Elastic cluster slow down afre a few weeks of uptime(cluster recommendations)

If one of them has a much higher steal time than the others, it's not working more--- it's working less. As the doc I linked to suggests, you could try moving it to a different physical host with less noisy neighbors.

If CPU is much higher on one node than the others, in my experience it's usually due to heavy segment merging brought on by frequent updates to one or more documents that happen to fall on shards on that node. A quick look at hot threads will tell you.