# Shards getting bigger with updates (same number of documents)

**URL:** <https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329>\
**Category:** Elasticsearch\
**Created:** [February 15, 2021, 3:31pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329 "2021-02-15T15:31:05Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcineq](https://avatars.discourse-cdn.com/v4/letter/m/e47c2d/32.png) [@marcineq](https://discuss.elastic.co/u/marcineq)\
**Post date:** [February 15, 2021, 3:31pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/1 "2021-02-15T15:31:05Z")

</div>

Hi all

I have a ES 7 cluster of couple of EC2 instances, the index has 6 shards and each shard has 2 replicas (so 1+2 x 6 = 18 shards for an index). When I create the index each shard size is around 25-30gb and we hold around 3mln of records in the database. We have a bit of updates happening everyday, let's say it's around 1mln, the update means the record gets replaced by a new one but the ID stays the same - we have pretty much the same amount of documents. I've noticed that after couple of weeks the shard size grows to 50gb so nearly double the size. Could someone please explain to me why this is happening and how can I fix it? (or should I fix it?) I've noticed search performance going down when we reach 50gb shards. Any comments/help would be highly appreciated.

Thanks

marcineq

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 15, 2021, 10:41pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/2 "2021-02-15T22:41:10Z")

</div>

Welcome to our community! 😃

What is the output from the `_cat/indices?v` API?

---

<div class="post-metadata">

**Author:** ![marcineq](https://avatars.discourse-cdn.com/v4/letter/m/e47c2d/32.png) [@marcineq](https://discuss.elastic.co/u/marcineq)\
**Post date:** [February 15, 2021, 11:23pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/3 "2021-02-15T23:23:53Z")

</div>

Thanks Mark

```auto
    index_name 2 p STARTED 46750788 50gb 11.11.11.111 ip-11.11.11.111-es
    index_name 2 r STARTED 46750788 49.3gb 22.22.22.222 ip-22.22.22.222-es
    index_name 2 r STARTED 46750788 44.4gb 33.33.33.333 ip-33.33.33.333-es
    index_name 1 p STARTED 46532522 47.9gb 44.44.44.444 ip-44.44.44.444-es
    index_name 1 r STARTED 46532522 52.7gb 55.55.55.555 ip-55.55.55.555-es
    index_name 1 r STARTED 46532522 49gb 66.66.66.666 ip-66.66.66.666-es
    index_name 3 r STARTED 46677577 52gb 11.11.11.111 ip-11.11.11.111-es
    index_name 3 p STARTED 46677577 47.5gb 55.55.55.555 ip-55.55.55.555-es
    index_name 3 r STARTED 46677577 44.4gb 77.77.77.777 ip-77.77.77.777-es
    index_name 5 p STARTED 46736104 50.8gb 88.88.88.888 ip-88.88.88.888-es
    index_name 5 r STARTED 46736104 52.8gb 99.99.99.999 ip-99.99.99.999-es
    index_name 5 r STARTED 46736104 48gb 66.66.66.666 ip-66.66.66.666-es
    index_name 4 p STARTED 46660338 45.7gb 77.77.77.777 ip-77.77.77.777-es
    index_name 4 r STARTED 46660338 49.6gb 88.88.88.888 ip-88.88.88.888-es
    index_name 4 r STARTED 46660338 46.8gb 99.99.99.999 ip-99.99.99.999-es
    index_name 0 r STARTED 46504385 43gb 44.44.44.444 ip-44.44.44.444-es
    index_name 0 r STARTED 46504385 53.3gb 22.22.22.222 ip-22.22.22.222-es
    index_name 0 p STARTED 46504385 51gb 33.33.33.333 ip-33.33.33.333-es

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 15, 2021, 11:31pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/4 "2021-02-15T23:31:50Z")

</div>

That doesn't look aligned with what you are suggesting, there's no deleted documents showing.

---

<div class="post-metadata">

**Author:** ![marcineq](https://avatars.discourse-cdn.com/v4/letter/m/e47c2d/32.png) [@marcineq](https://discuss.elastic.co/u/marcineq)\
**Post date:** [February 15, 2021, 11:42pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/5 "2021-02-15T23:42:59Z")

</div>

Sorry, maybe I explained it incorrectly - if I have document with \_id x, an update comes it, es.index is performed with an \_id x which replaces the doc x which already exists in the ES db. This operation happens to around 1mln records per day, I have 3mln records in total.

> **[API Reference | Elasticsearch Node.js client \[7.x\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/current/api-reference.html#_index)**

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 15, 2021, 11:43pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/6 "2021-02-15T23:43:58Z")

</div>

You explained it correctly, but that index is not showing any deleted documents based on the output you provided.

---

<div class="post-metadata">

**Author:** ![marcineq](https://avatars.discourse-cdn.com/v4/letter/m/e47c2d/32.png) [@marcineq](https://discuss.elastic.co/u/marcineq)\
**Post date:** [February 15, 2021, 11:46pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/7 "2021-02-15T23:46:50Z")

</div>

Is that based on the same doc count for the shards? the updates happened in the morning and everything is up to date now across primaries/replicas.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 15, 2021, 11:56pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/8 "2021-02-15T23:56:21Z")

</div>

It's based on what I can see from the output from the `_cat` command you ran. By default, it should show the number of deleted docs directly after the number of docs. There's nothing there though?

What version are you on?

---

<div class="post-metadata">

**Author:** ![marcineq](https://avatars.discourse-cdn.com/v4/letter/m/e47c2d/32.png) [@marcineq](https://discuss.elastic.co/u/marcineq)\
**Post date:** [February 15, 2021, 11:57pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/9 "2021-02-15T23:57:04Z")

</div>

7.3.2

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 15, 2021, 11:57pm UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/10 "2021-02-15T23:57:50Z")

</div>

And you run `_cat/indices?v`, exactly that?

---

<div class="post-metadata">

**Author:** ![marcineq](https://avatars.discourse-cdn.com/v4/letter/m/e47c2d/32.png) [@marcineq](https://discuss.elastic.co/u/marcineq)\
**Post date:** [February 16, 2021, 12:01am UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/11 "2021-02-16T00:01:53Z")

</div>

Sorry I was looking at the wrong thing - it's getting late now, here you go:

```auto
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open index_name 23BMWdfBQKukF5AKjORnkA 6 2 279861774 99922075 833.8gb 268.3gb

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 16, 2021, 6:13am UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/12 "2021-02-16T06:13:45Z")

</div>

Elasticsearch does not perform in place updates. Instead data is stored in immutable segments, so updating documents generates new additional segments that take up additional space and the data that was updated is not immediately deleted. It is not until segments are merged in the background that updated documents are removed from disk and this is triggered when the amount of updated documents in a segment exceeds a threshold. Having an index increase in size while updating is therefore expected.

---

<div class="post-metadata">

**Author:** ![marcineq](https://avatars.discourse-cdn.com/v4/letter/m/e47c2d/32.png) [@marcineq](https://discuss.elastic.co/u/marcineq)\
**Post date:** [February 16, 2021, 8:18am UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/13 "2021-02-16T08:18:12Z")

</div>

That makes sense, what should be done in this case? Should I increase the number of shards so that I don't get into a situation where the shard gets over the recommended size? Is there a way to trigger a merge?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 16, 2021, 8:42am UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/14 "2021-02-16T08:42:23Z")

</div>

You can use the [force merge API](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/indices-forcemerge.html) to trigger merges and it has a parameter named `only_expunge_deletes` that may help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2021, 8:42am UTC](https://discuss.elastic.co/t/shards-getting-bigger-with-updates-same-number-of-documents/264329/15 "2021-03-16T08:42:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
