# Data nodes removed from cluster one by one after indexing activity peak

**URL:** <https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764>\
**Category:** Elasticsearch\
**Created:** [November 9, 2023, 8:35am UTC](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764 "2023-11-09T08:35:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jalker](https://avatars.discourse-cdn.com/v4/letter/j/d26b3c/32.png) [@jalker](https://discuss.elastic.co/u/jalker)\
**Post date:** [November 9, 2023, 8:35am UTC](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764/1 "2023-11-09T08:35:12Z")

</div>

Elasticsearch 7.17, Debian, 12 data nodes, 5.5 Bi primary docs, 11.0 TB primary doc size.  
We have seen the following behavior twice now and we are clueless as to its root cause.  
We see an sudden increase of indexing activity on all nodes followed by a return to normal followed by the removal of all data nodes.

 ![Capture d'écran 2023-11-08 184446](https://us1.discourse-cdn.com/elastic/original/3X/4/6/4606590ce271bf7ed9e09eb177809e15c8489f77.png)

The activity peak does not seem to be matched by a significant increase of resource consumption (CPU, RAM, disks...) which are all well below their upper limit.  
Is there anything we should look at? Any insights would be appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2023, 8:35am UTC](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764/2 "2023-12-07T08:35:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
