Hey @josephmanalo
Please note that fortunately we are not all guys here ![]()
Do you have any elasticsearch monitoring activated so you can understand may be better what's the cause of this?
It sounds like you are using HDD disks for some nodes and SSD on other nodes. That's an issue IMO.
I also wonder why are you using Logstash for?
May be you have also too many shards per node.
What is the output of:
GET /_cat/health?v
GET /_cat/indices?v
May I suggest you look at the following resources about sizing:
And https://www.elastic.co/webinars/using-rally-to-get-your-elasticsearch-cluster-size-right