# LogsDB Without Synthetic \_Source: Storage Savings and Upgrade Risks?

**URL:** <https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858>\
**Category:** Elasticsearch\
**Created:** [January 6, 2025, 3:34pm UTC](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858 "2025-01-06T15:34:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Behnam.R](https://avatars.discourse-cdn.com/v4/letter/b/48db29/32.png) [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Post date:** [January 6, 2025, 3:34pm UTC](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858/1 "2025-01-06T15:34:48Z")

</div>

I am currently on Elasticsearch version 8.16 and considering using the LogsDB index mode for its benefits, particularly the improved querying speed and reduced storage footprint with the new sorting feature (up to 20%, based on the Elastic blog). However, I understand that starting with version 8.17, the **synthetic \_source** feature is only available with an **Enterprise license**.

Since I do not want to risk a sudden increase in log storage size after enabling the logsdb and later upgrading to 8.17 (if we do not have a valid Enterprise license), I want to know:

1. **Is it possible to enable LogsDB mode to take advantage of sorting-based storage savings and faster queries but disable synthetic \_source? (Cause I didn't find any setting for this)**
2. Is there any recommended approach to avoid potential issues when upgrading from 8.16 to 8.17 while using LogsDB, particularly without an Enterprise license?

Thanks in advance for any input

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 6, 2025, 4:19pm UTC](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858/2 "2025-01-06T16:19:28Z")

</div>

> [@Behnam.R](#):
>
> Is it possible to enable LogsDB mode to take advantage of sorting-based storage savings and faster queries but disable synthetic \_source? (Cause I didn't find any setting for this)

Yes, you can use `logsdb` without `synthetic_source`, I don't think that a specific setting exists, it will use `synthetic_source` if you have an enterprise license and the normal `_source` if you don't.

At least this is what is mentioned [here in the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/logs-data-stream.html#logsdb-synthetic-source).

> If you don’t have the required subscription, logsdb mode uses the original \_source field.

---

<div class="post-metadata">

**Author:** ![Behnam.R](https://avatars.discourse-cdn.com/v4/letter/b/48db29/32.png) [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Post date:** [January 6, 2025, 4:46pm UTC](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858/3 "2025-01-06T16:46:29Z")

</div>

@leandrojmp Thanks for the fast reply. This is something that I am concerned about. Using the `logsdb` index mode, I will benefit from the `synthetic_source` feature in my Elastic cluster (version 8.16) if there is no setting to disable this, which, together with smart sorting, provides around 50-60% storage savings.

However, if I upgrade to version 8.17 or later in future, the `synthetic_source` feature will be ignored as I don't have the required license. This will result in a big reversion of the storage savings, significantly impacting cluster storage occupancy.

For instance, we are ingesting around 300 GB of logs per day, so a 20-30% reversion would be significant

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 6, 2025, 5:51pm UTC](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858/4 "2025-01-06T17:51:58Z")

</div>

Hi @Behnam.R

Great questions, but I think we are all perhaps missing something.

LogsDB in 8.16 is in **Technical Preview mode**... we would never suggest that you use this in production, especially at the scale you are working with. Technical Preview means that the capability is subject to change..... including breaking changes **which it has / is effectivly with the 8.17 GA / licensing change.**

The documentation literally says this

> Logs data streams and the logsdb index mode are in tech preview and may be changed or removed in the future. Don’t use logs data streams or logsdb index mode in production.

So we / I would suggest that you **not** enable logsdb in production **before** you upgrade to 8.17 in the first place.

Then, all the required logic will be in place.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 8, 2025, 3:45pm UTC](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858/5 "2025-01-08T15:45:16Z")

</div>

@leandrojmp @Behnam.R  
To close it out a bit...  
Turns out there is a default value and setting for non synthetic `stored` etc.. and yup it needs to be better documented

> <https://github.com/elastic/elasticsearch/issues/119616>
>
> \### Description
> 
> Enhance the \_source / index.mapping.source docs to tell what a…re the available options and how they play with Logsdb and Synthetic \_source
> 
> Explain how to disable Synthetic \_source on specific indices.
> 
> Untangle the complexity of the following setting (and which one overrides what on which version)
> \- \`mappings.\_source.mode\` (synthetic | stored)
> \- \`settings.index.mode\` (time\_series | logsdb | standard)
> \- \`index.mapping.source.mode\` (SYNTHETIC | STORED)
> 
> Related to https://github.com/elastic/elasticsearch/issues/118596 and https://github.com/elastic/elasticsearch/pull/116689

---

<div class="post-metadata">

**Author:** ![Behnam.R](https://avatars.discourse-cdn.com/v4/letter/b/48db29/32.png) [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Post date:** [January 8, 2025, 6:16pm UTC](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858/6 "2025-01-08T18:16:05Z")

</div>

thanks for the update, as you suggested earlier I have upgraded the cluster to 8.17.0, but now I am also aware of the extra settings 🙂
