# \_source filed is using to much disk space

**URL:** <https://discuss.elastic.co/t/source-filed-is-using-to-much-disk-space/311103>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [August 1, 2022, 10:45am UTC](https://discuss.elastic.co/t/source-filed-is-using-to-much-disk-space/311103 "2022-08-01T10:45:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maksym\_Postument](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maksym_postument/32/106661_2.png) [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Post date:** [August 1, 2022, 10:45am UTC](https://discuss.elastic.co/t/source-filed-is-using-to-much-disk-space/311103/1 "2022-08-01T10:45:28Z")

</div>

\_source for metricbeat index is using a lot of space. Index size is 15.2gb and \_source filed is 12.2gb. And from 4 kubernetes nodes in one day total size of metricbeat size is 160 gb. Any ideas why metricbeat index size so big and how to reduce it?

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [August 1, 2022, 11:45am UTC](https://discuss.elastic.co/t/source-filed-is-using-to-much-disk-space/311103/2 "2022-08-01T11:45:01Z")

</div>

Unfortunately, `_source` is just one of those things that currently just takes up space. You didn't mention which version of Elasticsearch/Metricbeat you're currently using, but you can take a look at: [Tune for disk usage | Elasticsearch Guide [8.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-disk-usage.html) to see if there are any changes you could make to improve this.

Two things to note, there are 2 features being worked on on the Elasticsearch side that I think will greatly improve storage efficiency in the future:

1. TSDB - [Add better support for metric data types (TSDB) · Issue #74660 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/74660) this from what I can tell will allow for better optimization of storing metrics (like data from Metricbeat)
2. Synthetic Source - [Synthetic Source · Issue #86603 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/86603) this seems like it would effectively remove the overhead of `_source` while not having all the drawbacks of fully disabling `_source`.
  - [Synthetic source by nik9000 · Pull Request #85649 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/85649#issue-1190207781) there is a `perf numbers` section in the PR which seems to show significant reductions in disk usage

Note: Both of the above changes I don't think are GA in any current release of Elasticsearch.

---

<div class="post-metadata">

**Author:** ![Maksym\_Postument](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maksym_postument/32/106661_2.png) [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Post date:** [August 1, 2022, 12:11pm UTC](https://discuss.elastic.co/t/source-filed-is-using-to-much-disk-space/311103/3 "2022-08-01T12:11:55Z")

</div>

I am using version 8.3.2. Thank you for link. I will take a look

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2022, 2:12pm UTC](https://discuss.elastic.co/t/source-filed-is-using-to-much-disk-space/311103/4 "2022-08-29T14:12:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
