# How to get size (total) of events send by a host per day

**URL:** <https://discuss.elastic.co/t/how-to-get-size-total-of-events-send-by-a-host-per-day/251912>\
**Category:** Elasticsearch\
**Created:** [October 13, 2020, 1:59pm UTC](https://discuss.elastic.co/t/how-to-get-size-total-of-events-send-by-a-host-per-day/251912 "2020-10-13T13:59:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 13, 2020, 1:59pm UTC](https://discuss.elastic.co/t/how-to-get-size-total-of-events-send-by-a-host-per-day/251912/1 "2020-10-13T13:59:18Z")

</div>

We have been asked different scenarios

1. What is the original size/volume of data send by a particular host?
2. What is the size/volume of data indexed into ES from a particular host

For (1) it is actually the size of the "message"  
My thought was to calculate size per message and then multiply by number of messages per day from the host

Is my understanding correct that the "message" field which comes into ES (if there was no alteration) is the original \_raw data from the client system?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 14, 2020, 2:01pm UTC](https://discuss.elastic.co/t/how-to-get-size-total-of-events-send-by-a-host-per-day/251912/2 "2020-10-14T14:01:41Z")

</div>

I'd may be use the [mapper size plugin](https://www.elastic.co/guide/en/elasticsearch/plugins/7.9/mapper-size.html).

That would give you a raw idea of the size of every document.  
Then if you filter by host and run a `sum` agg to the size field, that'd give you an idea of the size of the related documents.

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 14, 2020, 6:13pm UTC](https://discuss.elastic.co/t/how-to-get-size-total-of-events-send-by-a-host-per-day/251912/3 "2020-10-14T18:13:04Z")

</div>

thanks for that. may be not approved in our installation. Any other methods to find the size of \_source field of already indexed fields?

I tried scrripts (using message.keyword, length) but all in vain

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [October 14, 2020, 6:17pm UTC](https://discuss.elastic.co/t/how-to-get-size-total-of-events-send-by-a-host-per-day/251912/4 "2020-10-14T18:17:41Z")

</div>

how about you do estimate. this is what I do.

run ingestion for a day from A system. after 24 hour I stop that.

go to index management and check the size and document count.  
size/count = your single document size.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2020, 6:17pm UTC](https://discuss.elastic.co/t/how-to-get-size-total-of-events-send-by-a-host-per-day/251912/5 "2020-11-11T18:17:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
