# Index size questions

**URL:** <https://discuss.elastic.co/t/index-size-questions/99045>\
**Category:** Elasticsearch\
**Created:** [August 31, 2017, 8:03pm UTC](https://discuss.elastic.co/t/index-size-questions/99045 "2017-08-31T20:03:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hburnswell](https://avatars.discourse-cdn.com/v4/letter/h/9e8a1a/32.png) [@hburnswell](https://discuss.elastic.co/u/hburnswell)\
**Post date:** [August 31, 2017, 8:03pm UTC](https://discuss.elastic.co/t/index-size-questions/99045/1 "2017-08-31T20:03:46Z")

</div>

All,

I am getting up to speed with the ELK stack in general and am curious about what I should expect for index sizing. I have a 3 node ES cluster and plan to use: 3 shards and 2 replicas for each index.

My first test is to ingest IIS data ( which if you are a regular to discuss.elastic you may have already read in other sections 😉 ) into ES. Using Filebeat -\> Logstash -\> ES, I am looking to ingest about the last 2 months worth of logs from our IIS log directory (using ignore\_older) that contains daily files dating back to Jan 2016. Each IIS log is about 250MB so, I guess my math is:

> Initial ingestion:
> 
> 250MB x 60 days = 15,000MB = 15G
> 
> With 3 shards, 2 replicas = ~45GB per node

1. Is this a reasonable assumption or is there other 'overhead' that will cause for more disk consumption?
2. Is creating a single index the same as creating multiple indices (say daily with an added date to index name) disk space wise?

Any guidance is greatly appreciated.

Thanks,

HB

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 31, 2017, 8:07pm UTC](https://discuss.elastic.co/t/index-size-questions/99045/2 "2017-08-31T20:07:37Z")

</div>

The size the data will take up on disk will depend on your mappings and how you enrich your data, as described in [this blog post](https://www.elastic.co/blog/filebeat-modiles-access-logs-and-elasticsearch-storage-requirements).

---

<div class="post-metadata">

**Author:** ![hburnswell](https://avatars.discourse-cdn.com/v4/letter/h/9e8a1a/32.png) [@hburnswell](https://discuss.elastic.co/u/hburnswell)\
**Post date:** [August 31, 2017, 9:38pm UTC](https://discuss.elastic.co/t/index-size-questions/99045/3 "2017-08-31T21:38:35Z")

</div>

Christian - Thank you very much, I will read your post..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2017, 9:38pm UTC](https://discuss.elastic.co/t/index-size-questions/99045/4 "2017-09-28T21:38:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
