus achieving read scalability or high availability.
- client application
-
Software that interacts with a Neo4j server.
- commit
-
A commit is the successful completion of a transaction, which ensures durability of any changes made. For more details, visit Operations Manual → Transaction management.
- composite database
-
Composite databases are the means to access partitioned graph data with a single Cypher query.
- constraint
-
Constraints are sets of data modeling rules that ensure the data is consistent and reliable.
- Cypher®
-
Neo4j’s graph query language.
- data model
-
A data model defines how information is organized in a database. A good data model will make querying and understanding your data easier. In Neo4j, the data models have a graph structure.
- database
-
A database is a container used by the DBMS to manage and store graph data. The physical structure of data is controlled by the database.
- database vs graph
-
Databases are the physical containers of graph data. Graphs are the logical structure of data in Neo4j.
- Database Management System
-
Database Management System, or DBMS, capable of managing multiple databases. A DBMS may run on a single server, or span several servers configured as a cluster.
- database schema
-
The prescribed property existence and datatypes for nodes and relationships.
- deallocate
-
An act of removing a database from a server or a server from a cluster without loss of data or reduced fault tolerance.
- degree (of a node)
-
The number of relationships of a specific node; loops are counted twice.
- disaster recovery
-
A manual intervention to restore availability of a cluster, or databases within a cluster.
- driver
-
A software library that provides access to Neo4j from a particular programming language.
- election
-
In the event that the Raft leader becomes unresponsive, followers automatically trigger an election and vote for a new leader.
- entity
-
A node or a relationship.
- expression (Cypher)
-
A component of a Cypher query which produces values. It may be used in projections, as a predicate, or when setting properties on graph elements.
- fabric
-
Fabric is the architectural design of a unified system that provides a single access point to local or distributed graph data.
- fault tolerance
-
A guarantee that a cluster can maintain a database’s persistence and availability in the event of one or more servers failing.
- follower
-
A primary copy of a database acting as a follower, receives and acknowledges synchronous writes from the leader.
- Generative AI (GenAI)
-
A type of artificial intelligence (AI) system that generates text, images, or other media in response to prompts.
- graph
-
A logical representation of a set of nodes where some pairs are connected by relationships.
- index
-
Data structure that improves read performance of a database.
- knowledge graph
-
A specific type of graph that has an organizing principle so that a user (or a computer system) can reason about the underlying data. The organizing principle provides an additional layer of structure that adds context to support knowledge discovery.
- label
-
Marks a node as a member of a named and indexed subset. A node may be assigned zero or more labels.
- leader
-
A single primary copy of a database is designated as the leader. It receives all write transactions from clients and replicates writes synchronously to followers and asynchronously to secondary copies of the database.
- main database
-
In terms of Neo4j Enterprise Studio, the database(s) containing the user’s data. Can exist in the same Neo4j deployment as the tool asset database.
- motif
-
A description of a specific pattern within a graph.
- node
-
A node represents an entity or discrete object in your graph data model. Nodes can be connected by relationships, hold data in properties, and are classified by labels.
- operator
-
A symbol representing a mathematical or logical operation.
- parameter
-
Named value provided when running a Cypher statement.
- path
-
A sequence of nodes and the relationships connecting them, that does not contain duplicate relationships. Several paths can match a pattern.
- pattern
-
A specific arrangement of nodes and relationships that can be matched in a graph. A pattern follows a motif.
- perspective (Bloom)
-
A Perspective defines a certain business view or domain that can be found in the target Neo4j graph. A single Neo4j graph can be viewed through different Perspectives, each tailored for a different business purpose.
- primary
-
A copy of the database that is able to process write transactions and is eligible to be elected as a leader. It participates in fault tolerant writes as it is part of the majority required to acknowledge and commit write transactions.
- primary vs secondary
-
In a cluster, databases can operate in either primary or secondary mode. Primary databases are able to process write and read transactions, ensuring fault tolerance. Secondary databases are replicated asynchronously from primaries, and their main purpose is to provide read scaling within the cluster.
- project (Aura)
-
An isolated environment in the unified Aura console that contains its own database instances, configurations, and resources. Preceded by tenant in the classic Aura console.
- property
-
Properties are key-value pairs that are used for storing data on nodes and relationships.
- query (Cypher)
-
A statement that retrieves or writes information to a database.
- Raft group
-
A group of servers that are participating in hosting a particular database in primary mode.
- Raft group member
-
A server that is participating in a Raft group. A server can be a member of one or more groups.
- Raft log
-
A shared log between all Raft group members that is guaranteed to be consistently updated and viewed by those members. The log contains both database data and operational state of the Raft group.
- Raft protocol
-
The networking mechanism that enables a database to replicate its data across multiple servers to give high availability for accessing the data and high durability to the data stored.
- read scaling
-
Distributing query load by creating additional database copies hosted in secondary mode (read-only).
- relationship
-
A relationship represents a connection between nodes in your graph data model. Relationships connect a source node to a target node, hold data in properties, and are classified by type.
- secondary
-
An asynchronously replicated copy of the database that provides read scaling within the cluster.
- seed
-
A seed is a database dump or a full backup used to create a database on a cluster. This is sometimes called seeding.
- server
-
A physical machine, a virtual machine, or a container running an instance of Neo4j. Servers can be standalone or part of a cluster.
- session
-
A causally linked sequence of transactions.
- session consistency
-
An alternative name for Neo4j’s causal consistency.
- standalone
-
A single server running Neo4j and not part of a cluster.
- synchronous replication
-
Synchronous replication requires the leader primary to replicate a transaction and block the commit until a quorum of the follower primaries acknowledges that the transaction is successfully replicated. Once the transaction is replicated, the commit is allowed to proceed. This ensures data durability and consistency within the cluster.
- system database
-
A database used by Neo4j to store system information.
- tenant (Aura)
-
An isolated environment in the classic Aura console that contains its own database instances, configurations, and resources. Replaced by project in the unified Aura console.
- tool asset database
-
In terms of Neo4j Enterprise Studio, the database where tools' assets are stored. This can be in the same Neo4j deployment as the main database(s) or in a separate deployment.
- topology
-
A configuration that describes how the copies of a database should be spread across the servers in a cluster, see primary mode and secondary mode.
- transaction
-
A transaction comprises a unit of work performed against a database. It is treated in a coherent and reliable way, independent of other transactions. Transactions comply with the ACID consistency model (atomic, consistent, isolated, and durable).