# Basic Query for ELK

**URL:** <https://discuss.elastic.co/t/basic-query-for-elk/161921>\
**Category:** Elastic Community and Ecosystem\
**Created:** [December 22, 2018, 4:22pm UTC](https://discuss.elastic.co/t/basic-query-for-elk/161921 "2018-12-22T16:22:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [December 22, 2018, 4:22pm UTC](https://discuss.elastic.co/t/basic-query-for-elk/161921/1 "2018-12-22T16:22:45Z")

</div>

I have some basic queries related to ELK

1. How much CPU and memory is utilized by (filebeat, winlogbeat, metricbeat)beats for shipping logs from client machines ? Can that be controlled in any manner
2. On an average how much disk space would be required to store (logs)data with the retention period of 30 day for 400 servers(300 Windows + 100 Linux). Just need an average idea.

Actually, there is an agreement with my client to keep backup of the system logs.

If there is any document that leads to these queries, please let me know the same.

Thank You

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 29, 2018, 10:47am UTC](https://discuss.elastic.co/t/basic-query-for-elk/161921/2 "2018-12-29T10:47:22Z")

</div>

> [@Yashwant\_Shettigar](#):
>
> How much CPU and memory is utilized by (filebeat, winlogbeat, metricbeat)beats for shipping logs from client machines ? Can that be controlled in any manner

I would say this depends a lot on how much work they have got to do, so your best bet is to test it.

> [@Yashwant\_Shettigar](#):
>
> On an average how much disk space would be required to store (logs)data with the retention period of 30 day for 400 servers(300 Windows + 100 Linux). Just need an average idea.

That will depend on how much data is generated on these servers as well as to what extent you have optimised you index settings and mappings, and as this is something that tend vary a lot from use-case to use-case your best bet is probably to test here as well.

---

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [December 30, 2018, 1:18pm UTC](https://discuss.elastic.co/t/basic-query-for-elk/161921/3 "2018-12-30T13:18:12Z")

</div>

Ok, every system will have its own usages. That's fine

Also, can let me know what are the risks involved using ELK and beats. Like, as we install beat agents on client machine and then data is sent by respective beats. So what is the risk involved in this. Would there be any risk after installing these agents, or when data is being sent in json format.

If these beats would be installed with non-admin users, will the risk be lowered ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 30, 2018, 1:23pm UTC](https://discuss.elastic.co/t/basic-query-for-elk/161921/4 "2018-12-30T13:23:54Z")

</div>

That is unfortunately something I do not think I will be able to help with, but maybe someone else have some inputs.

---

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [December 30, 2018, 2:39pm UTC](https://discuss.elastic.co/t/basic-query-for-elk/161921/5 "2018-12-30T14:39:07Z")

</div>

Is there any link or document, that can help ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 30, 2018, 4:12pm UTC](https://discuss.elastic.co/t/basic-query-for-elk/161921/6 "2018-12-30T16:12:36Z")

</div>

Not that I know of.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 6:48am UTC](https://discuss.elastic.co/t/basic-query-for-elk/161921/7 "2022-11-04T06:48:42Z")

</div>


