Show me.
There are many fields available in the mapping ... but they are not shipped in each squid document.
Show me the extra fields in one of the squid documents.
What do you mean the "real" squid logs logs size the size of the file... show me where you the data stream size.
GET _cat/indices?v
Two things 1 when indices / data streams first get created there is some overhead overtime elasticsearch will optimizes that overhead and the average document size will shrink. These processes are in the background. 2nd 66mb is very small in terms of index size and some the level of the optimization is also small...