# Index optimum size Elasticsearch Cluster

**URL:** <https://discuss.elastic.co/t/index-optimum-size-elasticsearch-cluster/132734>\
**Category:** Elasticsearch\
**Created:** [May 22, 2018, 7:23am UTC](https://discuss.elastic.co/t/index-optimum-size-elasticsearch-cluster/132734 "2018-05-22T07:23:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gourmax](https://avatars.discourse-cdn.com/v4/letter/g/eb9ed0/32.png) [@gourmax](https://discuss.elastic.co/u/gourmax)\
**Post date:** [May 22, 2018, 7:23am UTC](https://discuss.elastic.co/t/index-optimum-size-elasticsearch-cluster/132734/1 "2018-05-22T07:23:56Z")

</div>

I'm currently testing to store all kind of data on an elastic cluster. I start to dimension my cluster with a minimal safest configuration 3 nodes and my index with 3 shards and 2 replicas.

It's working fine but I was wondering if it's not too much according to my data right now. I have two kind of data:

- twitter input (from logstash) with a daily index
- time series with a daily index

For twitter (with my keywords) one index is around :

- 13 000 documents
- 26mb of storage size

For time series, one index is around:

- 300 documents
- 500 kb of storage size

I discover on different sources that one shard should not exceeded 1M documents and 50GB, but is there a minimal set also to speed query performance. Should I can use 3 shards - 2 replicas per index even if I have not a lot of data per days ?

I would like to keep the "backup" configuration thanks to replicas, but also have the best performance in query search according to my data size. I think over-dimension will slow my search.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 22, 2018, 7:27am UTC](https://discuss.elastic.co/t/index-optimum-size-elasticsearch-cluster/132734/2 "2018-05-22T07:27:32Z")

</div>

Having 2 replicas for this sort of data may not much a lot of sense unless it's really important.

> [@gourmax](#):
>
> I discover on different sources that one shard should not exceeded 1M documents and 50GB

There's a hard 2 billion doc limit due to lucene. We recommend shards are no bigger than 50GB, but you can go bigger.

---

<div class="post-metadata">

**Author:** ![gourmax](https://avatars.discourse-cdn.com/v4/letter/g/eb9ed0/32.png) [@gourmax](https://discuss.elastic.co/u/gourmax)\
**Post date:** [May 22, 2018, 7:51am UTC](https://discuss.elastic.co/t/index-optimum-size-elasticsearch-cluster/132734/3 "2018-05-22T07:51:03Z")

</div>

Thanks for you reply.

So 1 replica should be enough.  
But according to the "index pattern", what is the best way due to amount of my data per day ?

Is it better to have one index per day even if it is small or one bigger index per month ? according to query performance.  
I will do a lot of query by "value", "date range", and "keywords".

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 22, 2018, 7:52am UTC](https://discuss.elastic.co/t/index-optimum-size-elasticsearch-cluster/132734/4 "2018-05-22T07:52:51Z")

</div>

Given the data volumes you have mentioned I would recommend using monthly indices. For efficiency, you should ideally look to have an average shard size measured in gigabytes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2018, 7:52am UTC](https://discuss.elastic.co/t/index-optimum-size-elasticsearch-cluster/132734/5 "2018-06-19T07:52:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
