Hello,
Honestly the situation occured 2 weeks ago, we had to uninstall all elastic-agent and endpoint because our hosts were barely usable at that point.
I can only answer your questions from memory since we wiped all our elastic-agent and did a fresh deployment.
- None of integration you mentioned were installed at the time of the issue.
 - I did have Elastic Defend added to their policy at some point but I removed it days prior to the incident. Some hosts weren't even enrolled when I added and removed the Elastic Defend.
 - None to share.
 - version 8.12.0
 - I did some tests on a smaller scale, but couldn't reproduce the incident.
 
So I came to wonder, could this have been an issues with the policy changes that I made ? Maybe I didn't allocate enough resources for my cluster and some changes in the policy weren't taken into account or overlaped?
Also, I remember that it occured on the same day that I updated a bunch of elastic-agent.