# Shards too large to archive data

**URL:** <https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560>\
**Category:** Elasticsearch\
**Created:** [April 7, 2017, 3:54am UTC](https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560 "2017-04-07T03:54:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![weibin.wu](https://avatars.discourse-cdn.com/v4/letter/w/4491bb/32.png) [@weibin.wu](https://discuss.elastic.co/u/weibin.wu)\
**Post date:** [April 7, 2017, 3:54am UTC](https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560/1 "2017-04-07T03:54:36Z")

</div>

Hi Elasticsearch:

When I start to take care one of our cluster. I found this cluster is too hugh.  
Shards: 5  
Nodes: 5  
Replica: 1  
Each shard 400GB data.  
Total documents: 5 billions.  
Version: 1.4

I tried to do a simple search on the cluster but the query just run forever until timeout.  
I tried elasticdump from github but also got stuck when running. The search latency in my monitoring is bumping high.  
The data is time based, is there a way to archive the data? Any ideas?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 7, 2017, 5:35am UTC](https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560/2 "2017-04-07T05:35:42Z")

</div>

Query and aggregation latency will depend on the shard size as each query/aggregation runs single threaded over each shard. Multiple shards and queries can however be processed in parallel. Having this large shards can therefore result in poor query performance.

If you have time-based data, we generally recommend that you use [time-based indices](https://www.elastic.co/guide/en/elasticsearch/guide/2.x/time-based.html#index-per-timeframe).

As you are on a very old version, I would also recommend upgrading.

Having said that, I don't think there is any easy was out, and you will need to reindex your data into new indices. If even simple queries and scroll requests time out that may however be difficult.

---

<div class="post-metadata">

**Author:** ![weibin.wu](https://avatars.discourse-cdn.com/v4/letter/w/4491bb/32.png) [@weibin.wu](https://discuss.elastic.co/u/weibin.wu)\
**Post date:** [April 7, 2017, 10:30am UTC](https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560/3 "2017-04-07T10:30:10Z")

</div>

Thanks Christian:

I am using filter to extract the data monthly and seems its works for my case.  
I am going to build new index based on month. In my calculation if I build index based on month.  
1 index has 5 shards then each shard will have 60GB data about 5 millions documents.  
Do you think this shard is too big ? What is the recommendation for a shards size?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 7, 2017, 10:47am UTC](https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560/4 "2017-04-07T10:47:39Z")

</div>

The ideal shard size depends on the use case, but we generally recommend keeping it below 50GB. You do not have to go with 5 shards per index, and if they will get too large, maybe 8 or 10 shards per monthly index may be more suitable.

---

<div class="post-metadata">

**Author:** ![weibin.wu](https://avatars.discourse-cdn.com/v4/letter/w/4491bb/32.png) [@weibin.wu](https://discuss.elastic.co/u/weibin.wu)\
**Post date:** [April 7, 2017, 10:50am UTC](https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560/5 "2017-04-07T10:50:13Z")

</div>

Thanks Christian. That will solve my case for now.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 7, 2017, 10:50am UTC](https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560/6 "2017-04-07T10:50:46Z")

</div>

Also consider upgrading, at least to Elasticsearch 1.7.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2017, 10:59am UTC](https://discuss.elastic.co/t/shards-too-large-to-archive-data/81560/7 "2017-05-05T10:59:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
