Sharding for hidden index in elasticsearch

Hidden index like .kibana,.monitoring-logstash-7,.kibana-event-log-7,.kibana_task_manager_2 etc do we need to really care about sharding of these indices like we create 3 shards for winlogbeat 3 shards for packetbeat and we have 3 data node each node of one shard

Those system indices are managed automatically, so you can safely leave them alone.

For kibana system index also

Yes, anything with a . at the start is considered a system managed index.

Just one question i don't know how to calculate shard size suppose we have 2499 shards and 443 indices and its data size 650gb

Is this about the system indices in your first post? If not then it'd be better to create a new topic please :slight_smile: