# Data Writing into WARM nodes along with HOT nodes

**URL:** <https://discuss.elastic.co/t/data-writing-into-warm-nodes-along-with-hot-nodes/180444>\
**Category:** Elasticsearch\
**Created:** [May 9, 2019, 9:48pm UTC](https://discuss.elastic.co/t/data-writing-into-warm-nodes-along-with-hot-nodes/180444 "2019-05-09T21:48:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![chandukreddi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandukreddi/32/29241_2.png) [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Post date:** [May 9, 2019, 9:48pm UTC](https://discuss.elastic.co/t/data-writing-into-warm-nodes-along-with-hot-nodes/180444/1 "2019-05-09T21:48:50Z")

</div>

Hello Experts,

I noticed one thing while exploring HOT & WARM Architecture as per below blog.

> **[Elasticsearch Hot Warm Architecture](https://www.elastic.co/blog/hot-warm-architecture-in-elasticsearch-5-x)**
>
> A recommendation for using Elasticsearch 5.x for larger time-data analytics: indices & a tiered architecture with 3 different types of nodes, called “Hot-Warm”.

**This is my node config**

**Node-1**  
"cluster\_name" : "elk-test",  
"nodes" : {  
"szZvzywsRuGCTEzXhLU2-Q" : {  
"name" : "elk-1",  
"transport\_address" : "10.1.28.175:9300",  
"host" : "10.1.28.175",  
"ip" : "10.1.28.175",  
"version" : "6.7.1",  
"build\_flavor" : "oss",  
"build\_type" : "tar",  
"build\_hash" : "2f32220",  
"total\_indexing\_buffer" : 421645516,  
"roles" : [  
"master",  
"data",  
"ingest"  
],  
"attributes" : {  
**"data" : "hot"**  
},  
"settings" : {  
"cluster" : {  
"name" : "elk-test"  
},  
"node" : {  
"attr" : {  
"data" : "hot"  
},  
**"name" : "elk-1"**  
},  
"path" : {  
"data" : [  
"/opt/data/elastic",  
"/home/elk/opt1/data/elastic\_1"  
],  
**Node-2**  
XZlIzGZkSe2BE\_4LKNaOcQ" : {  
"name" : "elk-2",  
"transport\_address" : "10.1.28.176:9300",  
"host" : "10.1.28.176",  
"ip" : "10.1.28.176",  
"version" : "6.7.1",  
"build\_flavor" : "oss",  
"build\_type" : "tar",  
"build\_hash" : "2f32220",  
"total\_indexing\_buffer" : 421645516,  
"roles" : [  
"master",  
"data",  
"ingest"  
],  
"attributes" : {  
**"data" : "warm"**  
},  
"settings" : {  
"cluster" : {  
"name" : "elk-test"  
},  
"node" : {  
"attr" : {  
"data" : "warm"  
},  
**"name" : "elk-2"**  
},  
"path" : {  
"data" : [  
"/opt/data/elastic",  
"/home/elk/opt1/data/elastic\_1"  
],

**My Template:**

[elk@elk2 44SXSucURSKaGSVxmoq1Uw]$ cat /opt/logstash/config/templates/swift\_proxy\_log\_sizing.json  
{  
"template": "swift\_proxy\_logs",  
"index\_patterns": ["swift-proxy-logs-\*"],  
"settings": {  
"index.routing.allocation.require.box\_type": "hot",  
"index.refresh\_interval": "5s",  
"index.codec": "best\_compression",  
"number\_of\_shards": 5,  
"number\_of\_replicas": 0  
},  
"aliases": {  
"swift\_proxy\_log\_write\_alias": {}  
}  
}  
**questions:**

_1. I am writing into HOT node index swift-proxy-logs- which is elk-1 as per my template config but I see data is writing into WARM node as well, anything I am doing wrong here?_\*

**HOT Node: elk-1**  
[root@elk1 44SXSucURSKaGSVxmoq1Uw]# ll  
total 0  
drwxrwxr-x. 5 elk elk 46 May 9 13:05 0  
drwxrwxr-x. 5 elk elk 46 May 9 13:05 2  
drwxrwxr-x. 2 elk elk 23 May 9 13:06 \_state  
[root@elk1 44SXSucURSKaGSVxmoq1Uw]# cd /home/elk/opt1/data/elastic\_1/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw  
[root@elk1 44SXSucURSKaGSVxmoq1Uw]# ll  
total 0  
drwxrwxr-x. 5 elk elk 46 May 9 13:05 4  
drwxrwxr-x. 2 elk elk 23 May 9 13:06 \_state  
[root@elk1 44SXSucURSKaGSVxmoq1Uw]# du -sh /opt/data/elastic/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw;du -sh /home/elk/opt1/data/elastic\_1/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw  
**1.6G** /opt/data/elastic/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw  
**785M** /home/elk/opt1/data/elastic\_1/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw

**WARM Node: elk-2**  
[elk@elk2 44SXSucURSKaGSVxmoq1Uw] ll total 0 drwxrwxr-x. 5 elk elk 46 May 9 13:05 1 drwxrwxr-x. 2 elk elk 23 May 9 13:06 \_state [elk@elk2 44SXSucURSKaGSVxmoq1Uw] cd /home/elk/opt1/data/elastic\_1/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw  
[elk@elk2 44SXSucURSKaGSVxmoq1Uw] ll total 0 drwxrwxr-x. 5 elk elk 46 May 9 13:05 3 drwxrwxr-x. 2 elk elk 23 May 9 13:06 \_state [elk@elk2 44SXSucURSKaGSVxmoq1Uw] du -sh /opt/data/elastic/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw;du -sh /home/elk/opt1/data/elastic\_1/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw  
**785M** /opt/data/elastic/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw  
**785M** /home/elk/opt1/data/elastic\_1/nodes/0/indices/44SXSucURSKaGSVxmoq1Uw

**1. if you add up all the above index shards size its coming around 3 GB but cat index showing only 1.8 GB, why?**  
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
green open swift-proxy-logs-2019.05.09-1 44SXSucURSKaGSVxmoq1Uw 5 0 3357698 0 1.8gb 1.8gb

Thanks  
Chandra

---

<div class="post-metadata">

**Author:** ![chandukreddi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandukreddi/32/29241_2.png) [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Post date:** [May 10, 2019, 1:30pm UTC](https://discuss.elastic.co/t/data-writing-into-warm-nodes-along-with-hot-nodes/180444/2 "2019-05-10T13:30:47Z")

</div>

Just update on my index size - 2nd question.

Now I see index size matching with shard size, may be it was doing compression in the back-end but GET query was giving index size post compression.

Thanks  
Chandra

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2019, 1:41pm UTC](https://discuss.elastic.co/t/data-writing-into-warm-nodes-along-with-hot-nodes/180444/3 "2019-06-07T13:41:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
