# Elasticsearch: Cold Nodes

**URL:** <https://discuss.elastic.co/t/elasticsearch-cold-nodes/190125>\
**Category:** Elasticsearch\
**Created:** [July 12, 2019, 1:43am UTC](https://discuss.elastic.co/t/elasticsearch-cold-nodes/190125 "2019-07-12T01:43:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![eightnoteight](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eightnoteight/32/38526_2.png) [@eightnoteight](https://discuss.elastic.co/u/eightnoteight)\
**Post date:** [July 12, 2019, 1:43am UTC](https://discuss.elastic.co/t/elasticsearch-cold-nodes/190125/1 "2019-07-12T01:43:03Z")

</div>

Hi Guys,

We have a set of cold nodes for our logs whose utilisation is very very less, only a few developers send queries to these nodes. but because of our number of days we keep the logs in these cold nodes, the data keeps growing very fast(currently 9TB per node). Since the indexing doesn't happen on these nodes, do you recommend to increase the memory size from 31gb to 45gb, so to avoid constant memory pressure and memory circuit breaking for every request, which essentially is making the node useless.

Thanks

Elasticsearch Version: 6.2.4  
Shards Per Node: 1500  
Data Per Node: 9TB

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 12, 2019, 5:47am UTC](https://discuss.elastic.co/t/elasticsearch-cold-nodes/190125/2 "2019-07-12T05:47:41Z")

</div>

It sounds like you have an average shard size around 6GB, which is quite small. I would recommend you watch [this webinar](https://www.elastic.co/webinars/optimizing-storage-efficiency-in-elasticsearch) and read [this blog post](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster). If you are able to upgrade to version 6.8 you may also want to look into using [frozen indices](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/frozen-indices.html) on these cold nodes. This new feature is also described in [this blog post](https://www.elastic.co/blog/creating-frozen-indices-with-the-elasticsearch-freeze-index-api).

---

<div class="post-metadata">

**Author:** ![eightnoteight](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eightnoteight/32/38526_2.png) [@eightnoteight](https://discuss.elastic.co/u/eightnoteight)\
**Post date:** [July 13, 2019, 3:46pm UTC](https://discuss.elastic.co/t/elasticsearch-cold-nodes/190125/3 "2019-07-13T15:46:25Z")

</div>

but frozen indices seems to be a commercial feature, is there any open source alternative?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 13, 2019, 3:58pm UTC](https://discuss.elastic.co/t/elasticsearch-cold-nodes/190125/4 "2019-07-13T15:58:44Z")

</div>

Frozen indices sound perfect for your use case and although they are not included in the purely open-source distribution they _are_ [included in the basic license](https://www.elastic.co/subscriptions) which is free from cost.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2019, 3:59pm UTC](https://discuss.elastic.co/t/elasticsearch-cold-nodes/190125/5 "2019-08-10T15:59:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
