# 24:1 ratio

**URL:** <https://discuss.elastic.co/t/24-1-ratio/140081>\
**Category:** Elasticsearch\
**Created:** [July 16, 2018, 6:06am UTC](https://discuss.elastic.co/t/24-1-ratio/140081 "2018-07-16T06:06:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![safhw91](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@safhw91](https://discuss.elastic.co/u/safhw91)\
**Post date:** [July 16, 2018, 6:06am UTC](https://discuss.elastic.co/t/24-1-ratio/140081/1 "2018-07-16T06:06:35Z")

</div>

Hi!

Simple question: is the recommended 24:1 disk:memory ratio using the entire machine's memory or just the memory allocated to Elastic's JVM?

E.g. I have a 64GB machine and 30GB is for Elastic (rest for Lucene), does my memory count as 64GB or 30GB?

Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 16, 2018, 6:07am UTC](https://discuss.elastic.co/t/24-1-ratio/140081/2 "2018-07-16T06:07:39Z")

</div>

When we use disk to RAM ratios we typically base this on the RAM the node has available, which includes the heap as well as the file system cache. This also usually assumes that the heap is assigned 50% of the RAM the nodes has available.

The ideal ratio can however vary a lot depending on use case. What is the use case? Where does this recommendation come from?

---

<div class="post-metadata">

**Author:** ![safhw91](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@safhw91](https://discuss.elastic.co/u/safhw91)\
**Post date:** [July 16, 2018, 6:20am UTC](https://discuss.elastic.co/t/24-1-ratio/140081/3 "2018-07-16T06:20:01Z")

</div>

Thank you!

My use case:  
Using logstash as a log parser (static logs which I keep on disk and then manually parse).  
200+ folders  
2000+ files in the folders  
Each file ranges from few hundred MB to few GB  
Each line in file, when matching the grok regex, has typically only ~2-5 fields stored (each field max 10-40 chars)  
Each folder occupies 1 index, so 200+ indexes  
Total folder size ~300 GB currently, and increasing  
64 GB RAM, 30GB to Elastic (default 1GB to logstash since disk util is at 100% already, so don't think increasing it helps)  
Elastic on HDD, Logstash parsing done on SSD  
Very few queries currently (even in the future will not be much), mainly indexing at this point (manually running logstash on each folder)  
Disk usage on HDD is 0-1%, Disk usage on SSD is 100%  
Logstash and Elastic on the same machine, although I'm planning to add another machine running Logstash as well (so 2 Logstash to 1 Elastic)

Sorry just rambling here, but maybe you can find a few holes in this config 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2018, 6:31am UTC](https://discuss.elastic.co/t/24-1-ratio/140081/4 "2018-08-13T06:31:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
