# Fit size of filebeat

**URL:** https://discuss.elastic.co/t/fit-size-of-filebeat/266109
**Category:** Beats
**Tags:** filebeat
**Created:** [March 3, 2021, 12:53pm UTC](https://discuss.elastic.co/t/fit-size-of-filebeat/266109 "2021-03-03T12:53:20Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![The\_Guaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/the_guaz/32/79315_2.png) [@The\_Guaz](https://discuss.elastic.co/u/The_Guaz)
#### Post date: [March 3, 2021, 12:53pm UTC](https://discuss.elastic.co/t/fit-size-of-filebeat/266109/1 "2021-03-03T12:53:20Z")

</div>

Hi,

Generally filebeat mapping creating a lot of unused fields in my elasticsearch environment. I wonder, because size of the logs are excessivelly large (around 5-6 GB per day). Can I somehow delete unused mapping from index? Because if this is DB-like, I don't need table where every record contains around thousand nulls. How can I fit it, or it isn't use additional disk space?

Please correct me if I am wrong, but for comparrison, the same logs from the same source in wazuh weight like 8-10 times less.

Thanks in advance for reply and have a good day 🙂

---

<div class="post-metadata">

### Author: ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)
#### Post date: [March 4, 2021, 9:38am UTC](https://discuss.elastic.co/t/fit-size-of-filebeat/266109/2 "2021-03-04T09:38:18Z")

</div>

There is a similar product called Fleet that uses a different model of setting fields. It will configure only those fields that you're using.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 1, 2021, 11:38am UTC](https://discuss.elastic.co/t/fit-size-of-filebeat/266109/3 "2021-04-01T11:38:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
