# Elastic Search 7.12 Java CPU useage

**URL:** https://discuss.elastic.co/t/elastic-search-7-12-java-cpu-useage/270996
**Category:** Elasticsearch
**Created:** [April 22, 2021, 5:16pm UTC](https://discuss.elastic.co/t/elastic-search-7-12-java-cpu-useage/270996 "2021-04-22T17:16:05Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)
#### Post date: [April 22, 2021, 5:16pm UTC](https://discuss.elastic.co/t/elastic-search-7-12-java-cpu-useage/270996/1 "2021-04-22T17:16:05Z")

</div>

1 x3 node cluster 2 stand alone nodes all showing the same signs.

Elastic+ Java process is running at 100% CPU. CentOS 8.

Anyone else running into the issue. The same machines have been fine with the CPU and memory since version 7.0 and updated to 7.12. Only in 7.12 has it been problematic. It's causing SIEM rules to fail to run and it's the same subset that has been used in for the past 2 versions.

Edit:  
Disabled all SIEM rules and it's normal.

Cannot use field [event.category] due to ambiguities being mapped as [2] incompatible types: [text] in [winlogbeat-7.12.0], [keyword] in [.ds-logs-endpoint.events.file-default-000001

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 27, 2021, 1:52am UTC](https://discuss.elastic.co/t/elastic-search-7-12-java-cpu-useage/270996/2 "2021-04-27T01:52:15Z")

</div>

What is the output from the `_cluster/stats?pretty&human` API?  
What does hot threads show?

---

<div class="post-metadata">

### Author: ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)
#### Post date: [April 27, 2021, 4:30pm UTC](https://discuss.elastic.co/t/elastic-search-7-12-java-cpu-useage/270996/3 "2021-04-27T16:30:49Z")

</div>

EDIT:  
Todays update 4/27/2021 -- 7.12.1-1 resolved the issue.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 27, 2021, 11:49pm UTC](https://discuss.elastic.co/t/elastic-search-7-12-java-cpu-useage/270996/4 "2021-04-27T23:49:56Z")

</div>

How did you resolve it? Please share the solution in the thread, it might help someone in future 🙂

---

<div class="post-metadata">

### Author: ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)
#### Post date: [April 28, 2021, 12:29am UTC](https://discuss.elastic.co/t/elastic-search-7-12-java-cpu-useage/270996/5 "2021-04-28T00:29:16Z")

</div>

> [@PublicName](#):
>
> 7.12.1-1 resolved the issue.

dnf update, nothing more.

I have 1 stand alone machine that is still higher then 7.11 CPU but haven't looked into that one as it's a dev box.

One thing I've noticed is with winlogbeat/metricbeat the last few minor version of kibana if your agents are not matching they really eat your server alive. Have to be in lock step sense version 7.11.1 or it becomes unusable in any meaningful way. This isn't all that easy to accomplish at times.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 26, 2021, 12:30am UTC](https://discuss.elastic.co/t/elastic-search-7-12-java-cpu-useage/270996/6 "2021-05-26T00:30:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
