# How is log storage working?

**URL:** <https://discuss.elastic.co/t/how-is-log-storage-working/913>\
**Category:** Logstash\
**Created:** [May 19, 2015, 4:05pm UTC](https://discuss.elastic.co/t/how-is-log-storage-working/913 "2015-05-19T16:05:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yzord](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yzord/32/44824_2.png) [@Yzord](https://discuss.elastic.co/u/Yzord)\
**Post date:** [May 19, 2015, 4:05pm UTC](https://discuss.elastic.co/t/how-is-log-storage-working/913/1 "2015-05-19T16:05:25Z")

</div>

I have an ELK server where all my other (50+) servers are sending their logs to it. It's a virtual machine and i gave it at first 60GB of storage which i divided.

I monitor this server and i received a warning that my harddisk space is running out of space. The ELK server runs for 3 weeks now so it is using a lot of space to store the logs.

I would like to understand how the storage is working. I know it makes an index of all the logs, but does it also (g)zips the logs?

I would like to have the logs for at least 6 months and after that the oldest ones can be deleted. How is ELK working with these kind of settings?

Can anyone give me some idea about this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 19, 2015, 5:15pm UTC](https://discuss.elastic.co/t/how-is-log-storage-working/913/2 "2015-05-19T17:15:50Z")

</div>

The relation between the size of the data being indexed and how much space it takes up on disk will depend a lot on the mappings you use. The default Logstash config indexes most fields both as analyzed and not\_analyzed which adds a lot of flexibility when you query it, but tends to take up a fair bit of space on disk. You can save a significant amount of disk space by optimising how you store data and map it. We published a [blog post.](https://www.elastic.co/blog/elasticsearch-storage-the-true-story) last month which shows the effect eliminating certain fields and rationalising mappings can have on the size for typical logging use cases.

Best regards,

Christian

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/how-is-log-storage-working/913/3 "2017-07-06T05:39:40Z")

</div>


