# Index pattern type in Elasticsearch

**URL:** <https://discuss.elastic.co/t/index-pattern-type-in-elasticsearch/248183>\
**Category:** Elasticsearch\
**Created:** [September 10, 2020, 1:43pm UTC](https://discuss.elastic.co/t/index-pattern-type-in-elasticsearch/248183 "2020-09-10T13:43:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 10, 2020, 1:43pm UTC](https://discuss.elastic.co/t/index-pattern-type-in-elasticsearch/248183/1 "2020-09-10T13:43:48Z")

</div>

HI Team,  
I would like to take some suggestion to create index pattern in ELK.

As per my current configuration in production, i'm index data in ES by monthly index with 1 Primary Shard and 2 replicas.

Due to that i was faced below in ES,

" [Elasticsearch throwing number of documents in the index cannot exceed 2147483519](https://discuss.elastic.co/t/elasticsearch-throwing-number-of-documents-in-the-index-cannot-exceed-2147483519/242512)"

To avoid such issue i would to break monthly into weekly or Day basis.

I need your input which approach is best approach in production.

Looking forward your inputs on this query

---

<div class="post-metadata">

**Author:** ![lzukel](https://avatars.discourse-cdn.com/v4/letter/l/4491bb/32.png) [@lzukel](https://discuss.elastic.co/u/lzukel)\
**Post date:** [September 10, 2020, 2:20pm UTC](https://discuss.elastic.co/t/index-pattern-type-in-elasticsearch/248183/2 "2020-09-10T14:20:40Z")

</div>

There are a lot of factors at play.

1. You could increase the number of primary shards for your index, which would allow you 2^31 documents per primary shard.
2. You could goto a weekly index ~4 times the amount of shards you currently have per month
3. You could goto a daily index ~30 times the amount of shards you currently have per month

Which is best is going to be based on many factors, including but not limited to:  
Your cluster architecture, number of nodes, indexing pressure, read pressure, number of cpus available, amount of heap and ram available, speed of disks... The best approach would be to test, test, and test again.

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 10, 2020, 2:27pm UTC](https://discuss.elastic.co/t/index-pattern-type-in-elasticsearch/248183/3 "2020-09-10T14:27:33Z")

</div>

I have below setup,

3 master node, 3 data node

```
total used free shared buff/cache available
Mem: 65808032 35851440 367148 7704 29589444 29416536
Swap: 2097148 586240 1510908

```

How to increase the shards value in index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2020, 2:27pm UTC](https://discuss.elastic.co/t/index-pattern-type-in-elasticsearch/248183/4 "2020-10-08T14:27:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
