Analyze messages by size


I have noticed that index grew almost 100Gb/day, remaining the almost similar overall message count
How can i find/anaylze which log files have change their size recently ?

unfortunately you can’t order by size.
do a search :slight_smile:
under source you can check the top sources, after search, and check the incoming log messages.

Or you can try with elasticdump, and some linux cli tricks you can do it.

