# Huge logs - how Tuning filebeat

**URL:** <https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 19, 2023, 7:04pm UTC](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333 "2023-04-19T19:04:43Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![pepite](https://avatars.discourse-cdn.com/v4/letter/p/b487fb/32.png) [@pepite](https://discuss.elastic.co/u/pepite)\
**Post date:** [April 28, 2023, 12:58pm UTC](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333/6 "2023-04-28T12:58:35Z")

</div>

> [@warkolm](#):
>
> Why's that? You aren't storing additional data are you?

Hi,

No only my indices 😉

> [@warkolm](#):
>
> Yes, that's a requirement for shrink.

I will test 😉  
The old indices when shrinking is deleted automatically ?

I would like to shrink only one index and reallocate this one on dedicated WARM node with custom attiribute, but for the moment i can't apply index template 😉

> [@Index template - exclude index seems not working](https://discuss.elastic.co/t/index-template-exclude-index-seems-not-working/331060):
>
> Hi everybody. I dont find the correct syntax to exclude one index of an index pattern in index template 2 index template slight_smile 1st { "order": 0, "index\_patterns": ["\*\_\*","-tdir\_business\_prod-\*"], "settings": { "index.lifecycle.name": "Hot\_toWarm\_toCold\_policy", "index.refresh\_interval": "60s", "index.number\_of\_shards": 1, "index.number\_of\_replicas": 1 } } 2nd { "order": 1, "index\_patterns": ["tdir\_business\_prod-\*"], "settings": { "index.lifec…

---

_[View the full topic](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333)._
