# Investigating high disk usage

**URL:** <https://discuss.elastic.co/t/investigating-high-disk-usage/243992>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [August 6, 2020, 9:26am UTC](https://discuss.elastic.co/t/investigating-high-disk-usage/243992 "2020-08-06T09:26:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gfeher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gfeher/32/73390_2.png) [@gfeher](https://discuss.elastic.co/u/gfeher)\
**Post date:** [August 6, 2020, 9:26am UTC](https://discuss.elastic.co/t/investigating-high-disk-usage/243992/1 "2020-08-06T09:26:03Z")

</div>

I am running Elastic App Search on [https://cloud.elastic.co/](https://cloud.elastic.co/) (GCP). I have about 40000 documents and I have multiple deployments with these same sets of documents. What I have noticed is that the disk usage is very different between these deployments. For example in the deployment that I have been running for months, it is:  
GCP.DATA.HIGHCPU.1 Disk allocation = 13.31 GB  
And in the new deployment, started recently with the same documents, it is:  
GCP.DATA.HIGHCPU.1 Disk allocation = 402 MB  
I do have some small technical differences between these clusters, but they shouldn't justify such a big difference, I guess. My main suspicion is that some sort of logging or automatic snapshotting is taking up all the space.

For example, I know that some of the logs are going into ".app-search-app-logs-loco\_togo\_production\*". Is there a way to check how much space it is taking? I'd also appreciate any other suggestions on how to investigate the disk usage in my Elastic Cloud environment.

Thanks,  
Gabor

---

<div class="post-metadata">

**Author:** ![Carlos\_Redondo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_redondo/32/60914_2.png) [@Carlos\_Redondo](https://discuss.elastic.co/u/Carlos_Redondo)\
**Post date:** [August 11, 2020, 6:43pm UTC](https://discuss.elastic.co/t/investigating-high-disk-usage/243992/2 "2020-08-11T18:43:43Z")

</div>

Very interesting question! I also wondering if AppSearch settings could be adjusted (how and where) to limit the historical information stored.

---

<div class="post-metadata">

**Author:** ![gfeher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gfeher/32/73390_2.png) [@gfeher](https://discuss.elastic.co/u/gfeher)\
**Post date:** [August 11, 2020, 7:05pm UTC](https://discuss.elastic.co/t/investigating-high-disk-usage/243992/3 "2020-08-11T19:05:46Z")

</div>

I am making some progress with this question. It turns out that Kibana contains some management features for Elasticsearch. (It was installed by default in my case.) Inside Kibana, I looked for "Stack Management", created an "Index Lifecycle Policy" and linked it to "ent-search-ecs-logs". (I am using one of those new versions where App Search is called Enterprise Search.) Also under "Stack Management", you can select "Index Management", flip the "Include System Indices" switch and see how much space your indices are currently taking up.

I am still waiting to see if this solution has worked for me or not. I am also quite surprised that the deployments I can create within the Elastic Cloud don't have some sort of sane lifecycle policy to prevent the logs from filling up the disk space over time.

---

<div class="post-metadata">

**Author:** ![Carlos\_Redondo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_redondo/32/60914_2.png) [@Carlos\_Redondo](https://discuss.elastic.co/u/Carlos_Redondo)\
**Post date:** [August 11, 2020, 7:33pm UTC](https://discuss.elastic.co/t/investigating-high-disk-usage/243992/4 "2020-08-11T19:33:08Z")

</div>

I totally agree with you. I'll take a look over the Life Cycle Policy, it sounds like a very promising solution. I'm dealing with performance, trying to get the best response from AppSearch Enterprise Search solution. So far the Query\_Suggestions and Search API's requests are taking ~220ms response, and we want to be under 100ms. So far I have few documents loaded into the Engine, and I'm changing up/down RAM/Zones/Cloud Provider (AWS/Google/Azure) trying to benchmark each deployment and found a good balance between performance and cost.

---

<div class="post-metadata">

**Author:** ![gfeher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gfeher/32/73390_2.png) [@gfeher](https://discuss.elastic.co/u/gfeher)\
**Post date:** [August 11, 2020, 9:09pm UTC](https://discuss.elastic.co/t/investigating-high-disk-usage/243992/5 "2020-08-11T21:09:15Z")

</div>

Cool. Sorry, I don't have any info on response times for you. Maybe you have a better chance of your performance questions answered if you open a separate topic for them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2020, 9:09pm UTC](https://discuss.elastic.co/t/investigating-high-disk-usage/243992/6 "2020-09-08T21:09:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
