# Tuning ELK Performance and controlling Logs

**URL:** <https://discuss.elastic.co/t/tuning-elk-performance-and-controlling-logs/60999>\
**Category:** Elasticsearch\
**Created:** [September 20, 2016, 9:53am UTC](https://discuss.elastic.co/t/tuning-elk-performance-and-controlling-logs/60999 "2016-09-20T09:53:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [September 20, 2016, 9:53am UTC](https://discuss.elastic.co/t/tuning-elk-performance-and-controlling-logs/60999/1 "2016-09-20T09:53:08Z")

</div>

Hi All,

I need solution or guidance for below queries, to improve the performance. Kindly help.

1. We can control logs in kibana, like log only if Error, is there any other way to do the same for logstash?
2. Similarly Is it possible to deprecate index in run time, Like, i want to clear index data that are older than a week?
3. Also my Elasticsearch data file is around 50Gb, is there any method to reduce the size other than deleting the index.
4. There is only one node currently available, how to create more nodes and replicas? Do i need to run another elasticsearch instance in same machine?

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [September 20, 2016, 10:12am UTC](https://discuss.elastic.co/t/tuning-elk-performance-and-controlling-logs/60999/2 "2016-09-20T10:12:35Z")

</div>

> Similarly Is it possible to deprecate index in run time, Like, i want to clear index data that are older than a week?

You might want to look at curator: [GitHub - elastic/curator: Curator: Tending your Elasticsearch indices](https://github.com/elastic/curator)

> Also my Elasticsearch data file is around 50Gb, is there any method to reduce the size other than deleting the index.

Running `optimize` might help a bit, curator can ke used to automate it.

> There is only one node currently available, how to create more nodes and replicas? Do i need to run another elasticsearch instance in same machine?

You can have multiple shards on a single node. However having multiple replicas of the same shard is not helpful on a single node since you can lose both at once. You should look into starting up another node on another machine.

---

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [September 20, 2016, 10:52am UTC](https://discuss.elastic.co/t/tuning-elk-performance-and-controlling-logs/60999/3 "2016-09-20T10:52:37Z")

</div>

Hi Adrien,

Thanks a lot will check on that.

Is there any other way like adding in few parameter/function in config. will be really helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:18pm UTC](https://discuss.elastic.co/t/tuning-elk-performance-and-controlling-logs/60999/4 "2017-07-05T22:18:53Z")

</div>


