# Guidance on increasing cluster.max\_shards\_per\_node

**URL:** <https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978>\
**Category:** Elasticsearch\
**Created:** [July 13, 2020, 1:38pm UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978 "2020-07-13T13:38:24Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrudrego](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mrudrego](https://discuss.elastic.co/u/mrudrego)\
**Post date:** [July 13, 2020, 1:38pm UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/1 "2020-07-13T13:38:24Z")

</div>

Hi,  
We use Elasticsearch(7.x) to store application/system logs and our indices are time based where new index is created everyday. We have a requirment where different indices are created for every log types and also for every diff application per day. This results in too many indices created everyday and with having retention period of 15 days, this is increasing the default `cluster.max_shards_per_node` value of 1000. Each index is not too big in size( few in gbs/mbs/kbs also)  
Can you please suggest us can we safely exceed this limit by increasing any env parameters like JVM. Any guidance on memory usage based on shards will be very helpful.

Thanks in advance,

---

<div class="post-metadata">

**Author:** ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)\
**Post date:** [July 14, 2020, 4:33am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/2 "2020-07-14T04:33:12Z")

</div>

We run this higher, like 2-3K for the same daily index reason without issues, but does depend on having enough RAM (i.e. don't do it with a 1GB heap), and watching for any issues or circuit breakers. Depends on your loads, queries, etc.

Note you can freeze indexes to save RAM, and we also just close indexes to retain but not use them unless needed, letting us keep months of very rarely-used data (just uses disk space).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 14, 2020, 4:53am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/3 "2020-07-14T04:53:43Z")

</div>

You should move to [ILM](https://www.elastic.co/guide/en/elasticsearch/reference/current/ilm-start.html) to mange this. Otherwise look to use `_shrink` and/or reindex to reduce the index and shard count (eg monthly indices).

Having lots of small shards is a waste of resources, and you will find your nodes will eventually run out of resources to manage them.

---

<div class="post-metadata">

**Author:** ![mrudrego](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mrudrego](https://discuss.elastic.co/u/mrudrego)\
**Post date:** [July 14, 2020, 6:11am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/4 "2020-07-14T06:11:54Z")

</div>

Thanks for the reply Steve and Mark.

We use 2GB jvm for data nodes and 1GB for master nodes.

Mark, we have only one shard per index. Because of the requirement having indices created everyday, i'm afraid we won't be allowed to shrink the indices.

Can you please let us know if there is any high level analogy which we can create about the size of shards to the memory that will be required.  
I did look at a [blog](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster) where they suggest to have 1GB for around 20 Shards (where each shard has around 20 to 40GB data).  
While in our case the shards size is low ☹  
Any help or guidance on the dimensioning would be very much appreciated.

Thanks,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 14, 2020, 6:14am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/5 "2020-07-14T06:14:53Z")

</div>

Move to ILM anyway. Or at least move to monthly indices.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 14, 2020, 6:18am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/6 "2020-07-14T06:18:02Z")

</div>

Having lots of small shards is very inefficient and can cause a large cluster state as well as performance issues in addition to heap pressure. If you have that little heap I would recommend limiting the shard count as outlined in the blog post by revisiting your requirements or add resources to your cluster. These limitations and guidelines are there for a reason. I have numerous times seen users overshard clusters to the point where they can no longer operate or be fixed, resulting in data loss.

---

<div class="post-metadata">

**Author:** ![mrudrego](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mrudrego](https://discuss.elastic.co/u/mrudrego)\
**Post date:** [July 14, 2020, 7:56am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/7 "2020-07-14T07:56:29Z")

</div>

Thanks for the response Christian.

The initial setting of the resource is 2GB for data node. But we are ok to increase the memory 2x or 4x etc . But we just want to know if there is any high level mapping between the memory and shards data in a node.

thanks,

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 14, 2020, 8:16am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/8 "2020-07-14T08:16:38Z")

</div>

As I explained above it is not all about heap usage so I would recommend following the provided guidelines.

---

<div class="post-metadata">

**Author:** ![Steve\_Mushero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steve_mushero/32/22441_2.png) [@Steve\_Mushero](https://discuss.elastic.co/u/Steve_Mushero)\
**Post date:** [July 16, 2020, 6:10am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/9 "2020-07-16T06:10:12Z")

</div>

Agreed - we run a big system this way with dozens of daily indexes and you can't scale it for any length of time beyond a couple of months - much better to use ILM (which wasn't available to us), or at least move to monthly indexes, one per service/type, etc. And we run with 8-16GB Heaps; on 2GB you can't really do any sizable counts - our challenge was modifying all the clients to use an alias or ILM stuff, but bit the bullet and do it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2020, 6:10am UTC](https://discuss.elastic.co/t/guidance-on-increasing-cluster-max-shards-per-node/240978/10 "2020-08-13T06:10:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
