# Document count is same but index size is growing every logstash run

**URL:** <https://discuss.elastic.co/t/document-count-is-same-but-index-size-is-growing-every-logstash-run/198984>\
**Category:** Elasticsearch\
**Created:** [September 10, 2019, 11:23pm UTC](https://discuss.elastic.co/t/document-count-is-same-but-index-size-is-growing-every-logstash-run/198984 "2019-09-10T23:23:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Metehan\_Gulcicek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metehan_gulcicek/32/53952_2.png) [@Metehan\_Gulcicek](https://discuss.elastic.co/u/Metehan_Gulcicek)\
**Post date:** [September 10, 2019, 11:23pm UTC](https://discuss.elastic.co/t/document-count-is-same-but-index-size-is-growing-every-logstash-run/198984/1 "2019-09-10T23:23:15Z")

</div>

```auto
input {
	jdbc {
		jdbc_connection_string => "jdbc:mysql:// ******.rds.amazonaws.com:3306/"
		jdbc_user => "user"
		jdbc_password => "pass"
		jdbc_driver_library => " **** \mysql-connector-java-5.1.46/mysql-connector-java-5.1.46-bin.jar"
		jdbc_driver_class => "com.mysql.jdbc.Driver"
		statement => "SELECT id,title,url FROM tableName"
		schedule => "*/2 * * * *"
	}
}
filter {
  json {
    source => "texts"
    target => "texts"
  }
  mutate { remove_field => ["@version", "@timestamp"] }
}
output {
    stdout {
            codec => json_lines
    }
    amazon_es {
      hosts => [" *****.es.amazonaws.com"]
      document_id => "%{id}"
      index => "texts"
      region => " ****"
      aws_access_key_id => ' *****'
      aws_secret_access_key => ' *****'
  }  
}

```

Here is the logstash.conf file .  
how can I solve this problem? The index size is growing every two minutes.

The first run had 333 documents. The size is approximately 200kb.

Now also the size is 1.6mb  
 ![Ba%C5%9Fl%C4%B1ks%C4%B1z-2](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7bd3080c7e22408cb8d5e2fdfa4ea0fb85517719.jpeg)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 11, 2019, 4:23pm UTC](https://discuss.elastic.co/t/document-count-is-same-but-index-size-is-growing-every-logstash-run/198984/2 "2019-09-11T16:23:04Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.

Here I guess this is because the number of segments has increased a bit.  
You can try to run [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-forcemerge.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-forcemerge.html) if this is really a problem for you.

BTW did you look at [https://www.elastic.co/cloud](https://www.elastic.co/cloud) and [https://aws.amazon.com/marketplace/pp/B01N6YCISK](https://aws.amazon.com/marketplace/pp/B01N6YCISK) ?

Cloud by elastic is one way to have access to all features, all managed by us. Think about what is there yet like Security, Monitoring, Reporting, SQL, Canvas, APM, Logs UI, Infra UI, SIEM, Maps UI and what is coming next 🙂 ...

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 11, 2019, 7:53pm UTC](https://discuss.elastic.co/t/document-count-is-same-but-index-size-is-growing-every-logstash-run/198984/3 "2019-09-11T19:53:01Z")

</div>

Not to answering your question but  
your schedule seems wrong it should be \*/2 \* \* \* \* ( five field)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2019, 7:53pm UTC](https://discuss.elastic.co/t/document-count-is-same-but-index-size-is-growing-every-logstash-run/198984/4 "2019-10-09T19:53:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
