# Difference between regular induces and logsdb (datastreams)

**URL:** <https://discuss.elastic.co/t/difference-between-regular-induces-and-logsdb-datastreams/379324>\
**Category:** Elasticsearch\
**Created:** [June 19, 2025, 12:59pm UTC](https://discuss.elastic.co/t/difference-between-regular-induces-and-logsdb-datastreams/379324 "2025-06-19T12:59:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![roman.stupko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roman.stupko/32/140267_2.png) [@roman.stupko](https://discuss.elastic.co/u/roman.stupko)\
**Post date:** [June 19, 2025, 12:59pm UTC](https://discuss.elastic.co/t/difference-between-regular-induces-and-logsdb-datastreams/379324/1 "2025-06-19T12:59:21Z")

</div>

Hi,  
I recently decided to move my k8s cluster logs from regular induces to logsdb type of datastreams.  
For my induces now i use:

- dynamic mapping for all string fields to keyword (except message field, which i use for text search)
- ignore event.original field (as it is same to message field)
- default compression codec

Official docs say that logsdb save more space due to new mechanisms and so.  
So i made some tests with my log-generating app. All the logs are same.

So my test results for 1kk logs:

- Regural index with dynamic mapping applied (as it works for me now): 2.52gb
- Logsdb datastream with default settings and mappings: 2.83gb
- Logsdb datastream with my dynamic mappings applied: 1.92gb
- Regural index with dynamic mapping and best\_compression (as in logsdb settings) applied: 1.91gb

Now it seems to me that i don't get any andvantages in using logsdb (which actually gives less flexibility in naming for example).  
So my question is: is there only difference between regular induces and logsdb in default mapping of all fields to keyword and best\_compression?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 19, 2025, 1:46pm UTC](https://discuss.elastic.co/t/difference-between-regular-induces-and-logsdb-datastreams/379324/2 "2025-06-19T13:46:56Z")

</div>

Hello and welcome,

Do you have a license or are using the trial license?

The `logsdb` mode also requires the `synhetic_source`, if you do not have a license or are not using the trial license it will use the normal `_source`, so the saving in space will not be that high.

Also, I think your dataset may be too small to do this comparison and see any savings.

You need to get into tens or hundreds of GB to see differences.

In my experience I had something from 30% to 50% reduction after start using logsdb with synthetic source.

---

<div class="post-metadata">

**Author:** ![roman.stupko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roman.stupko/32/140267_2.png) [@roman.stupko](https://discuss.elastic.co/u/roman.stupko)\
**Post date:** [June 19, 2025, 6:54pm UTC](https://discuss.elastic.co/t/difference-between-regular-induces-and-logsdb-datastreams/379324/3 "2025-06-19T18:54:44Z")

</div>

Thanks for the note about `synthetic_source`. As I checked it does not support dynamic mapping and text search. Is there a way to use text search?

I use opensource Elastic Cloud on Kubernetes v8.17.0 (no licensing).

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 19, 2025, 8:21pm UTC](https://discuss.elastic.co/t/difference-between-regular-induces-and-logsdb-datastreams/379324/4 "2025-06-19T20:21:16Z")

</div>

> [@roman.stupko](#):
>
> As I checked it does not support dynamic mapping and text search. Is there a way to use text search?

Hmmm not sure where you got `text` not supported.

> **[\_source field | Reference](https://www.elastic.co/docs/reference/elasticsearch/mapping-reference/mapping-source-field#synthetic-source-fields-native-list)**
>
> The \_source field contains the original JSON document body that was passed at index time. The \_source field itself is not indexed (and thus is not searchable),...
