# ElasticSearch 7.4 taking 100% cpu usage

**URL:** <https://discuss.elastic.co/t/elasticsearch-7-4-taking-100-cpu-usage/249241>\
**Category:** Elasticsearch\
**Created:** [September 20, 2020, 8:30am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-taking-100-cpu-usage/249241 "2020-09-20T08:30:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pavan\_Kalyan\_Ladi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pavan_kalyan_ladi/32/75885_2.png) [@Pavan\_Kalyan\_Ladi](https://discuss.elastic.co/u/Pavan_Kalyan_Ladi)\
**Post date:** [September 20, 2020, 8:30am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-taking-100-cpu-usage/249241/1 "2020-09-20T08:30:49Z")

</div>

Recently we migrated from ES-5.1 to ES7.4 and the CPU usage too high in ES7.4 compared to ES5.1

With a given load the max. cpu usage of 5.1 is in between 0% to 10%.  
However the performance and max. cpu usage of 7.4 is in between 20% to 100%.  
The cluster configuration of 7.4 is exactly same as 5.1 and same queries being used.

Please find the hot threads output for ES7.4  
When there is no load  
[https://gist.github.com/pavanladi98/ad867151bc2f5b2803f724dc8d3493db](https://gist.github.com/pavanladi98/ad867151bc2f5b2803f724dc8d3493db)  
When there is usual load  
[https://gist.github.com/pavanladi98/dc5cab94be43dc2771ef8362bccc4a7a](https://gist.github.com/pavanladi98/dc5cab94be43dc2771ef8362bccc4a7a)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 21, 2020, 11:51am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-taking-100-cpu-usage/249241/2 "2020-09-21T11:51:26Z")

</div>

hey,

can you go into some more details about your query load? What kind fo query are you running? Does it include an aggregation? Do you have any special configuration for global ordinals in your mapping? Do you use any special fields? Is this a heavily updated index?

Some more context would be great.

--Alex

---

<div class="post-metadata">

**Author:** ![Pavan\_Kalyan\_Ladi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pavan_kalyan_ladi/32/75885_2.png) [@Pavan\_Kalyan\_Ladi](https://discuss.elastic.co/u/Pavan_Kalyan_Ladi)\
**Post date:** [September 21, 2020, 5:11pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-taking-100-cpu-usage/249241/3 "2020-09-21T17:11:37Z")

</div>

Hi, thanks for the reply

1. We mostly use a function\_score query with some filters on geolocation, date etc... fileds.
2. We also use another boolean match query along with aggregations.

`The data and queries we used are same in 5.1 and 7.4.`

But in 7.4 ,  
To improve the search speed of this aggregation query, we used `Eager_global_ordinals: True` on few fields. Since this might be costly at indexing time, as suggested in elasticsearch documentaion we are using `refresh_interval: 30s` .

Yes, our data gets indexed/updated frequently but at slow rate, approximately at rate of 20 docs per minute.

> Other differences:
> 
> 1. we enabled encryption(REST encryption and node-to-node encryption) on our 7.4 elasticsearch cluster.
> 2. we increased number of shards for our largest index(pri.size = 600GB) in 7.4  
> number\_of\_shards: 6 (in 5.1)  
> number\_of\_shards: 15 (in 7.4)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 22, 2020, 7:31am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-taking-100-cpu-usage/249241/4 "2020-09-22T07:31:08Z")

</div>

The important part about global ordinals is [in the last paragraph](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/eager-global-ordinals.html#_avoiding_global_ordinal_loading)

> Because global ordinals provide a unified mapping for all segments on the shard, they also need to be rebuilt entirely when a new segment becomes visible.

You may want to try a different `execution_hint` and see what happens.

Just to be sure, did you use eager loading of ordinals in 5.1 as well or added it in 7.4?

---

<div class="post-metadata">

**Author:** ![Pavan\_Kalyan\_Ladi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pavan_kalyan_ladi/32/75885_2.png) [@Pavan\_Kalyan\_Ladi](https://discuss.elastic.co/u/Pavan_Kalyan_Ladi)\
**Post date:** [September 22, 2020, 8:39am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-taking-100-cpu-usage/249241/5 "2020-09-22T08:39:07Z")

</div>

We used `Eager_global_ordinals: true` in mapping only in 7.4

We had millions of docs matching the query. So, as suggested we are using default `excecution_hint`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2020, 8:39am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-taking-100-cpu-usage/249241/6 "2020-10-20T08:39:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
