# Last 12 hours indexing size elasticsearch

**URL:** <https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994>\
**Category:** Elasticsearch\
**Created:** [June 23, 2019, 8:24am UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994 "2019-06-23T08:24:10Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [June 23, 2019, 8:24am UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/1 "2019-06-23T08:24:11Z")

</div>

Hi,  
How do i get the total size of data received at my elasticsearch cluster for last 12 hours?

**\_stats** API give total size of the cluster, but i need to filter out for only last 12 hours data received by elasticsearch  
what is the query,or any specific API?

Help needed.

Regards,  
Ramya

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 23, 2019, 9:21am UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/2 "2019-06-23T09:21:01Z")

</div>

If you are looking for the size in bytes, it's not really doable unless you added previously the mapper size plugin.  
If you are using time based indices you can may be try to guess what was the size for the last 2 days using index stats API.  
Another basic solution would be to compute the average size of a typical document, count the number of documents during the period you want and multiply by this average size.

---

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [June 23, 2019, 10:23am UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/3 "2019-06-23T10:23:19Z")

</div>

@dadoonet  
How to do this

> If you are using time based indices you can may be try to guess what was the size for the last 2 days using index stats API.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 23, 2019, 11:24am UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/4 "2019-06-23T11:24:46Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/7.1/indices-stats.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/indices-stats.html)

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 23, 2019, 12:49pm UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/5 "2019-06-23T12:49:06Z")

</div>

Hi @RamyaGowda Ramya  
or you can determine size of daily indices if you have. And try to guess size of last 12 hour.

Switch for bytes:

```
bytes=b

```

ES Query

```
GET /_cat/indices/itles-sec*?v&bytes=b&h=index,store.size&s=store.size:asc

```

output:

```
index store.size
itles-sec-2019.06.23 33776464751
....
```

---

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [June 23, 2019, 1:59pm UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/6 "2019-06-23T13:59:18Z")

</div>

@vasek Hi Vasek,

how could we guess how much data we recived for last 12 hours? it is a huge data that we are receiving.  
Is there any filters can i apply on timestamp

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 23, 2019, 2:07pm UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/7 "2019-06-23T14:07:40Z")

</div>

I was thinking in a simple way.

```auto
33776464751 per day = per 24 hours
33776464751 / 2 = 16888232375.5

```

**But I point out that it is not accurate but it is very fast**.

Of course you can use this approach If amount of received data is the same between 0-12 and 12-24.

---

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [June 23, 2019, 2:34pm UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/8 "2019-06-23T14:34:06Z")

</div>

@vasek  
Thank you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2019, 2:34pm UTC](https://discuss.elastic.co/t/last-12-hours-indexing-size-elasticsearch/186994/9 "2019-07-21T14:34:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
