# Monitoring-es indices more than 10g a day

**URL:** <https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [June 11, 2019, 7:39am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114 "2019-06-11T07:39:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [June 11, 2019, 7:39am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114/1 "2019-06-11T07:39:21Z")

</div>

Hello,

I have a question. I have several cluster running and everything works except one cluster.

The monitoring for elasticsearch is enabled with all default values, but my 3 node Cluster (7.1.0) uses 10g a day.  
My other clusters (7.0.1) do only have 1g a day.

I did not find any breaking changes. Am I missing a new option?

---

<div class="post-metadata">

**Author:** ![cachedout](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cachedout/32/38707_2.png) [@cachedout](https://discuss.elastic.co/u/cachedout)\
**Post date:** [June 11, 2019, 7:56am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114/2 "2019-06-11T07:56:49Z")

</div>

@logger

Hmm, I can't think of anything offhand that would cause this. I assume you checked the logs on the cluster for errors? Could we see a sanitized copy of the settings for the 7.1 cluster?

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [June 11, 2019, 8:01am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114/3 "2019-06-11T08:01:43Z")

</div>

No errors or warnings in the logs.

> bootstrap.memory\_lock: false  
> cluster.name: cluster  
> discovery.seed\_hosts: ["host1","host2"]
> 
> http.port: 9200  
> node.data: true  
> node.ingest: true  
> node.master: true  
> node.max\_local\_storage\_nodes: 1  
> node.name: host2  
> path.data: F:\elastic\data  
> path.logs: F:\elastic\logs  
> transport.tcp.port: 9300  
> network.host: 0.0.0.0
> 
> xpack.watcher.enabled: true  
> xpack.monitoring.enabled: true  
> xpack.security.enabled: true  
> xpack.security.transport.ssl.enabled: true  
> xpack.security.transport.ssl.verification\_mode: certificate  
> xpack.security.transport.ssl.keystore.path: F:\elastic\config\certs\elastic-certificates.p12  
> xpack.security.transport.ssl.truststore.path: F:\elastic\config\certs\elastic-certificates.p12

OK I forgot this one is the only Windows cluster. I think this info is important.

---

<div class="post-metadata">

**Author:** ![cachedout](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cachedout/32/38707_2.png) [@cachedout](https://discuss.elastic.co/u/cachedout)\
**Post date:** [June 11, 2019, 8:17am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114/4 "2019-06-11T08:17:24Z")

</div>

> [@logger](#):
>
> OK I forgot this one is the only Windows cluster. I think this info is important.

Ah, interesting. Do you have other 7.1 clusters which are behaving as-expected and it just the Windows cluster which is emitting data at a higher rate?

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [June 11, 2019, 8:23am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114/5 "2019-06-11T08:23:45Z")

</div>

I have only the Windows Cluster with 7.1.0  
the others are debian and version 7.0.1 I will try to upgrade one debian Cluster to 7.1.0 and see what will happen.

And it is only the monitoring-es ; logstash and kibana are behaving normal

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [June 12, 2019, 7:15am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114/6 "2019-06-12T07:15:53Z")

</div>

Ok, looks like it handled itself.

This cluster was a 3 node test cluster on windows server 2016.  
with way too much shards and indices. 1600 shards per node.

Now after a cleanup to 60 shards all is running well.  
Does elasticsearch monitor other events and put it in the .monitoring-es index?

---

<div class="post-metadata">

**Author:** ![cachedout](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cachedout/32/38707_2.png) [@cachedout](https://discuss.elastic.co/u/cachedout)\
**Post date:** [June 12, 2019, 8:31am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114/7 "2019-06-12T08:31:16Z")

</div>

Hi @logger. Glad you got it working. Elasticsearch monitors a variety of metrics in the .monitoring-es index. Since Elasticsearch was collecting data on all those shards, that probably explains the increase in data usage.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2019, 8:31am UTC](https://discuss.elastic.co/t/monitoring-es-indices-more-than-10g-a-day/185114/8 "2019-07-10T08:31:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
