# Storage rate for a specefic machine

**URL:** <https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043>\
**Category:** Elasticsearch\
**Created:** [May 4, 2021, 7:34am UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043 "2021-05-04T07:34:54Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [May 4, 2021, 7:34am UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/1 "2021-05-04T07:34:54Z")

</div>

Hello everyobody,

I have a production cluster where I have some windows machines connected to my ELK Cluster, and for some monitoring reasons, I would like to know how many data collected from each machine for eample for the last 24 hours

Could you please to tell me if there is a way to do that from an `SQL` request in canvas, or using the `Dev Tool` in kibana or any other way !

Thanks for your help

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2021, 7:36am UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/2 "2021-05-04T07:36:48Z")

</div>

> [@TheHunter1](#):
>
> I would like to know how many data collected from each machine for eample for the last 24 hours

In terms of MB/GB per host stored in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [May 4, 2021, 7:54am UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/3 "2021-05-04T07:54:29Z")

</div>

Yes @warkolm that's what I would like to get as a result

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2021, 9:50pm UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/4 "2021-05-04T21:50:17Z")

</div>

Then take a look at [Mapper Size Plugin | Elasticsearch Plugins and Integrations [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/plugins/current/mapper-size.html)

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [May 10, 2021, 9:12am UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/5 "2021-05-10T09:12:25Z")

</div>

Thanks for your answer @warkolm ,

I just had access to my cluster today and I installed it, and restarted all the nodes.  
If I understand well, to enable the `_size` field I should run the command in the `DEV Tool` of kibana :

```auto
PUT my-index-000001
{
  "mappings": {
    "_size": {
      "enabled": true
    }
  }
}

```

Is there a quick way to enable it in all my indexes (even the futur ones) ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 10, 2021, 10:27am UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/6 "2021-05-10T10:27:05Z")

</div>

You cannot apply it to existing indices.  
For future ones, make sure you add that to the relevant index template.

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [May 10, 2021, 11:20am UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/7 "2021-05-10T11:20:32Z")

</div>

So, for example if my indice now it's `packetbeat-7.12.0-2021.05.06-000012`, I should apply it to the indice `packetbeat-7.12.0- ****.**.**-000013` , and then automatically it will be enabled for all the future indices ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 10, 2021, 11:03pm UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/8 "2021-05-10T23:03:11Z")

</div>

If you are using the default (aka bundled) Packetbeat template, you will need to tell Packetbeat to use a custom one (based on that template) with your additions.

[Configure Elasticsearch index template loading | Packetbeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-template.html) should provide some assistance on that aspect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2021, 11:03pm UTC](https://discuss.elastic.co/t/storage-rate-for-a-specefic-machine/272043/9 "2021-06-07T23:03:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
