# Local Storage in Elastic/kibana/Logstash VM

**URL:** https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607
**Category:** Elasticsearch
**Created:** [September 16, 2024, 7:19am UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607 "2024-09-16T07:19:28Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![otortosa](https://avatars.discourse-cdn.com/v4/letter/o/90db22/32.png) [@otortosa](https://discuss.elastic.co/u/otortosa)
#### Post date: [September 16, 2024, 7:19am UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607/1 "2024-09-16T07:19:28Z")

</div>

Hello Team,

Im concern about the storage utility in my Elastic/Kibana/Logstash instance, is only 4 months up and 40 fleet agents and already used 500gb, is a normal behaviour?

How can I avoid the high storage utility?

Thanks in advance.  
Kind regards,

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [September 16, 2024, 12:58pm UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607/2 "2024-09-16T12:58:51Z")

</div>

> [@otortosa](#):
>
> is only 4 months up and 40 fleet agents and already used 500gb, is a normal behaviour?

What are the integrations that you are using? The space used depends on the data that's been collected.

Please describe the integrations you are using in your agents.

---

<div class="post-metadata">

### Author: ![otortosa](https://avatars.discourse-cdn.com/v4/letter/o/90db22/32.png) [@otortosa](https://discuss.elastic.co/u/otortosa)
#### Post date: [September 16, 2024, 1:49pm UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607/3 "2024-09-16T13:49:43Z")

</div>

Hello Leandro!

Thanks for the reply.

Find below my current integrations.

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e5a471a9006c1f4d0b3dc2221f9bad9a94c507e3.png)

Kind regards,

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [September 16, 2024, 2:02pm UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607/4 "2024-09-16T14:02:53Z")

</div>

Yeah, but how are your policies organized?

You are running all those integrations in all agents? It does not make much sense.

Do you have one single policy for all agents or do you have multiple policies? It is expected to have multiple policies.

But from what you shared the amount of data seems to be ok, it is basically something around 100 MB per host per day, which is reasonable when you have things like metrics and an xdr (elastic defend) running, both can get a lot of logs.

---

<div class="post-metadata">

### Author: ![otortosa](https://avatars.discourse-cdn.com/v4/letter/o/90db22/32.png) [@otortosa](https://discuss.elastic.co/u/otortosa)
#### Post date: [September 16, 2024, 2:21pm UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607/5 "2024-09-16T14:21:38Z")

</div>

Found the 2 index.

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/9/8/987a894602493da7b089d3ba5a2d996f3a24185a.png)

I understand the system integration due it has 44 hosts, but my windows integration? Only have 7 hosts on it and it is 164Gb.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [September 16, 2024, 3:37pm UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607/6 "2024-09-16T15:37:37Z")

</div>

> [@otortosa](#):
>
> I understand the system integration due it has 44 hosts, but my windows integration? Only have 7 hosts on it and it is 164Gb.

This is a metrics integration, metics can generate a lot of data and it also can vary from server to server.

You may have a noisy server with a lot of things happening that would result in a lot of metrics for the perfmon dataset.

The solution is to check the integration and see if you really need all the metrics that are getting collected.

---

<div class="post-metadata">

### Author: ![otortosa](https://avatars.discourse-cdn.com/v4/letter/o/90db22/32.png) [@otortosa](https://discuss.elastic.co/u/otortosa)
#### Post date: [September 18, 2024, 6:37am UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607/7 "2024-09-18T06:37:37Z")

</div>

Hello Leandro,

Thanks for the reply.  
Will configure Index Lifecycles to avoid the high use of the storage in the VM.  
If I configure to move the index to another VM, will can import again in case to check any log in the future?

Kind regards,
