# How to limit amount of incoming data

**URL:** <https://discuss.elastic.co/t/how-to-limit-amount-of-incoming-data/68683>\
**Category:** Elasticsearch\
**Created:** [December 12, 2016, 9:20am UTC](https://discuss.elastic.co/t/how-to-limit-amount-of-incoming-data/68683 "2016-12-12T09:20:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![caecilie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/caecilie/32/12472_2.png) [@caecilie](https://discuss.elastic.co/u/caecilie)\
**Post date:** [December 12, 2016, 9:20am UTC](https://discuss.elastic.co/t/how-to-limit-amount-of-incoming-data/68683/1 "2016-12-12T09:20:37Z")

</div>

To collect and analyze our logfiles from 15 server we use elasticsearch 2.4.2, logstash 2.4.0, kibana 4.6.1 and filebeat and everything works fine. In normal case the size of our daily indexes is about 1GB.  
Last week, the size of the daily log was many times higher than the normal case on 6 server (30-40GB on each server). As a result the cluster state changes to red, because there was no disk space.  
Is it possible to prevent such a case? It was a really unexpected behaviour.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 13, 2016, 3:17am UTC](https://discuss.elastic.co/t/how-to-limit-amount-of-incoming-data/68683/2 "2016-12-13T03:17:55Z")

</div>

There's currently no way to do this.

Are you monitoring your disk space on each of the nodes?

---

<div class="post-metadata">

**Author:** ![caecilie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/caecilie/32/12472_2.png) [@caecilie](https://discuss.elastic.co/u/caecilie)\
**Post date:** [December 15, 2016, 8:54am UTC](https://discuss.elastic.co/t/how-to-limit-amount-of-incoming-data/68683/3 "2016-12-15T08:54:52Z")

</div>

Thanks, you have confirmed my intuition.  
Yes we are monitoring disk space on our nodes.  
Same problem yesterday  
My actual workaround: check cluster state or monitoring result in the morning, if red delete the "monster" index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2017, 8:55am UTC](https://discuss.elastic.co/t/how-to-limit-amount-of-incoming-data/68683/4 "2017-01-12T08:55:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
