# Huge size for elastic endpoint (defend) integration indices?

**URL:** <https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344>\
**Category:** Endpoint Security\
**Created:** [February 23, 2023, 3:49pm UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344 "2023-02-23T15:49:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rebug](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rebug/32/117669_2.png) [@rebug](https://discuss.elastic.co/u/rebug)\
**Post date:** [February 23, 2023, 3:49pm UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344/1 "2023-02-23T15:49:23Z")

</div>

Hello,

Cluster information:  
3 nodes with 1TB

I have configured a fleet server with elastic defend integration to start using elastic security.  
Currently only 2 servers are enrolled with the agent. Here is the integrations of the policy that we use:

- Endpoint Security

- Elastic APM

- Auditd Logs

- ModSecurity Audit

- System (desactivated process,network,file)

Everything works fine but I would like to share with you my disk usage for the elastic integration because I think that its huge amount for only **2 servers** enrolled.

 ![Capture d'écran du 2023-02-23 16.45.03](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4d52222ab52d29163fae511a7f7050ed8f954f7a.png)

There is 1 replicas so we are around 25gb for only 2 servers per day with 50gb disk usage.

I have 30 servers to monitor, we are going to use **750GB per day** for process event only ? It is normal ?

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [February 24, 2023, 10:26am UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344/2 "2023-02-24T10:26:14Z")

</div>

It happens 😉 Some processes are particularly noisy and quickly fill out the indexes. It's possible to suppress such events, but it makes blind spots in your data so it's an _opt-out_ for users.  
See details here [Event Filters](https://www.elastic.co/guide/en/security/master/event-filters.html)

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [February 24, 2023, 3:18pm UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344/3 "2023-02-24T15:18:14Z")

</div>

I forgot to mention that since we added the Event Filters, we also started looking closely which events have little value and are curating an out-of-the box filter. This filter can be toogled off by an advanced policy option

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10dc58d382104dc0f0a4ec2ef703c4dbc7f1183a.png)

I hope you don't have it accidentally set to `false`.

---

<div class="post-metadata">

**Author:** ![rebug](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rebug/32/117669_2.png) [@rebug](https://discuss.elastic.co/u/rebug)\
**Post date:** [February 24, 2023, 6:21pm UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344/4 "2023-02-24T18:21:48Z")

</div>

> [@lesio](#):
>
> I hope you don't have it accidentally set to `false`.

Thank you for your reply.  
I can confirm that i have not set the value to false, all advanced settings are default.

I will take a look at the event filter.

If i understand, the event filtered can always be used to trigger alert, but there are not indexed in ES, that right ?

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [February 27, 2023, 9:36am UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344/5 "2023-02-27T09:36:46Z")

</div>

Events filtered out by Endpoint are dropped just before going to the wire so all detections work internally raising appropriate Alerts, moving malware into quarantine, etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2023, 9:37am UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344/6 "2023-03-27T09:37:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
