# Inaccurate Cluster total Data in app Monitoring

**URL:** <https://discuss.elastic.co/t/inaccurate-cluster-total-data-in-app-monitoring/375820>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring\
**Created:** [March 13, 2025, 10:42am UTC](https://discuss.elastic.co/t/inaccurate-cluster-total-data-in-app-monitoring/375820 "2025-03-13T10:42:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nicoletta](https://avatars.discourse-cdn.com/v4/letter/n/e9bcb4/32.png) [@Nicoletta](https://discuss.elastic.co/u/Nicoletta)\
**Post date:** [March 13, 2025, 10:42am UTC](https://discuss.elastic.co/t/inaccurate-cluster-total-data-in-app-monitoring/375820/1 "2025-03-13T10:42:45Z")

</div>

Hello,

I noticed that the total Data managed by a cluster (version 7.2) is slighty different than the sum of the store.size of all indexes (including system ones).

I see something like this in the Kibana app Monitoring

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e3bc3ab451d29d135041e16eb2a6690be56d45b2.png)

but if I get all the indexes sizes with

GET \_cat/indices/\*?v=true&s=index&bytes=b

and sum over all indexes I get a different number, something like 51.5TiB (or 56.6TB in SI).

How come?

Thanks,  
Nicoletta

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 13, 2025, 1:12pm UTC](https://discuss.elastic.co/t/inaccurate-cluster-total-data-in-app-monitoring/375820/2 "2025-03-13T13:12:46Z")

</div>

> [@Nicoletta](#):
>
> GET \_cat/indices/\*?v=true&s=index&bytes=b

Does that cover all indices?

See below

```auto
% curl -u $EUSER:$EPASS -skX GET "https://localhost:9200" --request-target "_cat/indices/*?v=true&bytes=b&h=store.size&s=store.size" | awk 'NR>1{sum+=$1}END {printf "%10.2fGB\n",sum/1000000000.0}'
      6.11GB

% curl -u $EUSER:$EPASS -skX GET "https://localhost:9200" --request-target "_cat/indices/*,.*?v=true&bytes=b&h=store.size&s=store.size" | awk 'NR>1{sum+=$1}END {printf "%10.2fGB\n",sum/1000000000.0}'
      6.18GB

```

---

<div class="post-metadata">

**Author:** ![Nicoletta](https://avatars.discourse-cdn.com/v4/letter/n/e9bcb4/32.png) [@Nicoletta](https://discuss.elastic.co/u/Nicoletta)\
**Post date:** [March 13, 2025, 1:40pm UTC](https://discuss.elastic.co/t/inaccurate-cluster-total-data-in-app-monitoring/375820/3 "2025-03-13T13:40:10Z")

</div>

> [@RainTown](#):
>
> `% `

It seems that they are included.

```auto
nicoletta@XXX:~$ curl -u $ES_PRD_US:$ES_PRD_PW -skX GET "http://localhost:9200" --request-target "_cat/indices/*?v=true&bytes=b&h=store.size&s=store.size" | awk 'NR>1{sum+=$1}END {printf "%10.2fGB\n",sum/100000000.0}' && curl -u $ES_PRD_US:$ES_PRD_PW -skX GET "http://localhost:9200" --request-target "_cat/indices/*,.*?v=true&bytes=b&h=store.size&s=store.size" | awk 'NR>1{sum+=$1}END {printf "%10.2fGB\n",sum/100000000.0}'
 568025.64GB
 568032.80GB

```

(I think there's a zero missing somewhere because the total size should be 56TB, but still the two values are pretty the same.)

---

<div class="post-metadata">

**Author:** ![Nicoletta](https://avatars.discourse-cdn.com/v4/letter/n/e9bcb4/32.png) [@Nicoletta](https://discuss.elastic.co/u/Nicoletta)\
**Post date:** [March 13, 2025, 2:01pm UTC](https://discuss.elastic.co/t/inaccurate-cluster-total-data-in-app-monitoring/375820/4 "2025-03-13T14:01:01Z")

</div>

Ok I found why. My bad.

There are closed indices that are counted in the total data managed by the cluster, but since their metadata are not available their size is 0 in the \_cat/indices .

Thanks for you time and support.

Nicoletta

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 13, 2025, 2:03pm UTC](https://discuss.elastic.co/t/inaccurate-cluster-total-data-in-app-monitoring/375820/5 "2025-03-13T14:03:22Z")

</div>

> [@Nicoletta](#):
>
> I think there's a zero missing somewhere

there was, and I edited and fixed it in the reply, case someone cuts and pastes same months from now and is completely misled.
