Andrew Mercer
on this page

Steady state is the disk usage a lifecycle policy settles at once it has run long enough that old generations are deleted as fast as new ones are created. Before that point, usage is still climbing toward equilibrium.

Steady state vs. right now

What it tells you
Right now What is on disk at this moment. Distorted by manual deletions, recent bursts or a policy that has only just been applied.
Steady state The typical ongoing footprint under normal ingest. This is the number to use for capacity planning.

A one-off manual cleanup can make a policy look leaner than it is. For example, a data stream showing only one cold index right after old ones were deleted by hand. Steady state ignores blips like that.

Estimating it

For a policy that rolls over every R and deletes at D after rollover:

generations ≈ D / R + 1                  # +1 for the current write index
disk        ≈ generations × avg_generation_size × (1 + replicas)

Example: daily rollover, delete at 10 days, ~20 GB of primary data per day, 1 replica:

generations ≈ 10 / 1 + 1 = 11
disk        ≈ 11 × 20 GB × 2 = 440 GB

Adjust for the warm and cold phases. best_compression with a force merge typically shrinks those generations by another 15–30%, and searchable snapshots on frozen move them off local disk almost entirely.

Leave headroom on top of the estimate so the cluster stays below the low watermark (85% by default) at steady state, with room for force merges and shard relocation.