# Limiting the amount of data being sent

**URL:** <https://discuss.elastic.co/t/limiting-the-amount-of-data-being-sent/128904>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 20, 2018, 3:18pm UTC](https://discuss.elastic.co/t/limiting-the-amount-of-data-being-sent/128904 "2018-04-20T15:18:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![francisaugusto](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@francisaugusto](https://discuss.elastic.co/u/francisaugusto)\
**Post date:** [April 20, 2018, 3:18pm UTC](https://discuss.elastic.co/t/limiting-the-amount-of-data-being-sent/128904/1 "2018-04-20T15:18:56Z")

</div>

Hi,

I'm concerned about using Filebeat to gather information from multiple laptops running macOS, as some of them might be connected to cellular networks and it is therefore risky that huge logs might imply extra costs for the users.  
Is there a clever way to limit transfers to, say, 100k per hour, or something like that? I thought about limiting the bulk\_max\_size, but again, I don't think that would help, since data will be transferred no matter what as long as the harvester is reading files.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [April 20, 2018, 9:59pm UTC](https://discuss.elastic.co/t/limiting-the-amount-of-data-being-sent/128904/2 "2018-04-20T21:59:02Z")

</div>

There is no configuration option to impose a limit on the bandwidth used or the number of events that filebeat reports.

You can try using system tools (or a 3rd party app) to limit the bandwidth used by the filebeat process.

In macOS it might be possible using the builtin `pf` firewall:  
[https://mop.koeln/blog/2015/06/01/Limiting-bandwidth-on-Mac-OS-X-yosemite/](https://mop.koeln/blog/2015/06/01/Limiting-bandwidth-on-Mac-OS-X-yosemite/)

Also you have a few options to reduce the bandwidth that is used:

- Reduce the number of log sources monitored.
- Use the [max\_bytes](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_literal_max_bytes_literal) setting, to clip large log messages.
- Set a high [compression level](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#_literal_compression_level_literal) in the output.

---

<div class="post-metadata">

**Author:** ![francisaugusto](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@francisaugusto](https://discuss.elastic.co/u/francisaugusto)\
**Post date:** [April 21, 2018, 6:43am UTC](https://discuss.elastic.co/t/limiting-the-amount-of-data-being-sent/128904/3 "2018-04-21T06:43:18Z")

</div>

Thank you Adrian. Unfortunately all the options you mention (except using the OS to reduce bandwidth) are unpredictable in that high amount of data will eventually mean high data transfer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2018, 6:43am UTC](https://discuss.elastic.co/t/limiting-the-amount-of-data-being-sent/128904/4 "2018-05-19T06:43:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
