I did a query at my elastic nodes today.
curl -X GET "http://$IP:9200/_cat/indices?v"
I did see that i have some index that are 80-90Gb and some are smaller.
Is that normal or do i have some wrong settings ?
Does the big index impact on search from graylog/kibana ?
I have a Rotation period for 1day and Max number of indices set to 60 so i could have log for 60days and Max. number of segments set to 1 and shards to 4